> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# HeyPulse Database and Full Source Code Allegedly Leaked, Exposing French Small Business Clients
- URL: https://darkwebinformer.com/heypulse-database-and-full-source-code-allegedly-leaked-exposing-french-small-business-clients/
- Published: 2026-08-11T15:40:25.000Z
- Updated: 2026-08-11T15:40:25.000Z
- Author: Dark Web Informer
- Tags: Leaks

Breach Report ![France flag](https://flagcdn.com/w40/fr.png)France Marketing SaaS / SMB Point-Gated Download 

## HeyPulse Database and Full Source Code Allegedly Leaked, Exposing French Small Business Clients

A forum user posting as **slvsh3r** has published what they describe as the database and complete **source code** of **HeyPulse**, a French B2B marketing platform that runs prize-based games to help local businesses generate Google reviews and improve their visibility. The sample database shows client accounts for **restaurants, barbers, hair salons, and food outlets**, each with a business name, contact email, registration date, and password hash. The accompanying file tree covers the application's **authentication, billing, payment, email, and database layers**, with timestamps indicating the code was captured **within the past day**. The claim is **unverified**.

Severity HIGH 

Also takenSource code

Passwordsbcrypt

CaptureWithin a day

Actorslvsh3r

### ▣Post details

TargetHeyPulse

Country![France flag](https://flagcdn.com/w40/fr.png)France

SectorMarketing SaaS

ListingPoints to unlock

ClientsLocal businesses

DataClient accounts and codebase

ObservedAug 11, 2026

Actorslvsh3r

### !Allegedly included

- Business names
- Contact email addresses
- bcrypt password hashes
- Registration timestamps
- Account status flags
- Application source code
- Configuration files
- Payment integration code
- Authentication middleware
- Database layer
- Mail delivery components
- Review & prize modules

### ◱Screenshots

[ ![HeyPulse French marketing platform database and source code leak screenshot, August 2026 (1 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759823.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759823.png) [ ![HeyPulse French marketing platform database and source code leak screenshot, August 2026 (2 of 2)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759824.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/37298578926356897235879623968759824.png) 

### ⚠Potential impact

The client records are limited and the passwords use **bcrypt**, which is sound practice and makes bulk recovery impractical. The **source code is the real exposure**. The file listing includes configuration, payment, mail, and database components, the places where credentials and API keys are conventionally stored, so **live secrets should be assumed present until the operator confirms otherwise**. The tree also shows **three separate authentication middleware files** alongside debug and test scripts, a pattern that often indicates inconsistent access control and gives any reader a map for finding it. Client businesses face a smaller but real reputational question, since the platform's function concerns review generation.

### iStatus

Unverified 

Samples are published from both the database and the codebase, which is **more substantiation than most listings offer**. File timestamps run to the day of posting, suggesting access was **current at the time of capture** rather than historical. Dark Web Informer is **not reproducing the archive password or contact route**. The account is established with high standing. Nothing has been independently corroborated. The claim is **unverified** and HeyPulse has not publicly addressed it.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE