IT·SCIENCE

'My pre-surgery photos were leaked — and all I got was 50,000 points?' Data breach hits 220,000 Gangnam Unni users; CEO summoned to national audit

by
Ko Jae-woo
Published : Oct. 2, 2026 - 18:40:00
    • Copy Completed!

View Korean Original

A before-and-after cosmetic surgery illustration [Generated with ChatGPT AI]
A before-and-after cosmetic surgery illustration [Generated with ChatGPT AI]

"My pre-surgery photos were leaked — and the compensation is 50,000 points." (A post by a Gangnam Unni user on an online community)

Hong Seung-il, chief executive of Healing Paper, the company behind beauty and cosmetic surgery platform Gangnam Unni, will appear before this year's national audit after a hacking incident exposed the personal information of roughly 220,000 users in South Korea and abroad. Sensitive data — including pre-surgery photos and details of medical consultations — was among the information stolen.

The National Assembly's Political Affairs Committee adopted Hong as a witness for the national audit scheduled for Oct. 13, the Assembly said Friday.

Earlier this month, personal information belonging to 219,665 members of the Gangnam Unni platform was leaked — approximately 160,000 in South Korea, about 48,000 in Japan, 4,218 in Taiwan, 1,591 in Thailand, 481 in China, and 5,308 in English-speaking and other countries. Healing Paper reported the breach to the Personal Information Protection Commission and other authorities.

The leaked data included names (219,640 users), mobile phone numbers (208,040), email addresses (31,473), dates of birth and gender (219,646), country and region of residence (8,820), device information, IP addresses, and service usage and access records (219,536), order and purchase identification numbers (147,514), and the names of medical institutions consulted and the content of consultation requests (219,665).

Particularly sensitive medical consultation data was also widely exposed, including photos taken before procedures and details of surgical sites.

Information on desired surgeries or procedures was leaked for 203,516 users, while photos submitted during consultations and the reasons for seeking consultations were exposed for 1,670 users.

Additional data compromised in the breach included: clinic visit and consultation records, procedure and surgery status, scheduled procedure dates, and appointment details (219,665 users); information on paid procedure products, payment methods, and point usage (202,681 users); social login identification numbers (391 users); the names and contact details of the person who made the payment (452 users); and the name and contact details of the visitor (1 user).

Hong Seung-il, CEO of Healing Paper. [Provided by Healing Paper]
Hong Seung-il, CEO of Healing Paper. [Provided by Healing Paper]

Despite the exposure of highly sensitive data — including pre-surgery photos — critics say the company's response has fallen short of meaningful accountability.

Healing Paper offered affected users 50,000 points ($37) on the Gangnam Unni platform and one year of free identity protection insurance covering hacking and phishing-related damages, but many users have complained that the compensation is inadequate given the scale and sensitivity of the breach.

The national audit is expected to focus on the cause of the data leak, the extent of the company's liability, and measures to prevent a recurrence.

Meanwhile, the incident has cast a shadow over Healing Paper's otherwise strong growth trajectory. The company posted sales of about 75.22 billion won ($55.3 million) last year, up from about 53.01 billion won the year before, while operating profit came in at about 7.54 billion won, down from about 12.86 billion won the prior year. The decline in operating profit reflected increased hiring and salaries, an office relocation, and higher brand marketing costs. In February last year, the company also raised 42.8 billion won in a Series C funding round.

In a statement, Hong apologized for the incident. "When I think of the anxiety, worry, and disappointment our customers must have felt because of this incident, all of us at the company feel a deep sense of responsibility," he said. "I sincerely apologize again, and we will treat the protection of our customers' personal information as our highest priority and devote every effort to preventing a recurrence."


ko@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ