started · updated
Klaviyo sign-up bug potentially exposed passwords to advertisers
A misconfigured sign-up form on the marketing technology platform Klaviyo may have exposed new customers' registration data to third-party advertisers and tech giants. Security research conducted by Melurna co-founder Sam Jadali suggests the configuration error existed from at least February 2024 through November 2025.
The exposed information reportedly included email addresses, passwords, company names, website addresses, and phone numbers. This data may have been shared with trackers operated by companies including Meta, Google, HubSpot, Microsoft, LinkedIn, and X. The exposure was a browser-side issue involving website pixels rather than a direct breach of Klaviyo’s central customer database.
Klaviyo has confirmed the bug was an ‘application configuration issue’ and stated that the issue has been fixed. While the company reported that fewer than 200 individuals are known to be affected based on current logs, the total number of impacted users remains uncertain as the full duration of the misconfiguration is not fully clarified. Experts recommend that any users who created accounts during this period change their passwords immediately to prevent credential-stuffing attacks.
Entities
Google · Klaviyo · Melurna · Meta · Sam Jadali