Key facts
- Klaviyo's website sign-up form was misconfigured, sharing user data with third-party trackers.
- Data shared included email addresses, passwords, company names, and website addresses.
- Advertisers and tech giants like Facebook, Google, and Microsoft potentially received this data.
- Klaviyo confirmed the issue was fixed and stated fewer than 200 individuals were affected.
- The company did not publicly disclose the incident.
Marketing technology company Klaviyo inadvertently shared sensitive sign-up information, including customer passwords, with third-party advertisers due to a misconfigured website form. Security researcher Sam Jadali discovered the issue, which potentially exposed data of new customers to tech giants like Facebook, Google, Microsoft, and others.
Jadali stated the misconfiguration was present from at least February 2024 through November 2025, and possibly longer. The data shared included email addresses, passwords, company names, and website addresses. Klaviyo confirmed the bug has been fixed and stated that fewer than 200 individuals were affected, based on available logs. The company has notified the known affected individuals but has not publicly disclosed the incident.
This incident highlights the data risks associated with third-party website trackers when users do not employ defensive tools like ad-blockers. Similar security lapses involving misconfigured trackers have led to data breach disclosures and regulatory actions against companies in recent years.
