← Back to Archive
leakhigh9/4/2026

API hacks hit South Korea platforms, exposing hundreds of thousands

Healing Paper / Gangnam Unnie

Healing Paper said abnormal access to a consultation-history inquiry API on September 4 led to a leak of some customers’ personal information. The company blocked the access path after detection and later requested a police investigation.

The incident affected the aesthetic medical platform Gangnam Unnie, operated by Healing Paper, after attackers exploited an API vulnerability. The company said the abnormal access occurred on September 4, and it detected signs the same attacker tried again through a different path the next day. According to the report, the leak involved 219,665 customers across South Korea and overseas markets. Exposed data included names, contact information, consultation photos, preferred reservation times, consultation motives, practitioner identifiers, and procedure/payment-related information.

Tags

#data breach#API vulnerability#medical platform#personal information

Last updated: September 11, 2026