South Korean Medical Beauty Platform Gangnam Unni Suffers API Breach Exposing 220,000 Users' Sensitive Photos and Medical Records
Healing Paper, the operator of South Korea's largest medical beauty platform Gangnam Unni, issued a public apology on September 7 confirming that personal data of nearly 220,000 customers had been exposed through abnormal access to an API interface.
What Data Was Leaked
The breach involved far more than basic identifiers. Exposed information included names, phone numbers, email addresses, birth dates, gender, residential locations, social media IDs, and IP addresses. More critically, it also revealed medical beauty consultation details such as requested procedures, hospital and doctor names, reasons for consultation, treatment progress, user-uploaded consultation photos, appointment times, completed procedures, visit records, and payment information. These records create a comprehensive profile of an individual's health status, appearance insecurities, spending patterns, and movement history, including highly private pre-procedure images that users would never want shared.
Of the affected users, roughly 160,000 were in South Korea and 60,000 overseas. The overseas group included 48,000 from Japan, 4,218 from Taiwan, 1,591 from Thailand, and 481 from mainland China.
How the API Became the Leak Point
The attack path was straightforward and did not require sophisticated techniques. On September 4, attackers abnormally accessed an API endpoint designed for querying consultation records. After Healing Paper blocked that path, the same actor attempted access via a different route the next day. The root cause was insufficient authentication checks and missing rate-limiting controls on backend APIs. Many platforms focus security efforts on the main website and user interface while leaving API endpoints with loose access controls, incomplete logging, and no real-time anomaly detection.
Secondary Risks After the Breach
Security experts in South Korea have warned of immediate follow-on threats. Attackers could use the detailed medical and appointment data to craft convincing phishing messages impersonating the platform or clinics, offering fake promotions or appointment reminders. Even more concerning is the potential for extortion, where victims are threatened with the release of their pre-procedure photos and treatment records unless they pay.
Remediation and Recommendations
Healing Paper has reported the incident to the Korea Internet & Security Agency, involved law enforcement, conducted a full system review, strengthened identity verification, and added abnormal access monitoring. Users can check their exposure status on the official site within 30 days of the announcement.
Security teams are advised to treat APIs with the same rigor as primary web applications: enforce strict authentication and least-privilege access, implement rate limiting and behavioral analytics on sensitive endpoints, integrate API logs into SIEM systems, and include API attack surfaces in regular penetration testing. Users who registered with Gangnam Unni or similar platforms should verify any unexpected messages claiming to be from the service or clinics through official channels before clicking links or providing information.
Related articles
Revolut Confirms Limited Data Exposure After Fraudulent Government Email Request
Revolut has confirmed that a small number of customers had personal documents and full transaction histories exposed after the company responded to a fraudulent request that appeared to come from a government authority. The incident, disclosed on September 13, involved no intrusion into Revolut systems. Attackers instead used an unauthorized email account that carried valid credentials from a government domain, making the request appear legitimate. Exposed data included passport and driver’s license copies, identity verification selfies, full names, dates of birth, occupations, addresses, contact details, IBAN statements, complete transaction histories, and Bitcoin activity records. The combination of identity documents and detailed financial history significantly raises the risk of account takeover and targeted social engineering. Revolut stated that customer funds remained secure, blocked the malicious email source, notified regulators, and contacted all affected users.
Major Game Leaks: Rhysida, Cyberleek and High-Profile Breaches at Insomniac, Naughty Dog and Rockstar
A detailed retrospective examines multiple high-impact leaks of unreleased games, including early builds of Marvel’s Wolverine and Spider-Man 2 stolen from Insomniac by the Rhysida group, cutscenes from The Last of Us Part II obtained via an AWS vulnerability at Naughty Dog, and extensive GTA VI alpha footage taken by teenager Arian Kurtaj through social engineering against Rockstar. The article also covers the recent Cyberleek operation targeting GTA VI, where the perpetrator combined leaks with a memecoin scheme. Investigations, legal outcomes, and the broader consequences for developers and platforms are analyzed in depth.
Metascan Confirms Limited Data Breach After Two-Minute Telegram Bot Compromise
Metascan has publicly acknowledged a data breach involving internal materials obtained through a compromised Telegram bot token. The attacker gained access to a corporate Telegram chat for approximately two minutes on September 5 and exported a small set of documents before being removed. The incident stemmed from an overlooked bot token on test virtual machines after an employee departure. Among the leaked items were two pilot project reports from July 2026 that mentioned major Russian organizations including Transneft, Selectel, Lenta, Sberbank, and Rostelecom. Metascan attributed the leak to a former employee now working with a competitor and rejected claims of deliberately hidden vulnerabilities. The company has accepted full responsibility, outlined corrective measures, and launched a bug bounty program.
Unauthorized Access to Japan's Government Solution Service (GSS) Exposes 246,000 Personal Records via VPN Flaw
Japan's Digital Agency confirmed that its Government Solution Service (GSS) suffered unauthorized access after attackers exploited a vulnerability in VPN equipment used for external maintenance operations. The intrusion, believed to have begun in late May 2026, allowed threat actors to compromise maintenance accounts and access large volumes of files on internal servers. On June 25, 2026, security teams detected suspicious access to numerous files using a compromised account, prompting an investigation that concluded on July 9 with confirmation of the breach. Some files containing personal information may have been exfiltrated, affecting approximately 246,000 records of government officials, civil servants, contractors, and related individuals. The agency immediately disabled the affected accounts and severed external communications on July 9 but has not disclosed technical details of the exploited VPN vulnerability. The incident was reported by Security NEXT on September 11, 2026.