Klaviyo Bug Exposed New User Passwords to Facebook, Google, and Other Advertisers

Marketing technology company Klaviyo inadvertently shared the passwords and personal information of new sign-ups with dozens of third-party advertisers due to a misconfigured web form on its sign-up page, newly published security research has revealed.

The misconfiguration was active from at least February 2024 through November 2025, though possibly longer, according to Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna. Jadali shared the findings with TechCrunch ahead of a presentation at the Def Con security conference in Las Vegas.

The exposed data included new customers’ email addresses and passwords, along with their company name, website address, and phone number. This information was transmitted to third-party trackers — known as “pixels” — embedded on Klaviyo’s website, belonging to companies including Facebook, Google, HubSpot, Microsoft, LinkedIn, and X.

Klaviyo, a Boston-based company that serves 205,000 paying customers and manages over seven billion customer profiles, confirmed to TechCrunch that it fixed the bug, describing it as an “application configuration issue.” Spokesperson Danielle Zanatta said the number of known affected individuals was fewer than 200, “based on our readily available active logs.” The company declined to say how far back its logs extend or how long the bug was active, leaving the full scope of the leak unclear.

Klaviyo said it notified the known affected individuals but would not provide TechCrunch with a copy of that communication. The company did not publicly disclose the incident, and it remains unclear why.

The incident highlights the data risks that misconfigured third-party pixel trackers can pose to website users. In recent years, similar lapses at other companies have prompted data breach disclosures and regulatory enforcement action. Security researchers note that tools such as ad-blockers may help users limit exposure to such trackers.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top