What's in the package
━━━━━━━━━━━━━━━━━━━━
pabau_dump/
├── all_emails.csv ← 479,715 unique patient/user emails
├── booking_settings.txt ← 1,842 clinics — full booking page config
├── notification_settings.txt ← 15,916 notification rules across 1,464 clinics
├── notification_toggles.txt ← 4,865 user ID → notification preference mappings
├── permission_groups.txt ← 2,160 access control groups with bitmasks
├── dashboards.txt ← 1,555 internal dashboards with sharing lists
├── object_fields.txt ← 1,179 DB schema field mappings
├── store_configs.txt ← 8 clinic online stores
└── graphql_schema.txt ← Full introspection — 808 queries, all types
──────────────────────────────────────────────────
THE DATA
──────────────────────────────────────────────────
Pabau is a SaaS CRM/EMR platform used by aesthetic clinics, medispas,
dermatologists, plastic surgeons, and private healthcare providers across
the UK and Europe. Think: the software that runs your local Botox clinic,
laser hair removal center, or private cosmetic surgery practice.
What came back:📧 479,715 UNIQUE EMAILS
All validated. No duplicates. These are real patients and clinic staff
who use the Pabau platform. Internal user IDs range from 63 to 16,366,091
showing the platform's growth over time. ~90K are UK-based (.co.uk, .nhs.uk,
.ac.uk). The rest span 24,154 unique domains across 70+ countries.
🏥 1,842 CLINIC BOOKING PAGES — FULL CONFIG
• Public booking URLs
• Header/footer messages (often contain clinic phone numbers and emails)
• Brand colors
• Privacy policy URLs → 393 clinics have real external policy links
• Full booking flags: whether deposits are required, cancellation policies,
rescheduling rules, minimum advance time, whether employee photos are shown
🔔 15,916 NOTIFICATION RULES
• Which notification types each clinic uses (new-appointment, lead-response,
appointment-reminder, cancelled, no-show, etc.)
• Whether email/SMS delivery is enabled per clinic
• Creation timestamps
🔑 2,160 PERMISSION GROUPS
• Group names like "Doctor", "Nurse Practitioner", "Pharmacist", "Finance"
• Full permission bitmasks across 11 system areas (clients, money, calendar,
marketing, inventory, analytics, team, setup, dashboard, leads, activities)
• Owner user IDs
📊 1,555 INTERNAL DASHBOARDS
• Dashboard names, owner user IDs, shared user lists
🗺️ FULL GRAPHQL SCHEMA INTROSPECTION
• 808 root-level queries mapped
• All type definitions, field names, argument names & types
• Confirms existence of: cmContact (patient PII records),
ContactMedicalCondition (medical conditions), SentPrescription,
findManyUser, UserPermission, ApiKey, OauthTokens
→ These tables returned auth errors at runtime, but the schema
disclosure alone is gold for targeting.
──────────────────────────────────────────────────
WHY THIS IS WORTH YOUR TIME
──────────────────────────────────────────────────
This isn't just another email dump. Here's what makes it actually useful:
1. MEDICAL CONTEXT — Every single email is tied to someone who visited,
works at, or registered with a cosmetic/medical clinic. You know their
provider. You know what services that provider offers. You know the
clinic's brand color and booking URL. This is targeted intel.
2. HIGH-VALUE TARGETS PEPPERED THROUGHOUT — I've already ID'd:
GOVERNMENT / PUBLIC SECTOR (549+)
├── 300 Trafford Council employees (single largest gov cluster)
├── 140 Luton Council employees
├── 2 FCDO diplomats (Foreign Office)
├── 4 UK Parliament staff (including Scottish Parliament)
├── 1 sitting UK judge (Her Honour Judge — ejudiciary.net)
├── 7 Ministry of Justice officials
├── 1 Crown Prosecution Service employee
├── 6 police officers (Met Police, Sussex, Herts, South Wales, Avon & Somerset)
├── 1 US State Department official (state.gov)
├── 1 US Navy civilian
└── 1 French Ministry of Culture employee
NHS / HEALTHCARE (885+)
├── 66 NHS trusts represented
├── Great Ormond Street Hospital
├── St George's Hospital London
└── NHS Lothian, NHS Wales, dozens more
ACADEMIA (1,872+)
├── Oxford University — 211 (Saïd Business School: 154)
├── UCL — 53
├── King's College London — 38
├── LSE — 16
└── 255+ other UK universities and colleges
CORPORATE (500+)
├── PwC — 142 employees
├── Deloitte — 28
├── KPMG — 19
├── Accenture — 11
├── Google, Apple, Meta, Microsoft, Amazon, LinkedIn, Spotify, Salesforce
├── HSBC, Barclays, RBS, Lloyds, Credit Suisse, Santander
├── McKinsey, BCG, Bain (including Bain's chairman)
├── Linklaters, Clifford Chance, Allen & Overy, Kirkland & Ellis,
│ Freshfields, Slaughter and May, White & Case, DLA Piper
├── AstraZeneca, GSK, Roche, Pfizer, Novartis, J&J, Merck, Bayer
└── Hermès, Dior, Louis Vuitton, Gucci, Burberry
MEDIA (179+)
├── BBC — 17 journalists/staff
├── ITV — 10
├── The Times, The Sun, New York Times
└── Sky, Reuters, Bloomberg, The Economist
INTERNATIONAL ORGS
├── WHO (World Health Organization) — 2
├── IOM (UN Migration) — 1
├── ESA (European Space Agency) — 1
├── Bank of England — 1
└── Interpol-adjacent domains
3. PASSWORD RESET AUTH TABLE — The email dump comes from the literal
password_reset_auth table. These aren't marketing list scrapes.
These are real authentication records. Spear-phishing gold.
4. CLINIC INTEL — 393 privacy policy URLs point to real clinic websites.
465 clinics have phone numbers in their booking messages. You can map
every email to a specific clinic's booking page and branding. Social
engineering has never been easier: "Hi, this is [Clinic Name] calling
about your upcoming appointment..."
5. PABAU INTERNAL — 1,540 @pabau.com accounts identified. Development
team appears heavily Balkan-based (Albanian/Kosovo/Macedonian names).
Internal permission structure fully mapped.
──────────────────────────────────────────────────
PRICE & TERMS
──────────────────────────────────────────────────
Price: Discussed in PM
Sample : https://pastebin.com/3j41V3sE
Escrow: Available via established forum escrow
Format: CSV + raw text dumps, clean and ready to import
Sample: Available on request for established members
Bulk discount: Considered for the full package
No splits. No trades. No "collabs." One buyer, one sale.
━━━━━━━━━━━━━━━━━━━━
pabau_dump/
├── all_emails.csv ← 479,715 unique patient/user emails
├── booking_settings.txt ← 1,842 clinics — full booking page config
├── notification_settings.txt ← 15,916 notification rules across 1,464 clinics
├── notification_toggles.txt ← 4,865 user ID → notification preference mappings
├── permission_groups.txt ← 2,160 access control groups with bitmasks
├── dashboards.txt ← 1,555 internal dashboards with sharing lists
├── object_fields.txt ← 1,179 DB schema field mappings
├── store_configs.txt ← 8 clinic online stores
└── graphql_schema.txt ← Full introspection — 808 queries, all types
──────────────────────────────────────────────────
THE DATA
──────────────────────────────────────────────────
Pabau is a SaaS CRM/EMR platform used by aesthetic clinics, medispas,
dermatologists, plastic surgeons, and private healthcare providers across
the UK and Europe. Think: the software that runs your local Botox clinic,
laser hair removal center, or private cosmetic surgery practice.
What came back:📧 479,715 UNIQUE EMAILS
All validated. No duplicates. These are real patients and clinic staff
who use the Pabau platform. Internal user IDs range from 63 to 16,366,091
showing the platform's growth over time. ~90K are UK-based (.co.uk, .nhs.uk,
.ac.uk). The rest span 24,154 unique domains across 70+ countries.
🏥 1,842 CLINIC BOOKING PAGES — FULL CONFIG
• Public booking URLs
• Header/footer messages (often contain clinic phone numbers and emails)
• Brand colors
• Privacy policy URLs → 393 clinics have real external policy links
• Full booking flags: whether deposits are required, cancellation policies,
rescheduling rules, minimum advance time, whether employee photos are shown
🔔 15,916 NOTIFICATION RULES
• Which notification types each clinic uses (new-appointment, lead-response,
appointment-reminder, cancelled, no-show, etc.)
• Whether email/SMS delivery is enabled per clinic
• Creation timestamps
🔑 2,160 PERMISSION GROUPS
• Group names like "Doctor", "Nurse Practitioner", "Pharmacist", "Finance"
• Full permission bitmasks across 11 system areas (clients, money, calendar,
marketing, inventory, analytics, team, setup, dashboard, leads, activities)
• Owner user IDs
📊 1,555 INTERNAL DASHBOARDS
• Dashboard names, owner user IDs, shared user lists
🗺️ FULL GRAPHQL SCHEMA INTROSPECTION
• 808 root-level queries mapped
• All type definitions, field names, argument names & types
• Confirms existence of: cmContact (patient PII records),
ContactMedicalCondition (medical conditions), SentPrescription,
findManyUser, UserPermission, ApiKey, OauthTokens
→ These tables returned auth errors at runtime, but the schema
disclosure alone is gold for targeting.
──────────────────────────────────────────────────
WHY THIS IS WORTH YOUR TIME
──────────────────────────────────────────────────
This isn't just another email dump. Here's what makes it actually useful:
1. MEDICAL CONTEXT — Every single email is tied to someone who visited,
works at, or registered with a cosmetic/medical clinic. You know their
provider. You know what services that provider offers. You know the
clinic's brand color and booking URL. This is targeted intel.
2. HIGH-VALUE TARGETS PEPPERED THROUGHOUT — I've already ID'd:
GOVERNMENT / PUBLIC SECTOR (549+)
├── 300 Trafford Council employees (single largest gov cluster)
├── 140 Luton Council employees
├── 2 FCDO diplomats (Foreign Office)
├── 4 UK Parliament staff (including Scottish Parliament)
├── 1 sitting UK judge (Her Honour Judge — ejudiciary.net)
├── 7 Ministry of Justice officials
├── 1 Crown Prosecution Service employee
├── 6 police officers (Met Police, Sussex, Herts, South Wales, Avon & Somerset)
├── 1 US State Department official (state.gov)
├── 1 US Navy civilian
└── 1 French Ministry of Culture employee
NHS / HEALTHCARE (885+)
├── 66 NHS trusts represented
├── Great Ormond Street Hospital
├── St George's Hospital London
└── NHS Lothian, NHS Wales, dozens more
ACADEMIA (1,872+)
├── Oxford University — 211 (Saïd Business School: 154)
├── UCL — 53
├── King's College London — 38
├── LSE — 16
└── 255+ other UK universities and colleges
CORPORATE (500+)
├── PwC — 142 employees
├── Deloitte — 28
├── KPMG — 19
├── Accenture — 11
├── Google, Apple, Meta, Microsoft, Amazon, LinkedIn, Spotify, Salesforce
├── HSBC, Barclays, RBS, Lloyds, Credit Suisse, Santander
├── McKinsey, BCG, Bain (including Bain's chairman)
├── Linklaters, Clifford Chance, Allen & Overy, Kirkland & Ellis,
│ Freshfields, Slaughter and May, White & Case, DLA Piper
├── AstraZeneca, GSK, Roche, Pfizer, Novartis, J&J, Merck, Bayer
└── Hermès, Dior, Louis Vuitton, Gucci, Burberry
MEDIA (179+)
├── BBC — 17 journalists/staff
├── ITV — 10
├── The Times, The Sun, New York Times
└── Sky, Reuters, Bloomberg, The Economist
INTERNATIONAL ORGS
├── WHO (World Health Organization) — 2
├── IOM (UN Migration) — 1
├── ESA (European Space Agency) — 1
├── Bank of England — 1
└── Interpol-adjacent domains
3. PASSWORD RESET AUTH TABLE — The email dump comes from the literal
password_reset_auth table. These aren't marketing list scrapes.
These are real authentication records. Spear-phishing gold.
4. CLINIC INTEL — 393 privacy policy URLs point to real clinic websites.
465 clinics have phone numbers in their booking messages. You can map
every email to a specific clinic's booking page and branding. Social
engineering has never been easier: "Hi, this is [Clinic Name] calling
about your upcoming appointment..."
5. PABAU INTERNAL — 1,540 @pabau.com accounts identified. Development
team appears heavily Balkan-based (Albanian/Kosovo/Macedonian names).
Internal permission structure fully mapped.
──────────────────────────────────────────────────
PRICE & TERMS
──────────────────────────────────────────────────
Price: Discussed in PM
Sample : https://pastebin.com/3j41V3sE
Escrow: Available via established forum escrow
Format: CSV + raw text dumps, clean and ready to import
Sample: Available on request for established members
Bulk discount: Considered for the full package
No splits. No trades. No "collabs." One buyer, one sale.
