Klaviyo Exposed User Passwords to Advertisers Due to Website Bug

Recent security research has uncovered that Klaviyo, a prominent marketing technology company, inadvertently shared new customers’ sign-up information, including passwords, with external advertisers. This misconfiguration persisted from at least February 2024 through November 2025.

The issue stemmed from a flaw in Klaviyo’s sign-up web form, which caused user data to be transmitted to third-party entities embedded on the company’s website. The exposed information encompassed email addresses, passwords, company names, website addresses, and phone numbers. Notable recipients of this data included major advertising and tech companies such as Facebook, Google, HubSpot, Microsoft (including LinkedIn), and X.

Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, identified the vulnerability and shared his findings ahead of a presentation at the Def Con security conference in Las Vegas. Klaviyo has since addressed the issue, but questions remain regarding the extent of the data exposure and the number of individuals affected over the years.

Based in Boston, Klaviyo serves approximately 205,000 paying customers, facilitating advertising campaigns across various channels. The company manages over seven billion customer profiles, highlighting the potential scale of the data exposure.

This incident underscores the risks associated with third-party trackers, commonly known as “pixels,” which are used to collect information about website visitors. When misconfigured, these trackers can inadvertently share sensitive user data. Similar security lapses have led to data breach disclosures and regulatory actions in recent years.

Klaviyo spokesperson Danielle Zanatta confirmed that the issue was due to an “application configuration” problem. The company identified fewer than 200 individuals affected based on available logs but did not specify the duration of log retention or the exact timeframe of the vulnerability. Klaviyo has notified the known affected individuals but has not publicly disclosed the incident.

This situation highlights the critical importance of robust security practices and vigilant monitoring of third-party integrations to prevent inadvertent data exposures. Organizations must ensure that their data collection tools are correctly configured to protect user information and maintain trust.