Klaviyo sign-up bug leaked passwords to Facebook, Google

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Sam Jadali of cybersecurity startup Melurna discovered that Klaviyo's sign-up form was misconfigured from at least February 2024 through November 2025 — and likely longer — funneling new customer data to third-party trackers embedded on the company's site.
- The leaked fields included email addresses, passwords, company names, website addresses, and phone numbers, which were shared with Facebook, Google, HubSpot, Microsoft, LinkedIn, X, and other ad-tech companies whose trackers were present on the Klaviyo sign-up page.
- Klaviyo confirmed the bug stemmed from an "application configuration issue" and told TechCrunch that fewer than 200 known individuals were affected "based on our readily available active logs," but declined to disclose how long it retains logs or how far back the bug was actually live.
- Klaviyo notified the known affected individuals but did not publicly disclose the incident, and would not provide a copy of the customer notification when asked by TechCrunch.
- The Boston-based marketing automation company serves 205,000 paying customers and manages over seven billion customer profiles, giving the sign-up-form bug potential exposure well beyond the fewer-than-200 figure the company confirmed.
- Jadali presented the findings at the Def Con security conference in Las Vegas, and the report adds another example to a pattern of misconfigured pixel trackers that has triggered data-breach disclosures and regulatory enforcement in recent years.
Why it matters: Klaviyo's "fewer than 200" figure rests on logs it won't characterize, and the researcher says the bug was likely active longer than the Feb 2024–Nov 2025 window he confirmed — so the real exposure is unverifiable. For Klaviyo's 205,000 paying brands sending campaigns through a platform managing seven billion profiles, an undisclosed leak of plaintext passwords to Facebook, Google, and LinkedIn is a material trust event regardless of final count.
Ask SkimNews



