Urgent.News

What's breaking now, across thousands of outlets.

Tech

Signed up for Klaviyo? Dozens of advertisers may have seen your password

A bug in the tech giant's website mistakenly shared users' sign-up information, including personal data and their password, to third-party companies.

Security research has uncovered a concerning incident where marketing platform Klaviyo inadvertently exposed sign-up details, including customers' passwords, to various third-party advertisers and tech giants. Sam Jadali, a cybersecurity researcher, discovered that the web form on Klaviyo's sign-up page was misconfigured between February 2024 and November 2025, potentially for an even longer period.

Signing up using this flawed form could have resulted in sharing customers' email addresses, passwords, company names, website addresses, and phone numbers with numerous entities, such as Facebook, Google, HubSpot, Microsoft, LinkedIn, X, and others.

Klaviyo, a Boston-based marketing company providing email, text message, and other advertising campaign services, confirmed the bug had been fixed. However, the exact number of individuals affected remains undisclosed. The company only confirmed that the affected individuals were fewer than 200, based on their available log data. Klaviyo does not disclose the duration for which they retain log data nor confirm how long the bug had been active.

This incident highlights the risks posed by third-party trackers, like "pixels," which gather visitor information from websites and apps. Previous security lapses from misconfigured pixel trackers have led to data breach disclosures and regulatory action. Klaviyo stated that the bug was related to an "application configuration issue."

The company notified affected individuals but did not disclose the content of those communications. The incident remains unresolved in terms of explaining why Klaviyo did not publicly disclose the breach.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techcrunch.com →

More in Tech

More from Monday 10 August →