Truth that Matters. Stories that Impact

Truth that Matters. Stories that Impact

Technology

Klaviyo Website Bug Exposed New User Passwords to Third-Party Advertisers

Marketing technology platform Klaviyo inadvertently shared the sign-up details of new customers—including passwords, email addresses, and phone numbers—with third-party advertising and technology companies due to a website configuration issue, according to cybersecurity research.

What Happened

Security findings revealed by Melurna co-founder Sam Jadali indicated that a web form on Klaviyo’s sign-up page was misconfigured from at least February 2024 through November 2025, and potentially longer. Research testing showed that when individuals registered using the affected form, their entered credentials and business information were sent to third-party tech platforms whose trackers were embedded across the website.

The exposed data included customers’ passwords, email addresses, business names, website addresses, and contact phone numbers. The third-party companies receiving data through these embedded trackers included Google, Facebook, Microsoft and LinkedIn, HubSpot, and social media platform X, among others.

Klaviyo spokesperson Danielle Zanatta confirmed the incident was caused by an “application configuration issue” and stated that the vulnerability has been resolved. Zanatta reported that fewer than 200 known individuals were affected based on the company’s readily available active logs. However, the company declined to state how far back those active logs extend or provide an exact timeline for how long the misconfiguration persisted on its website.

Key Highlights

  • Exposed Information: User passwords, emails, phone numbers, company names, and website addresses were inadvertently sent to external trackers during registration.
  • Third Parties Involved: Tracking pixels belonged to major tech and ad companies, including Google, Facebook, HubSpot, Microsoft, LinkedIn, and X.
  • Scope and Duration: Melurna’s tests found the issue was active from at least February 2024 to November 2025; Klaviyo identified fewer than 200 affected users in its current active logs.
  • Remediation: Klaviyo confirmed it patched the misconfiguration and stated it notified the known affected users.

Why This Matters

The incident highlights the ongoing security and privacy challenges posed by third-party tracking pixels on corporate websites. While website owners often deploy tracking pixels to monitor application usage and diagnose technical errors, misconfigurations can cause these tools to ingest and transmit sensitive user inputs directly from web forms to outside vendors. In the marketing sector, where companies like Boston-based Klaviyo manage extensive communication pipelines for over 205,000 paying clients and billions of customer profiles, unaddressed tracker leakage can expose sensitive administrative credentials.

What to Watch Next

Additional details regarding the vulnerability are scheduled to be presented by Melurna at the Def Con security conference in Las Vegas. While Klaviyo stated it communicated with the identified affected individuals, the company has not publicly released the customer notification or clarified its historical data log retention policies.

Frequently Asked Questions

What caused the data exposure on Klaviyo’s platform?

The exposure resulted from an application configuration issue on Klaviyo’s sign-up page, which allowed embedded third-party tracking pixels to capture and send form fields to external advertising platforms.

Which third-party platforms received the sign-up information?

Trackers embedded on the page transmitted data to several major tech and marketing firms, including Google, Facebook, Microsoft, LinkedIn, HubSpot, and X.

How many users were impacted by the misconfiguration?

According to Klaviyo, fewer than 200 known individuals were affected based on the company’s readily available active logs, though the total duration and historical extent of the exposure remain unconfirmed.

Source: TechCrunch