Briev
Live
Technology

Klaviyo flaw exposed passwords of new users to major ad platforms

Security researcher Sam Jadali discovered that a misconfigured sign-up form on Klaviyo’s website leaked customers' passwords and other details to third-party advertisers.

Researcher Sam Jadali, co-founder of the cybersecurity startup Melurna, reported that Klaviyo’s sign-up page was incorrectly configured for a period spanning from February 2024 to November 2025, potentially longer. During that window, the form transmitted sign-up data—including email addresses, passwords, company names, website URLs and phone numbers—to a range of embedded third-party trackers used by advertising giants such as Facebook, Google, HubSpot, Microsoft, LinkedIn and X. Klaviyo, which serves about 205,000 paying customers and manages over seven billion profiles, acknowledged the bug as an application configuration issue and said it has now been corrected.

The firm indicated that fewer than 200 people appear in its readily available active logs and that those users were notified, though it declined to share the notification text. The breach underscores how mismanaged tracking pixels can expose sensitive user information, adding to recent similar incidents that have prompted regulatory scrutiny. Klaviyo has not disclosed how far back its logs extend or the exact duration of the vulnerability.

Why it matters

It shows how simple website misconfigurations can expose passwords and personal data to major advertisers.

In this story

data breachpassword leakthird-party trackersapplication configuration issueadvertising giantsuser privacysecurity research