France
Marketing SaaS / SMB
Point-Gated Download
HeyPulse Database and Full Source Code Allegedly Leaked, Exposing French Small Business Clients
A forum user posting as slvsh3r has published what they describe as the database and complete source code of HeyPulse, a French B2B marketing platform that runs prize-based games to help local businesses generate Google reviews and improve their visibility. The sample database shows client accounts for restaurants, barbers, hair salons, and food outlets, each with a business name, contact email, registration date, and password hash. The accompanying file tree covers the application's authentication, billing, payment, email, and database layers, with timestamps indicating the code was captured within the past day. The claim is unverified.
▣Post details
France!Allegedly included
- Business names
- Contact email addresses
- bcrypt password hashes
- Registration timestamps
- Account status flags
- Application source code
- Configuration files
- Payment integration code
- Authentication middleware
- Database layer
- Mail delivery components
- Review & prize modules
◱Screenshots
⚠Potential impact
The client records are limited and the passwords use bcrypt, which is sound practice and makes bulk recovery impractical. The source code is the real exposure. The file listing includes configuration, payment, mail, and database components, the places where credentials and API keys are conventionally stored, so live secrets should be assumed present until the operator confirms otherwise. The tree also shows three separate authentication middleware files alongside debug and test scripts, a pattern that often indicates inconsistent access control and gives any reader a map for finding it. Client businesses face a smaller but real reputational question, since the platform's function concerns review generation.
iStatus
UnverifiedSamples are published from both the database and the codebase, which is more substantiation than most listings offer. File timestamps run to the day of posting, suggesting access was current at the time of capture rather than historical. Dark Web Informer is not reproducing the archive password or contact route. The account is established with high standing. Nothing has been independently corroborated. The claim is unverified and HeyPulse has not publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE