← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Klaviyo inadvertently shared customer sign-up passwords with advertisers due to misconfiguration

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Klaviyo's sign-up form misconfigured from Feb 2024 to Nov 2025.
  • Customer passwords and other data shared with advertisers like Google, Facebook.
  • Security researcher Sam Jadali discovered the vulnerability.
  • Klaviyo confirmed the fix, stating fewer than 20 individuals affected.

Klaviyo Exposes Customer Data

Marketing technology company Klaviyo inadvertently shared new customer sign-up information, including passwords, with outside advertisers. This exposure was due to a misconfigured web form on its sign-up page, active from at least February 2024 through November 2025, and potentially longer.

Details of the Data Exposure

Security researcher Sam Jadali, co-founder of Melurna, discovered that sign-up data, including email addresses, passwords, company names, website addresses, and phone numbers, was shared. This information went to advertising and tech giants such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X, among others, whose trackers were embedded on Klaviyo's website.

Klaviyo's Response and Impact

Klaviyo confirmed the bug, which it described as an "application configuration issue," and stated it has been fixed. A spokesperson indicated that fewer than 20 individuals were known to be affected. The incident raises questions about the total number of affected users over the period the bug was active.

Third-Party Tracker Risks

This incident underscores the data risks posed by third-party trackers, or "pixels," when they are misconfigured. While trackers are used to collect information for analytics and bug identification, they can inadvertently expose personal data entered on web pages. Similar security lapses from misconfigured pixel trackers have led to data breach disclosures and regulatory actions in the past.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Marketing platform Klaviyo inadvertently exposed new customer sign-up information, including passwords, to third-party advertisers due to a web form misconfiguration. This issue, active from at least February 2024 to November 2025, highlights risks associated with third-party website trackers and misconfigured pixels.