DMR News

Advancing Digital Conversations

Klaviyo Sign-Up Bug Exposed Customer Passwords to Third-Party Trackers

ByJolyen

Aug 12, 2026

Klaviyo Sign-Up Bug Exposed Customer Passwords to Third-Party Trackers

Marketing technology company Klaviyo inadvertently shared some new customers’ sign-up information, including passwords, with third-party advertising and technology companies because of a configuration error on its website. Klaviyo confirmed the issue has been fixed and said fewer than 200 people are known to have been affected based on the active logs available to the company.

Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, said the affected sign-up form was misconfigured from at least February 2024 through November 2025, and possibly for longer. The research was presented at the Def Con security conference in Las Vegas.

The exposed information included email addresses, passwords, company names, website addresses and phone numbers. According to the research, third-party trackers embedded on Klaviyo’s website could receive the information when customers submitted the form.

Trackers Could Receive Sign-Up Details

The companies whose tracking technology could receive the data included Google, Facebook, HubSpot, Microsoft, LinkedIn and X, among others. Jadali said the issue did not require an attacker to break into Klaviyo because the website itself was transmitting information through its existing tracking setup.

Website trackers, often called pixels, are commonly used to measure visitor activity, advertising performance and software problems. Configuration errors can cause information entered into web pages to be transmitted alongside the data those systems are intended to collect.

Klaviyo spokesperson Danielle Zanatta told TechCrunch that the problem resulted from an “application configuration issue.” The company said it notified the known affected customers but did not disclose how long its available logs extend or provide a copy of the notification when requested.

Full Number of Affected Users Remains Unclear

Klaviyo said fewer than 200 individuals are known to have been affected, but that figure is based only on its readily available active logs. The company did not specify how long those logs are retained, leaving the total number of people whose information may have been exposed during the full period unclear.

Klaviyo provides email, text message and other marketing tools to more than 205,000 paying customers and says its platform manages more than seven billion customer profiles. The company’s security guidance advises customers to use unique passwords and change them immediately when compromise is suspected.

Similar problems involving misconfigured tracking technologies have previously led companies to disclose data breaches and attracted regulatory action. Jadali said the Klaviyo case illustrates how personal information can be exposed through ordinary analytics infrastructure without a conventional intrusion.


Featured image credits: creativecommons.org

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *