Klaviyo Signup Bug Exposed Passwords to Facebook, Google and Other Trackers
Klaviyo says a signup bug exposed fewer than 200 known users' passwords and contact data to Facebook, Google and other trackers before it was recently fixed.
Summary
Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, found Klaviyo’s signup form was misconfigured from at least February 2024 through November 2025, and likely longer. Tests showed new customers’ email addresses, passwords, company names, websites and phone numbers may have reached embedded trackers operated by Facebook, Google, HubSpot, Microsoft, LinkedIn, X and others. Melurna gave TechCrunch its findings before presenting them at Def Con in Las Vegas.
Klaviyo spokesperson Danielle Zanatta blamed an application configuration issue and confirmed the Boston marketing technology company fixed it. Klaviyo identified fewer than 200 affected people from readily available active logs and said it notified them, but would not disclose its log retention period, the bug’s full duration or the notification, leaving the total exposure unknown. The company also did not explain why it made no public disclosure. Klaviyo serves 205,000 paying customers sending email, text and other advertising campaigns, and says it manages more than seven billion customer profiles. Pixels commonly measure usage and identify bugs, but misconfiguration can transmit form data to outsiders. Similar failures have triggered breach disclosures and regulatory enforcement, while ad blockers can reduce users’ exposure.
Positives
- Klaviyo fixed the application configuration issue after the password and customer data exposure was identified.
- Fewer than 200 known individuals appeared in Klaviyo’s readily available active logs, according to spokesperson Danielle Zanatta.
- Klaviyo said it notified the known affected individuals after reviewing its active logs.
- Melurna shared Sam Jadali’s research with TechCrunch before presenting it at Def Con in Las Vegas.
Risks & concerns
- Passwords, email addresses, company names, websites and phone numbers may have reached third-party trackers embedded on Klaviyo’s signup page.
- Facebook, Google, HubSpot, Microsoft, LinkedIn, X and other outside companies potentially received signup information.
- The misconfiguration existed from at least February 2024 through November 2025, and Melurna believes it may have lasted longer.
- Klaviyo’s limited active logs leave the total number of affected customers and the bug’s full duration unknown.
- Klaviyo withheld its log retention period and customer notification, and did not explain why the incident was not publicly disclosed.
- Klaviyo manages more than seven billion profiles, underscoring the potential consequences of tracker configuration failures at its scale.