Klaviyo Bug May Have Exposed New Users’ Passwords to Advertisers
3 min read
A security flaw on marketing technology company Klaviyo’s website may have exposed sensitive sign-up information, including passwords, to outside advertisers and technology companies for more than a year.
Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, told TechCrunch that Klaviyo’s sign-up form was incorrectly configured from at least February 2024 through November 2025. The issue may have existed for even longer.
According to Melurna’s research, people who created a Klaviyo account through the affected sign-up form may have had their registration information sent to third-party companies whose tracking technologies were installed on Klaviyo’s website.
That information reportedly included users’ email addresses and passwords, along with details such as their company name, website address and phone number.
The data was potentially shared with a number of major technology and advertising companies. The list included Facebook and Google, marketing platform HubSpot, Microsoft and its LinkedIn subsidiary, social media platform X, and others.
Melurna provided its findings to TechCrunch ahead of a presentation at the Def Con security conference in Las Vegas.
Klaviyo has since fixed the website issue. However, the company has not disclosed how many people may have been affected over the entire period that the problem was active.
The Boston-based company provides marketing tools that businesses use to send campaigns through email, text messages and other channels. Klaviyo says it has 205,000 paying customers and manages more than seven billion customer profiles.
Klaviyo spokesperson Danielle Zanatta confirmed to TechCrunch that the incident resulted from an “application configuration issue.” The company said its available active logs indicate that fewer than 200 known individuals were affected.
That figure, however, comes with an important limitation. Klaviyo would not say how far back its logs go or exactly how long the problematic configuration remained active. As a result, the total number of people whose information may have been exposed remains unclear.
The incident highlights a broader privacy problem involving website tracking technologies.
These tools, commonly called “pixels,” are widely used by websites and apps to understand how visitors interact with their services, measure performance and identify technical problems. But when tracking systems are incorrectly configured, they can sometimes collect and transmit information that users enter into web forms.
That creates a potential security risk when sensitive information is submitted on a page containing third-party trackers.
Similar problems involving improperly configured pixels have emerged in recent years, with some incidents leading companies to file data breach disclosures and regulators taking enforcement action.
Klaviyo said it had contacted the individuals it knows were affected by the incident. However, the company declined to provide TechCrunch with a copy of the notification it reportedly sent to those customers.
The company also did not publicly explain why it had not disclosed the incident more broadly.
For users, the episode serves as another reminder that information entered into a website may not always stay only with the company operating that site. Third-party tracking technologies can create additional pathways through which data is collected and shared, particularly when websites fail to properly isolate sensitive form information.
Also read :TechCrunch Disrupt 2026 Offers Final $100 Flash Discoun
