SHINDO4

Unni (Gangnam Unni)

Unauthorized accessSize not disclosed

LEAK CONFIRMEDHealth / medical / treatment / Payment data (unspecified)Contained

Open in the live monitor ▶
Disclosed
Sep 7, 2026
Detected
Sep 4, 2026
Detection to disclosure
3 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Compensation offered

What leaked

IdentityFull name
ContactPhone number, Email address
Transactions & activityBooking and consultation information, Booking and consultation information
Financial & paymentPayment information
Special-care dataTreatment information

Who is affected

  • Members

Cause

Unauthorized access to an integration function (API) for looking up consultation history. A repeat attempt via a different route occurred on 9/5

Timeline

  1. Intrusion began
  2. Detected
  3. Contained
  4. Intrusion stopped
  5. Repeat attempt via a different route
  6. Reported to authority
  7. First disclosure
  8. Individuals notified
  9. First disclosure
  10. Company issued an update

Response

  • Blocked the entry point
  • MFA
  • Forensic investigation
  • New detection
  • External audit

Strengthened multi-factor authentication, introduced an anomaly detection system, security audit of all APIs and databases by outside experts

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Check authorization on every API call and detect and stop bulk pulls
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources