Signed up for Klaviyo? Dozens of advertisers may have seen your password
A bug in the tech giant's website the logo of US marketing automation company Klaviyo Inc. is seen displayed on a smartphone in front of an abstract background on a computer screen..

本条来自 TechCrunch(AI / 创投),聚焦 brand。 Signed up for Klaviyo? Dozens of advertisers may have seen your password
A bug in the tech giant's website the logo of US marketing automation company Klaviyo Inc
- Media & Entertainment
- TechCrunch Brand Studio
- Zack Whittaker
- 7:14 AM PDT · August 10, 2026
- Signed up for Klaviyo
A bug in the tech giant's website the logo of US marketing automation company Klaviyo Inc
is seen displayed on a smartphone in front of an abstract background on a computer screen
Media & Entertainment
TechCrunch Brand Studio
Signed up for Klaviyo? Dozens of advertisers may have seen your password
Zack Whittaker
7:14 AM PDT · August 10, 2026
Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers.
Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna , told TechCrunch that the web form on Klaviyo’s sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer.
The startup’s tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company’s website.
This sign-up data included the customer’s email address and password, as well as their company’s name, website address, and phone number. This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsidiary LinkedIn; social media site X; and others.
The startup shared its findings with TechCrunch ahead of its talk at the Def Con security conference in Las Vegas.
Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger about the incident, including how many people were affected by the data leak over the years. The Boston-based marketing giant allows its 205,000 paying customers to send advertising campaigns across email, text messages, and other channels. Klaviyo’s website says it manages over seven billion customer profiles.
The bug underscores the data risks that third-party trackers can pose to website users when not using defensive tools, like ad-blockers . Klaviyo is the latest company in recent years to have been caught out by inadvertently sharing data with outsiders.
Website trackers, known as “pixels,” allow website and app owners to collect information about their visitors and users, often for understanding how their apps are used and for identifying bugs. These trackers can be misconfigured to also share personal information entered into any web page that they are on.
In the past few years, security lapses stemming from misconfigured pixel trackers have resulted in companies filing data breach disclosures and regulators taking enforcement action .
When reached by TechCrunch, Klaviyo spokesperson Danielle Zanatta confirmed that the bug was related to an “application configuration issue.” Zanatta said the number of known individuals affected was fewer than 200 people, “based on our readily available active logs.” Klaviyo would not say how far back it stores logs, or for how long the bug was active on its website.
Klaviyo said it notified the known individuals affected, but would not provide a copy of the communication that the company allegedly shared with affected customers when asked by TechCrunch.
It’s unclear why the company did not publicly disclose the incident.
When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.
Zack Whittaker
Security Editor
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security .
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com .
October 13 – 15
San Francisco
Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you.
Save up to $300 toda y!
Most Popular
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you
Zack Whittaker
Cloudflare launches Kitesurf, a browser built for AI agents
Sarah Perez
ChatGPT brings unlimited text chats to free users
Ivan Mehta
Tesla and SpaceX will invest $16.8B to start building ‘Terafab’ chip factory in Texas
Sean O'Kane
Amid legal battles, Suno says it will start watermarking songs
Ivan Mehta
Ford’s new electric truck, ‘Fathom,’ starts at $28,350
Sean O'Kane
Bending Spoons to buy Airtable for $1.28B
Ivan Mehta
X
youTube
Mastodon
Threads
Bluesky
TechCrunch Staff Contact Us Advertise Crunchboard Jobs Site Map
Terms of Service Privacy Policy RSS Terms of Use Code of Conduct
OpenAI vs Apple Nous Research Space Data Centers Staya Nadella SpaceX Starship Tech Layoffs ChatGPT
© 2026 TechCrunch Media LLC.
本条目归入「Brand Marketing」垂直,涉及真实话题:brand。
· 市场:关注 brand 对相关品类与竞争格局的潜在影响。
· 消费者:受众行为与偏好变化值得追踪。
· 品牌:本动向对品牌资产建设的启示。
· 渠道:内容分发与触点组合(社媒 / 电商 / 线下)的协同值得复盘。
· 核心话题:brand。
· 可思考:如何把「brand」的洞察,转化为可衡量的内容与增长动作?
面试中可引用「Signed up for Klaviyo? Dozens of advertisers may have seen your password」:围绕 brand,说明你对行业动向的判断与可落地动作。
本条目相关英文术语可在「商务英语」模块按话题检索,用于外企面试表达训练。
Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their pas…
Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger about the incident, including how many people were affected by the data leak over the years. The…
This sign-up data included the customer’s email address and password, as well as their company’s name, website address, and phone number. This information was shared with advertisi…