Signed up for Klaviyo? Dozens of advertisers may have seen your password

4 days ago 20

Newly revealed information probe recovered that until recently, selling tech elephantine Klaviyo was inadvertently sharing the sign-up accusation of its caller customers, including their passwords, with extracurricular advertisers.

Sam Jadali, a information researcher and co-founder of cybersecurity startup Melurna, told TechCrunch that the web signifier connected Klaviyo’s sign-up leafage was misconfigured betwixt astatine slightest February 2024 done November 2025, though apt longer.

The startup’s tests recovered that anyone who signed up to Klaviyo utilizing the misconfigured signifier whitethorn person had their sign-up accusation shared with immoderate of the third-party tech giants and advertisers whose trackers are besides embedded connected the company’s website.

This sign-up information included the customer’s email code and password, arsenic good arsenic their company’s name, website address, and telephone number. This accusation was shared with advertizing and tech giants including Facebook and Google; selling elephantine HubSpot; Microsoft and its subsidiary LinkedIn; societal media tract X, and others.

The startup shared its findings with TechCrunch up of its speech astatine the Def Con information league successful Las Vegas.

Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger astir the incident, including however galore radical were affected by the information leak implicit the years. The Boston-based marketing giant allows its 205,000 paying customers to nonstop advertizing campaigns crossed email, substance messages, and different channels. Klaviyo’s website says it manages implicit 7 cardinal lawsuit profiles.

The bug underscores the information risks that third-party trackers tin airs to website users erstwhile not utilizing antiaircraft tools, like ad-blockers. Klaviyo is the latest institution successful caller years to person been caught retired by inadvertently sharing information with outsiders.

Website trackers, known arsenic “pixels,” let website and app owners to cod accusation astir their visitors and users, often for knowing however their apps are utilized and for identifying bugs. These trackers tin beryllium misconfigured to besides stock idiosyncratic accusation entered into immoderate web leafage that they are on. 

In the past fewer years, information lapses stemming from misconfigured pixel trackers person resulted successful companies filing information breach disclosures and regulators taking enforcement action.

When reached by TechCrunch, Klaviyo spokesperson Danielle Zanatta confirmed that the bug was related to an “application configuration issue.” Zanatta said the fig of known individuals affected was less than 200 people, “based connected our readily disposable progressive logs.” Klaviyo would not accidental however acold backmost it stores logs, oregon for however agelong the bug was progressive connected its website.

Klaviyo said it notified the known individuals affected, but would not supply a transcript of the connection that the institution allegedly shared with affected customers erstwhile asked by TechCrunch. 

It’s unclear wherefore the institution did not publically disclose the incident. 

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Read Entire Article