Signed up for Klaviyo? Dozens of advertisers may have seen your password

August 2026 · 3 minute read

Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers.

Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, told TechCrunch that the web form on Klaviyo’s sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer.

The startup’s tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company’s website.

This sign-up data included the customer’s email address and password, as well as their company’s name, website address, and phone number. This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsidiary LinkedIn; social media site X; and others.

The startup shared its findings with TechCrunch ahead of its talk at the Def Con security conference in Las Vegas.

Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger about the incident, including how many people were affected by the data leak over the years. The Boston-based marketing giant allows its 205,000 paying customers to send advertising campaigns across email, text messages, and other channels. Klaviyo’s website says it manages over seven billion customer profiles.

The bug underscores the data risks that third-party trackers can pose to website users when not using defensive tools, like ad-blockers. Klaviyo is the latest company in recent years to have been caught out by inadvertently sharing data with outsiders.

Website trackers, known as “pixels,” allow website and app owners to collect information about their visitors and users, often for understanding how their apps are used and for identifying bugs. These trackers can be misconfigured to also share personal information entered into any web page that they are on. 

In the past few years, security lapses stemming from misconfigured pixel trackers have resulted in companies filing data breach disclosures and regulators taking enforcement action.

When reached by TechCrunch, Klaviyo spokesperson Danielle Zanatta confirmed that the bug was related to an “application configuration issue.” Zanatta said the number of known individuals affected was fewer than 200 people, “based on our readily available active logs.” Klaviyo would not say how far back it stores logs, or for how long the bug was active on its website.

Klaviyo said it notified the known individuals affected, but would not provide a copy of the communication that the company allegedly shared with affected customers when asked by TechCrunch. 

It’s unclear why the company did not publicly disclose the incident. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at [email protected].

View Bio