Signed up for Klaviyo? Dozens of advertisers may have seen your password

← Back to the feed

Signed up for Klaviyo? Dozens of advertisers may have seen your password

TechCrunch · 2 hours ago

Security researchers have found that marketing platform Klaviyo was inadvertently sharing new customers' sign-up details, including passwords, with outside advertisers due to a misconfigured web form. The flaw, identified by Sam Jadali of cybersecurity startup Melurna, exposed data to third-party trackers embedded on Klaviyo's site, including those run by Facebook, Google, HubSpot, Microsoft, LinkedIn and X, raising fresh concerns about the risks posed by poorly configured advertising trackers, or "pixels", on company websites.

The bug was reportedly active from at least February 2024 until it was fixed in November 2025, potentially exposing sign-up data such as email addresses, passwords, company names, website addresses and phone numbers. Klaviyo, which serves 205,000 paying customers and manages over seven billion customer profiles, told TechCrunch that fewer than 200 people were known to be affected based on its available logs, though it would not disclose how long those logs are retained or confirm the true scale or duration of the exposure. The company said it notified affected individuals but did not publicly disclose the incident, and declined to share the notification it sent to customers.

  • Klaviyo's sign-up form leaked passwords to advertisers via misconfigured trackers.
  • Bug ran from at least February 2024 to November 2025.
  • Klaviyo says under 200 known victims, but scope remains unclear.

Art Culture

Read the full article at the source →