All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Klaviyo data leak: Passwords shared with advertisers due to website bug

Created at 10 Aug · 2:36 PM1 source↑ Market-relevant
IN SHORT

Marketing tech firm Klaviyo inadvertently shared sign-up information, including passwords, with advertisers due to a website misconfiguration. The bug, active for an unknown period, potentially exposed data of new customers to third-party trackers.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

200known individuals affected
7 billioncustomer profiles managed by Klaviyo
205,000paying customers of Klaviyo

Who's Involved

Sam Jadali
Security researcher and co-founder of Melurna
Klaviyo
Marketing tech giant that experienced the data leak
Danielle Zanatta
Klaviyo spokesperson who confirmed the bug
Facebook
Advertising giant that potentially received leaked data
Google
Tech giant that potentially received leaked data
HubSpot
Marketing giant that potentially received leaked data
Microsoft
Tech giant that potentially received leaked data
LinkedIn
Microsoft subsidiary that potentially received leaked data
X
Social media site that potentially received leaked data
Klaviyo data leak: Passwords shared with advertisers due to website bug

↳ Why This Matters

The incident raises significant concerns about data privacy and security for Klaviyo's users and underscores the risks of third-party trackers embedded on websites, potentially exposing sensitive customer information to advertisers.

Key facts

  • Klaviyo's website sign-up form was misconfigured, sharing user data with third-party trackers.
  • Data shared included email addresses, passwords, company names, and website addresses.
  • Advertisers and tech giants like Facebook, Google, and Microsoft potentially received this data.
  • Klaviyo confirmed the issue was fixed and stated fewer than 200 individuals were affected.
  • The company did not publicly disclose the incident.

Marketing technology company Klaviyo inadvertently shared sensitive sign-up information, including customer passwords, with third-party advertisers due to a misconfigured website form. Security researcher Sam Jadali discovered the issue, which potentially exposed data of new customers to tech giants like Facebook, Google, Microsoft, and others.

Jadali stated the misconfiguration was present from at least February 2024 through November 2025, and possibly longer. The data shared included email addresses, passwords, company names, and website addresses. Klaviyo confirmed the bug has been fixed and stated that fewer than 200 individuals were affected, based on available logs. The company has notified the known affected individuals but has not publicly disclosed the incident.

This incident highlights the data risks associated with third-party website trackers when users do not employ defensive tools like ad-blockers. Similar security lapses involving misconfigured trackers have led to data breach disclosures and regulatory actions against companies in recent years.

Frequently asked questions

Klaviyo's website sign-up form was misconfigured, inadvertently sharing new customer data, including passwords, with third-party advertisers and tech companies.

Anyone who signed up for Klaviyo using the misconfigured form may have had their data shared with advertisers like Facebook, Google, and Microsoft.

Klaviyo stated that fewer than 200 individuals were affected, based on their readily available active logs.

No, it is unclear why Klaviyo did not publicly disclose the incident, although they did notify the known affected individuals.

What Happens Next

01Questions remain about the full duration of the bug and the total number of affected individuals.
02Klaviyo's internal log retention policies and the extent of their data breach notification process are unclear.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Security researcher Sam Jadali discovered a misconfiguration on Klaviyo's sign-up page.
The bug potentially shared new customer data, including passwords, with third-party advertisers.
Affected companies include Facebook, Google, HubSpot, Microsoft, and LinkedIn.
Klaviyo confirmed the bug was fixed and stated fewer than 200 individuals were affected based on logs.
The company notified affected individuals but did not disclose the incident publicly.

Sources

T1
Signed up for Klaviyo? Dozens of advertisers may have seen your passwordTechCrunch

Related Stories

Researcher's "noreply" domains reveal corporate data leaks
10 Aug · 2:31 PM
Waymo's rapid expansion is accompanied by an increase in operational glitches
10 Aug · 2:06 PM
UK manufacturers face rising hacking risk as survey shows 30% were hit last year
10 Aug · 5:16 AM
Amazon, Salesforce Lead in Tech Career Advancement, Study Finds
10 Aug · 8:21 AM
China's Long March 7A rocket explodes shortly after launch
10 Aug · 3:11 PM