Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers
Klaviyo says fewer than 200 people are known to be affected by a sign-up bug that may have exposed passwords to third-party trackers. The post Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers appeared first on TechRepublic .
A bug in Klaviyo's sign-up configuration may have exposed passwords and other registration data to third-party tracking services. The issue affected fewer than 200 users, according to Klaviyo's logs, with the misconfiguration occurring between February 2024 and November 2025. The exposed data included email addresses, passwords, company names, website addresses, and phone numbers, shared with trackers from companies such as Meta, Google, HubSpot, Microsoft, LinkedIn, and X. Klaviyo attributed the bug to an application configuration issue and notified those affected.
Businesses whose credentials were exposed should change their passwords and, if necessary, reset other accounts due to potential credential-stuffing attacks. Klaviyo advises using unique passwords and multi-factor authentication (MFA) for account security and recommends reviewing third-party scripts on registration and login pages to ensure sensitive fields are excluded from analytics and advertising data flows.
Written by urgent.news from TechRepublic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.