Signed up for Klaviyo? Dozens of advertisers may have seen your password
Article excerpt
Highlighted: the sentence this signal was extracted from
Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers. Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, told TechCrunch that the web form on Klaviyo's sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer. The startup's tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company's website. This sign-up data included the customer's email address and password, as well as their company's name, website address, and phone number. This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsidiary LinkedIn; social media site X, and others. The startup shared its findings with TechCrunch ahead of its talk at the Def Con security conference in Las Vegas. Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger about the incident, including how many people were affected by the data leak over the years. The Boston-based marketing giant allows its 205,000 paying customers to...
Keep reading with a free account
The rest of this article, and every signal for Klaviyo, is in your free account.
