Exposed data includes sensitive consultation details and photos
How would you feel if records of your cosmetic surgery consultation — including the procedure you were considering, the doctor you wanted to see and even photographs you shared — were leaked?
For about 220,000 users of Gangnam Unni, South Korea’s leading platform for cosmetic and plastic surgery procedures, that is now a possibility.
The platform’s operator, Healing Paper, said Tuesday that personal information belonging to 219,665 users was exposed in a data breach. The affected users include about 160,000 in South Korea and 48,000 in Japan, as well as users in Taiwan, Thailand, China and other countries.
The leaked data included names, phone numbers, email addresses, dates of birth, gender, countries or regions of residence, social media login IDs, IP addresses and device information.
The breach also exposed more sensitive consultation details, including procedure and hospital names, doctors, preferred appointment times, reasons for seeking consultations, consultation status and photos.
Healing Paper said an unauthorized party accessed its consultation records Thursday through an application programming interface, resulting in the exposure of some customer data. The access was blocked, but the same attacker was later found to have tried to breach the system through a different channel Friday.
Concerns are mounting that the leaked information could lead not only to privacy violations but also to phishing scams.
The company posted an apology on its website and notified all affected users individually. It also added a feature allowing users to check which of their personal data was leaked, which will remain available for 30 days.
"We take this incident with the utmost seriousness. We sincerely apologize again to our customers who have trusted and used Gangnam Unni," Healing Paper CEO Hong Seung-il said in a statement.
cjh@heraldcorp.com


