Klaviyo data leak exposed user passwords to third-party advertisers
Security researcher Sam Jadali identified the vulnerability, which persisted from February 2024 to November 2025, affecting fewer than 200 individuals according to active logs.

Marketing technology company Klaviyo inadvertently shared new customers' sign-up information, including passwords, email addresses, and company details, with third-party advertisers and tech giants such as Facebook, Google, and Microsoft due to a misconfigured web form. The vulnerability existed from at least February 2024 through November 2025. Klaviyo confirmed the bug has been fixed and stated that fewer than 200 individuals were affected based on active logs, though the full extent of the leak remains unclear.
Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, identified the misconfiguration, which allowed data to be shared with trackers embedded on Klaviyo’s website. The data exposed to third parties included email addresses, passwords, company names, website addresses, and phone numbers. Recipients of the leaked data included major tech and advertising entities such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X.
Klaviyo spokesperson Danielle Zanatta attributed the issue to an “application configuration issue.” Klaviyo notified the known affected individuals but has not provided a copy of the communication sent to them. The findings were shared with TechCrunch ahead of Jadali’s talk at the Def Con security conference in Las Vegas.
Klaviyo is a Boston-based marketing giant with 205,000 paying customers and manages over seven billion customer profiles. The incident highlights broader risks associated with third-party website trackers (pixels), which can inadvertently share personal information entered into web pages if misconfigured. Previous security lapses involving misconfigured pixel trackers have resulted in data breach disclosures and regulatory enforcement actions.
Klaviyo is the latest company to face scrutiny for inadvertently sharing user data with outsiders. The exact number of people affected may be higher than the 200 identified in active logs, as it is unclear how far back Klaviyo stores logs or the full duration the bug was active. It is unclear why Klaviyo did not issue a public disclosure regarding the incident. The specific mechanisms by which the trackers shared data with the listed third parties have not been fully detailed in public reports.

