Skip to main content
KlaviyoSecurity incident

Signed up for Klaviyo? Dozens of advertisers may have seen your password

What happened

Marketing technology company Klaviyo inadvertently shared new customer sign-up information, including passwords, with outside advertisers due to a misconfigured web form active from at least February 2024 through November 2025.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers. Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, told TechCrunch that the web form on Klaviyo's sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer. The startup's tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company's website. This sign-up data included the customer's email address and password, as well as their company's name, website address, and phone number. This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsidiary LinkedIn; social media site X, and others. The startup shared its findings with TechCrunch ahead of its talk at the Def Con security conference in Las Vegas. Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger about the incident, including how many people were affected by the data leak over the years. The Boston-based marketing giant allows its 205,000 paying customers to...

Keep reading with a free account

The rest of this article, and every signal for Klaviyo, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Location
Boston, Massachusetts, United States

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Misconfigured sign-up web form shared customer email addresses, passwords, company names, websites, and phone numbers with third-party advertisers.

Extraction

Confidence
100%
Detected
Aug 10, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Klaviyo and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Klaviyo this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/f02851cc-d6a5-4739-647e-d7f9cb332579 returns this record as JSON. POST /v1/companies/enrich returns every signal for klaviyo.com.

{
  "signal_id": "f02851cc-d6a5-4739-647e-d7f9cb332579",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-08-10T14:14:43+00:00",
  "company": {
    "name": "Klaviyo",
    "domain": "klaviyo.com"
  },
  "data": {
    "url": "https://techcrunch.com/2026/08/10/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password/",
    "title": "Signed up for Klaviyo? Dozens of advertisers may have seen your password",
    "author": "Zack Whittaker",
    "excerpt": "Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers. Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna , told TechCrunch that the web form on Klaviyo’s sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer. The startup’s tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company’s website. This sign-up data included the customer’s email address and password, as well as their company’s name, website address, and phone number. This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsidiary LinkedIn; social media site X, and others. The startup shared its findings with TechCrunch ahead of its talk at the Def Con security conference in Las Vegas. Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger about the incident, including how many people were affected by the data leak over the years. The Boston-based marketing giant allows its 205,000 paying customers to...",
    "summary": "Marketing technology company Klaviyo inadvertently shared new customer sign-up information, including passwords, with outside advertisers due to a misconfigured web form active from at least February 2024 through November 2025.",
    "location": "Boston, Massachusetts, USA",
    "planning": false,
    "image_url": "https://techcrunch.com/wp-content/uploads/2026/08/klaviyo-2283003642.jpg?resize=1200,800",
    "confidence": 1,
    "published_at": "2026-08-10T14:14:43Z",
    "location_data": [
      {
        "city": "Boston",
        "state": "Massachusetts",
        "region": "Northern America",
        "country": "United States",
        "continent": "Americas",
        "fuzzy_match": false
      }
    ],
    "vulnerability": "Misconfigured sign-up web form shared customer email addresses, passwords, company names, websites, and phone numbers with third-party advertisers.",
    "article_sentence": "Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.