Klaviyo’s Sign-Up Form Exposed User Passwords to Advertisers
Marketing technology firm Klaviyo has recently addressed a significant security vulnerability that inadvertently exposed the sign-up information of new customers, including their passwords, to a range of third-party advertisers. The issue stemmed from a misconfiguration in the web form on Klaviyo’s sign-up page, which, according to security research, was active for an extended period, potentially from February 2024 through November 2025, and possibly longer.
Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, detailed how this misconfiguration allowed any advertiser trackers embedded on Klaviyo’s website to access sensitive user data. This data included not only email addresses and passwords but also company names, website URLs, and phone numbers. The list of tech giants and advertisers that may have received this information includes prominent names such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X.
Klaviyo has acknowledged the flaw and stated that the website bug has been rectified. However, the full extent of the data exposure remains unclear, particularly regarding the total number of individuals affected over the duration of the vulnerability. The company, which serves over 205,000 paying customers and manages billions of customer profiles, has confirmed that fewer than 200 individuals were identified as affected based on available logs. Klaviyo has reportedly notified these individuals but has not publicly disclosed the incident or provided details on how far back its logs are stored.
This incident highlights the inherent data privacy risks associated with third-party website trackers, often referred to as pixels. These tools, while useful for understanding user behavior and identifying bugs, can become vectors for data leakage if misconfigured. The Klaviyo case is the latest in a series of security lapses involving misconfigured trackers, underscoring the ongoing challenges companies face in safeguarding user data in an increasingly interconnected digital landscape.
Key Takeaways
- Klaviyo's sign-up form was misconfigured, exposing new user data including passwords to advertisers.
- The vulnerability potentially affected users for over a year and included major tech companies like Google and Facebook.
- Klaviyo has fixed the bug and notified affected users, but the full scope of the breach remains uncertain.
Editor’s Analysis & Impact
The Klaviyo incident serves as a stark reminder of the pervasive data privacy risks inherent in modern web infrastructure. The inadvertent sharing of sensitive user credentials with third-party advertisers, even if unintentional, erodes customer trust and highlights the critical need for robust security audits and configuration management. For marketing tech companies like Klaviyo, whose business model relies on handling vast amounts of customer data, such lapses can have significant reputational and financial consequences. The ongoing reliance on third-party trackers, while beneficial for analytics, necessitates stringent oversight to prevent similar data exposure events. This case underscores the importance of proactive security measures and transparent communication with users following any potential breach.
Frequently Asked Questions
Q: What was the security issue with Klaviyo?
A: Klaviyo's sign-up form was misconfigured, causing it to inadvertently share new customer data, including email addresses and passwords, with third-party advertisers and tech companies that had trackers embedded on the website.
Q: Which companies may have received the exposed data?
A: The data may have been shared with major tech and advertising firms including Facebook, Google, HubSpot, Microsoft, LinkedIn, and X, among others.
Q: What has Klaviyo done to address the issue?
A: Klaviyo has confirmed that the website bug has been fixed. They have also stated that they have notified the fewer than 200 individuals identified as affected based on their logs.