Signed up for Klaviyo? Dozens of advertisers may have seen your password

Marketing platform Klaviyo inadvertently shared sensitive customer sign-up data, including passwords and email addresses, with third-party advertisers due to a misconfigured web form. The vulnerability persisted for over a year before being discovered by security researchers.
Why it matters
This incident highlights the pervasive risks of third-party tracking pixels and the potential for massive data leaks in the marketing technology ecosystem.
Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers.
Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna , told TechCrunch that the web form on Klaviyo’s sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer.
The startup’s tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company’s website.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in