Healing Paper disclosed that unauthorized, abnormal access to an API used by its Gangnam Unni beauty-medical platform exposed personal data belonging to 219,665 domestic and international users. The company detected access to a consultation-record retrieval API, blocked the identified route, and said the same attacker attempted to use another route the following day; no responsible threat actor has been identified.
The affected users include roughly 160,000 people in South Korea, 48,000 in Japan, and 4,218 in Taiwan. Potentially exposed information includes account and device details alongside highly sensitive consultation, treatment, payment, visit, procedure, and patient-photo data, creating material privacy, fraud, and extortion risk for affected individuals.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Healing Paper disclosed a personal-data breach affecting 219,665 Gangnam Unni users, including users in South Korea, Japan, and Taiwan. Exposed information reportedly included account and device data as well as consultation, treatment, payment, visit, procedure, and patient-photo information.
Healing Paper reported that the same attacker attempted to access its systems through a different route after the original API route was blocked.
Healing Paper identified abnormal access to Gangnam Unni's API integration feature used to view consultation records. The company blocked the access route after detection; the incident ultimately affected about 220,000 users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.