Marketing technology company Klaviyo inadvertently shared new customer sign-up information, including passwords, with outside advertisers. This exposure was due to a misconfigured web form on its sign-up page, active from at least February 2024 through November 2025, and potentially longer.
Security researcher Sam Jadali, co-founder of Melurna, discovered that sign-up data, including email addresses, passwords, company names, website addresses, and phone numbers, was shared. This information went to advertising and tech giants such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X, among others, whose trackers were embedded on Klaviyo's website.
Klaviyo confirmed the bug, which it described as an "application configuration issue," and stated it has been fixed. A spokesperson indicated that fewer than 20 individuals were known to be affected. The incident raises questions about the total number of affected users over the period the bug was active.
This incident underscores the data risks posed by third-party trackers, or "pixels," when they are misconfigured. While trackers are used to collect information for analytics and bug identification, they can inadvertently expose personal data entered on web pages. Similar security lapses from misconfigured pixel trackers have led to data breach disclosures and regulatory actions in the past.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Marketing platform Klaviyo inadvertently exposed new customer sign-up information, including passwords, to third-party advertisers due to a web form misconfiguration. This issue, active from at least February 2024 to November 2025, highlights risks associated with third-party website trackers and misconfigured pixels.