Klaviyo Users Warned: Your Password May Have Been Exposed to Advertisers

0
6

Key Takeaways

  • A misconfigured sign‑up form on Klaviyo’s website inadvertently transmitted new customers’ personal data—including passwords—to third‑party trackers from February 2024 through at least November 2025.
  • The exposed information comprised email addresses, passwords, company names, website URLs, and phone numbers, and was shared with major advertisers and tech platforms such as Facebook, Google, HubSpot, Microsoft/LinkedIn, and X (formerly Twitter).
  • Security researcher Sam Jadali of Melurna discovered the flaw and shared the findings with TechCrunch ahead of a Def Con presentation; Klaviyo later confirmed the bug was fixed and said fewer than 200 known individuals were affected based on its active logs.
  • The incident highlights the risks posed by uncontrolled website pixels and underscores the need for defensive measures like ad‑blockers, strict tracker governance, and prompt public disclosure when data leaks occur.

Overview of the Incident
Klaviyo, a Boston‑based marketing technology firm that serves over 205,000 paying customers and manages roughly seven billion consumer profiles, operated a sign‑up form on its website that was incorrectly configured. Between February 2024 and at least November 2025, the form transmitted the personal information entered by new users to any third‑party tracker embedded on the same page. This meant that passwords, email addresses, company details, and contact numbers were inadvertently shared with external advertisers and analytics services each time someone completed the registration process.

Researcher’s Findings
Sam Jadali, a security researcher and co‑founder of the cybersecurity startup Melurna, identified the misconfiguration during routine testing of Klaviyo’s web properties. Jadali told TechCrunch that the bug likely persisted for longer than the documented window, though concrete evidence only covered the February 2024–November 2025 period. He responsibly disclosed the issue to Klaviyo and subsequently shared the details with TechCrunch ahead of his scheduled talk at the Def Con security conference in Las Vegas, underscoring the importance of independent security research in catching subtle data‑exposure flaws.

Scope of Data Exposed
The data that leaked through the misconfigured form included the full set of fields typically collected during a Klaviyo sign‑up: the user’s email address, password, company name, company website URL, and phone number. Because the form was a gateway for new customers to begin using Klaviyo’s email‑and‑SMS marketing platform, the exposed credentials could grant attackers direct access to marketing accounts, potentially enabling unauthorized campaign sending, data theft, or further credential‑stuffing attacks against other services where users reuse passwords.

Third‑Party Recipients
The inadvertently shared information was routed to any third‑party tracker present on Klaviyo’s sign‑up page at the moment of submission. Jadali’s testing showed that the data reached major advertising and technology platforms, including Facebook (Meta), Google, HubSpot, Microsoft (and its subsidiary LinkedIn), and X (formerly Twitter). Numerous other ad‑tech vendors and analytics services that embed pixels on the page also received the data, illustrating how a single misconfiguration can expose user information to a broad ecosystem of external parties.

Impact on Users
Klaviyo told TechCrunch that, based on its readily available active logs, fewer than 200 individuals were known to have been affected by the leak. The company did not disclose how far back its logs extend, nor did it provide an exact timeline for when the bug first appeared, leaving open the possibility that the actual number of impacted users could be higher. Klaviyo’s customer base includes tens of thousands of businesses that rely on the platform for marketing automation, so even a limited exposure could have reputational and operational repercussions for those affected firms.

Company Response and Remediation
When contacted by TechCrunch, Klaviyo spokesperson Danielle Zanatta confirmed that the issue stemmed from an “application configuration issue” and that the bug had been remedied. Klaviyo stated it had notified the known affected individuals, though it declined to furnish a copy of the notification when asked. The firm also noted that it would not publicly disclose the incident beyond the direct communications to those users, a decision that raises questions about transparency and the adequacy of its breach‑response practices under emerging privacy regulations.

Regulatory and Industry Context
Klaviyo’s lapse fits a growing pattern of data‑exposure incidents caused by misconfigured website trackers, often referred to as “pixels.” Over the past few years, several companies have filed breach disclosures and faced regulatory scrutiny after similar pixel‑misconfiguration errors allowed personal data to leak to advertisers, analytics firms, or social‑media platforms. Regulators such as the FTC and European data‑protection authorities have emphasized that organizations remain responsible for protecting data collected through third‑party tools, even when the leakage originates from a vendor’s script.

Technical Explanation of Pixel Misconfiguration
Website pixels are snippets of JavaScript code supplied by advertisers, analytics providers, or social platforms that collect behavioral data—such as page views, clicks, and form interactions—for purposes like ad targeting, conversion measurement, and performance optimization. When a pixel is placed on a page, it typically gains access to the DOM and can read any user‑entered data in visible form fields. If the website’s form‑handling logic does not isolate or sanitize this data before the pixel fires, the pixel may inadvertently transmit sensitive inputs (including passwords) to its own servers, effectively turning a benign analytics tool into a data‑exfiltration channel.

Broader Implications for Web Security
The Klaviyo case underscores the necessity of treating third‑party trackers as privileged code that must be vetted, monitored, and, where possible, sandboxed. Organizations should adopt a defense‑in‑depth approach: employ Content Security Policy (CSP) headers to restrict which domains can execute scripts, use Subresource Integrity (SRI) checks for third‑party assets, and regularly audit the data flowing to each tracker. End‑users can mitigate risk by using ad‑blockers or privacy‑focused browser extensions that prevent unwanted pixels from loading, though the primary responsibility remains with the website operator to secure its own forms and data flows.

Outstanding Questions and Next Steps
Several uncertainties linger despite Klaviyo’s remediation. The exact duration of the vulnerability, the total number of users whose credentials were exposed, and the nature of any follow‑up assistance offered to affected customers remain undisclosed. Additionally, the decision not to issue a public breach notice may conflict with emerging disclosure requirements under laws such as GDPR, CCPA, and forthcoming U.S. federal privacy legislation. Moving forward, Klaviyo—and similar platforms—should consider publishing a transparent post‑mortem, offering affected users identity‑theft mitigation services, and implementing stricter change‑management controls to prevent recurrence of configuration‑driven data leaks.


This summary consolidates the publicly reported facts about Klaviyo’s misconfigured sign‑up form, the scope of the exposed data, the response from the company and the security researcher, and the broader lessons for website security and privacy compliance.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here