If you created a Klaviyo account between at least February 2024 and November 2025, your password and other personal details were likely shared with dozens of third-party advertising giants, including Facebook, Google, and Microsoft, due to a website bug.
According to TechCrunch, a misconfigured web form on the marketing tech giant's sign-up page inadvertently shared users' submitted information with any external trackers embedded on the site for a period of at least 21 months. The exposed data included a new user's email address, plaintext password, company name, website, and phone number.
The Marketing Platform That Leaked Data to Marketers
The irony is stark. A company dedicated to helping others manage customer data failed to secure its own.
Security researcher Sam Jadali and his cybersecurity startup, Melurna, discovered the flaw and disclosed it ahead of a talk at the Def Con security conference. Their tests indicated that the faulty configuration sent sign-up details to a who's who of the adtech and social media world. The list of unintended recipients included:
- Facebook and Google (through their advertising trackers)
- Marketing software firm HubSpot
- Microsoft and its subsidiary LinkedIn
- Social media site X
Klaviyo spokesperson Danielle Zanatta confirmed the incident was an "application configuration issue" and said it has been fixed. She stated that the number of known affected individuals was "fewer than 200 people," but this figure is based only on "readily available active logs." The company would not disclose how long it retains these logs or the total potential duration of the leak.
Zanatta said the number of known individuals affected was fewer than 200 people, "based on our readily available active logs."
This raises immediate questions about the true scope. Klaviyo claims it alerted the users it could identify but declined to provide TechCrunch with a copy of that notification. The company has not issued any public disclosure about the incident.
A Single Flaw, a Multi-Company Data Breach
This incident is less a traditional "hack" and more a passive, systemic leak, akin to how unintended data exposure often occurs through third-party components like the controversial Mac driverless docks that bypass Apple's ecosystem controls. Here’s how the risk multiplies:
The Leak Wasn't to One Place: The data wasn't stolen from a single database. It was broadcast to potentially dozens of separate corporate ecosystems. Once the information reached the servers of Facebook, Google, HubSpot, and others, it entered their logs, analytics pipelines, and data warehouses. Klaviyo has no control over or visibility into how those companies handle or retain that data.
The Role of Third-Party Trackers: The bug exploited the ubiquitous presence of marketing "pixels" and analytics scripts on websites. These tools, while useful for business insights, can become accidental data exfiltration channels when misconfigured. The Klaviyo flaw is a textbook example of a security failure caused by an oversight in how a sensitive form interacts with these invisible third-party observers.
A Pattern of Pixel Problems: Klaviyo is not alone. Similar misconfigured tracker incidents have led to major data breach disclosures and regulatory enforcement actions in recent years. It underscores a pervasive blind spot: companies often prioritize marketing functionality over the privacy and security implications of the tools they embed. For security professionals, tracking these shadow data flows is as critical as monitoring their own network perimeters, a discipline we’ve explored in integrating penetration test results into SIEM platforms.
What Klaviyo Customers and Their Users Must Do Now
The practical fallout extends beyond Klaviyo's direct sign-ups to the seven billion customer profiles it manages for its 205,000 paying clients.
For Anyone Who Signed Up for Klaviyo (Last Two Years):
Treat your Klaviyo password as compromised, regardless of whether you received a notification.
- Change Your Klaviyo Password Immediately. Log in and create a new, strong, unique password.
- Change That Password Everywhere Else. If you reused your Klaviyo password on any other service (email, banking, social media), change those passwords now. This is the primary risk: credential stuffing attacks.
- Enable Two-Factor Authentication (2FA) on your Klaviyo account. This is a non-negotiable step for any business-critical account.
- Audit Your Klaviyo Account. Look for unfamiliar logins, newly created API keys, or changes to your integrated stores and audience lists.
For Businesses That Use Klaviyo:
Your company data was not directly exposed by this flaw, but your operational security depends on your vendor's hygiene.
- Demand Transparency. Ask your Klaviyo account representative for their official incident report, the full forensic timeline, and details of their remediation steps. Their "fewer than 200" figure requires scrutiny.
- Review Your Own Security Posture. This incident is a reminder to enforce strict password policies and mandate 2FA for all team members accessing marketing platforms. Centralized, secure credential management is essential, a topic covered in our guide to stop texting your passwords to family or teams.
Klaviyo’s Unanswered Questions
The company's opaque response creates more problems than it solves. Key unresolved issues include:
- The True Timeline: How long was the bug actually active? "At least February 2024 through November 2025" leaves room for it to have been in place far longer.
- Full Scope: "Fewer than 200" relies on incomplete logs. What about users whose data was leaked outside that log-retention window?
- Regulatory Risk: When sensitive information like passwords is shared without consent, it may trigger data breach notification laws. Klaviyo's decision not to disclose publicly could attract regulatory scrutiny.
This bug is a costly lesson in the fragility of the modern data ecosystem. A single configuration error on one form didn't just expose data to one company, it sprayed sensitive credentials across the entire digital advertising infrastructure. The cleanup, for users and for Klaviyo's reputation, is only beginning.
Why This Changes Everything
- This security failure by a major marketing data company fundamentally undermines user trust in platforms that handle sensitive personal information.
- The exposure of plaintext passwords is a severe breach that could lead to account takeovers, identity theft, and further credential-based attacks on users.
- The incident highlights systemic weaknesses in data handling by third-party trackers and adtech integrations, putting millions of users at risk across the industry.
Originally published on XOOMAR. For more news and analysis, visit XOOMAR.

