Klaviyo leaked sign-up passwords to advertisers – Claril Noticias

Marketing technology giant Klaviyo inadvertently leaked the passwords and sign-up details of its new customers to third-party advertisers due to a website form misconfiguration active between February 2024 and November 2025.

How the security flaw was uncovered

Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, identified that the web form on Klaviyo’s sign-up page was compromised for nearly two years, and potentially longer. The startup shared these findings ahead of a scheduled presentation at the Def Con security conference in Las Vegas.

According to Melurna’s testing, any user who registered for Klaviyo’s services using the faulty form had their credential data transmitted directly to external advertising networks and tech firms whose tracking tools were embedded on the registration page.

Which tech giants received the leaked data?

The exposed information went far beyond basic contact details. It included highly sensitive user passwords, email addresses, company names, website URLs, and telephone numbers. This private data was transmitted to major advertising and technology platforms, including Google, Meta’s Facebook, HubSpot, Microsoft, LinkedIn, and X (formerly Twitter).

The hidden dangers of marketing pixels

This incident highlights the significant privacy risks associated with third-party tracking pixels when defensive tools like ad-blockers are not utilised. Pixels are small snippets of code designed to help website owners analyse user behaviour, track app performance, and detect software bugs. However, when poorly configured, these trackers can harvest and transmit sensitive personal data entered into web forms.

In recent years, similar tracking pixel errors have forced numerous organisations to issue formal data breach notifications and have triggered strict enforcement actions from global privacy regulators.

Klaviyo’s response and lingering concerns

Klaviyo spokesperson Danielle Zanatta confirmed that the leak stemmed from an “application configuration issue” and stated that the bug has now been resolved. According to Zanatta, the company’s active logs indicate that fewer than 200 individuals were affected by the exposure. However, the Boston-based firm declined to clarify how far back its active logs extend or the exact duration of the security vulnerability.

Although Klaviyo claims to have contacted the affected users directly, the company refused to share a copy of the notification sent to those customers. Furthermore, the marketing firm has not publicly disclosed the incident on its platforms.

Based in Boston, Klaviyo serves over 205,000 paying clients, enabling them to run marketing campaigns across email, SMS, and other digital channels. The company’s website claims it manages more than seven billion individual customer profiles.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *