Registered for Klaviyo? Numerous advertisers might have accessed your password.

Registered for Klaviyo? Numerous advertisers might have accessed your password.

Recent security findings indicate that marketing technology leader Klaviyo was, until recently, unintentionally disclosing the sign-up details of its new users, including their passwords, to external advertisers.

Sam Jadali, a security investigator and co-founder of the cybersecurity company Melurna, informed TechCrunch that the web form on Klaviyo’s registration page was incorrectly set up from at least February 2024 to November 2025, likely for an even longer period.

The startup’s investigations revealed that anyone registering with Klaviyo via the faulty form might have had their sign-up details shared with various third-party tech companies and advertisers whose tracking mechanisms are also integrated into the company’s website.

This sign-up information contained the user’s email, password, as well as the organization’s name, website, and phone number. This data was disclosed to advertising and tech firms such as Facebook and Google; marketing leader HubSpot; Microsoft and its subsidiary LinkedIn; social media platform X, among others.

The startup disclosed its results to TechCrunch prior to its presentation at the Def Con security conference in Las Vegas.

Klaviyo acknowledged to TechCrunch that it rectified the website flaw, yet uncertainties remain regarding the incident, including the total number of individuals impacted by the data exposure throughout the years. The Boston-based marketing leader permits its 205,000 paid clients to execute advertising campaigns through email, SMS, and various other means. Klaviyo’s site claims it oversees over seven billion customer profiles.

The flaw highlights the data vulnerabilities that third-party trackers can inflict on website users when defensive measures, like ad-blockers, are not employed. Klaviyo joins the list of companies in recent times that have unintentionally exposed data to external entities.

Website trackers, referred to as “pixels,” enable website and app proprietors to gather information concerning their visitors and users, commonly for understanding how their applications are utilized and for detecting issues. These trackers can be misconfigured to also disclose personal information entered on any webpage where they are present. 

In recent years, security breaches arising from improperly configured pixel trackers have led to businesses submitting data breach notifications and regulators initiating enforcement measures.

When contacted by TechCrunch, Klaviyo representative Danielle Zanatta confirmed the flaw was linked to an “application configuration issue.” Zanatta mentioned that the count of known affected individuals was fewer than 200, “based on our readily available active logs.” Klaviyo refrained from commenting on how far back it retains logs or how long the flaw was present on its website.

Klaviyo stated it informed the known affected individuals, but did not provide a copy of the communication that the company supposedly sent to impacted customers when requested by TechCrunch. 

It remains uncertain why the company did not disclose the incident publicly. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Leave a Reply