LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Wonjin Plastic Surgery Listed by Black X Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Wonjin Plastic Surgery Listed by Black X Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 2, 2026
Wonjin Plastic Surgery Listed by Black X Ransomware Group

Occurred April 2026 · publicly disclosed June 2, 2026.

HIGH
Severity
June 2, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Wonjin Plastic Surgery was listed by the Black X ransomware group on June 02, 2026, after internal files were exfiltrated in a ransomware attack. Individuals connected to the clinic should check whether their data was exposed and take protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Public information shows that on June 02, 2026, Wonjin Plastic Surgery was listed by the Black X ransomware group. The listing states that internal files were exfiltrated during a ransomware attack. The number of people affected is not known, and no further details on the incident have been released by the organization or independent sources.

Individuals who have received treatment or worked at the clinic may now face uncertainty about whether their information was among the files taken. Medical providers hold records that can include personal identifiers and health details, so any confirmed exposure would carry practical consequences for privacy and potential misuse.

Inside the incident

The only reported detail is the Black X listing itself, which claims internal files were removed. No information has been made public about when the attack occurred, how access was gained, how much data was involved, or whether the files were later published. The organization has not issued a statement confirming or denying the claims.

The group behind it: Black X

The Black X ransomware group is the entity that placed Wonjin Plastic Surgery on its leak site. The group claims the exfiltration took place as part of a ransomware operation. Public reporting on this actor describes a pattern of targeting organizations and using leak sites to draw attention to stolen data, though no verified details specific to this listing beyond the claim have been confirmed.

Wonjin Plastic Surgery and its sector

Wonjin Plastic Surgery operates as a medical clinic providing surgical and related services. Organizations in this sector routinely collect and store patient registration data, medical histories, treatment records, and billing information to deliver care and manage appointments. A breach at such a facility is consequential because the records often contain information that cannot be changed, such as health details and identification numbers.

What was likely exposed

The listing refers only to “internal files exfiltrated in ransomware attack.” The precise contents of those files have not been disclosed. Clinics of this type commonly hold patient names, contact information, dates of birth, medical notes, procedure records, and payment data, but it remains unconfirmed whether any of these categories were present in the exfiltrated material.

Why it matters

Exposed medical and personal records can be used for identity-related fraud or targeted scams. Patients may need to monitor financial accounts and insurance statements for unusual activity over an extended period. For the organization, the incident adds operational and reputational costs while it addresses any required notifications or security improvements.

What to do if you're exposed

Review statements from Wonjin Plastic Surgery for any official guidance. Change passwords on associated accounts and enable multi-factor authentication where available. Request a copy of your medical records to verify their accuracy. Readers can run a free exposure scan of their email address to check whether their information appears in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyWonjin Plastic Surgery security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Wonjin Plastic Surgery’s full breach history →

More recent breaches

Daechang Solution Listed by Black X Ransomware GroupJune 13, 2026sanaa hospital Listed by Black X Ransomware GroupJuly 29, 2026Tong Kong E & E Sdn Bhd (95907X) Listed by Black X Ransomware GroupJuly 29, 2026sanaa Listed by Black X Ransomware GroupJuly 16, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Wonjin Plastic Surgery Listed by Black X Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by black-x — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram