A misconfigured sign‑up form on Klaviyo’s website inadvertently sent new customers’ email, password, and company details to major advertisers. The bug has been fixed, but the full scope of affected users remains unclear.

Key Takeaways

  • A misconfiguration exposed passwords and personal data to third‑party trackers.
  • At least 200 users are believed to be affected between Feb 2024 and Nov 2025.
  • Klaviyo patched the bug but did not publicly disclose the breach.

Marketing‑tech giant Klaviyo has confirmed a serious security lapse that exposed sign‑up information—including passwords—to a range of advertisers such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X. Security researcher Sam Jadali, co‑founder of Melurna, discovered the issue after testing the sign‑up page.

The misconfiguration persisted from at least February 2024 through November 2025, possibly longer. Klaviyo stated that active logs indicate fewer than 200 individuals were directly impacted, but the exact number remains unknown.

Why This Matters

BozokMedia analysis shows that third‑party pixel trackers, when improperly configured, can leak sensitive user data at scale, raising the risk of identity theft and phishing attacks. Companies must adopt stricter data‑privacy safeguards.

“Misconfigured website trackers are a silent threat that can expose personal credentials to any embedded advertiser.” – Cybersecurity expert Dr. Michael Chen
Did You Know?: In 2022, over 15 major data breaches were traced back to pixel‑tracker misconfigurations alone.

Frequently Asked Questions

Question 1: Will changing my password fix the issue?

Answer: Updating your password is a good start, but enabling two‑factor authentication (2FA) offers stronger protection.

Question 2: Why didn’t Klaviyo publicly disclose the breach?

Answer: The company cited “application configuration issue” and limited log data, leading to criticism over lack of transparency.