HealingPaper, operator of the beauty-medical platform Gangnam Unni, has notified about 220,000 users that personal information was exposed after unauthorized access to its systems. Korean reports say the affected data included consultation and reservation records and, for some users, details tied to actual procedures and consultation images. That makes the incident more sensitive than a breach limited to names or contact details.

The breach carries more than a password-reset risk

The company said it detected abnormal access on September 4 through an application programming interface used to retrieve consultation information. It blocked that route after spotting the activity, but reports say the same attacker attempted access through another path the following day. The company has since notified affected users and warned about possible secondary harm.

The practical risk is targeted impersonation. A scammer who knows which clinic a person contacted, what procedure they discussed or when a booking occurred can make a fake message or payment request look much more credible. Consultation images or treatment history also create a privacy cost that cannot be solved simply by changing a password.

The incident now turns on how precisely HealingPaper can identify what each user lost and whether access controls around connected services were sufficient. Users need clear information about which fields were exposed, whether payment or authentication data was involved and what suspicious messages they should treat as high risk.

Regulatory scrutiny is also likely to focus on the sequence of the intrusion. Blocking one route did not end the attackerโ€™s attempts, according to the company account reported in Korean media. Useful follow-up reporting should explain how the second access path worked, what has been changed and whether further exposure has been ruled out.