IT-PUB NEWS

Klaviyo fixed bug that exposed sign-up passwords

11.08.2026 13:03 • Author: IT-PUB
Klaviyo fixed bug that exposed sign-up passwords

Research shared with TechCrunch says Klaviyo’s sign-up form sent passwords and other details to third-party trackers. Klaviyo says fewer than 200 people were affected.

A newly disclosed security issue at Klaviyo has raised fresh questions about how much personal data can leak through website trackers. According to security research shared with TechCrunch, the company’s sign-up form was misconfigured for a long period and may have exposed new customers’ details — including passwords — to outside advertisers and tech companies.

That matters because registration is one of the moments when people expect their information to stay private. It also points to a broader problem for businesses and users alike: analytics and advertising tools can collect far more than intended when they are set up poorly.

Sign-up data was reportedly sent to outside trackers

Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, told TechCrunch that Klaviyo’s web form on its sign-up page was misconfigured between at least February 2024 and November 2025, and likely longer.

Melurna’s tests found that people who signed up through the affected form may have had their information shared with third-party trackers embedded on Klaviyo’s website. Those trackers belonged to major advertising and tech companies.

The data reportedly included email addresses and passwords, along with company names, website addresses and phone numbers. The companies named in the report included Facebook, Google, HubSpot, Microsoft and its subsidiary LinkedIn, X and others.

The findings were shared with TechCrunch ahead of Melurna’s planned talk at the Def Con security conference in Las Vegas. As IT-PUB News notes, the central concern is not just the presence of trackers, but the claim that a sign-up form passed along highly sensitive registration data.

Klaviyo says it fixed the configuration issue

Klaviyo confirmed to TechCrunch that the website bug has been fixed. The company described it as an “application configuration issue.”

Klaviyo also said the number of known affected individuals was fewer than 200, based on what it called its “readily available active logs.” But it did not say how far back those logs go or how long the bug remained active on the site.

That leaves a gap in the public picture. Klaviyo has not explained how many people may have been exposed before the period covered by the logs it reviewed, and the exact duration of the issue remains unclear.

The company also said it notified the known affected individuals. When asked by TechCrunch, though, it did not provide a copy of the message it said it sent to customers.

Klaviyo's scale made the bug hard to ignore

Klaviyo is a major marketing platform with 205,000 paying customers, according to the company. Its website says it manages more than seven billion customer profiles. That helps explain why even a bug on a sign-up page drew attention: the flaw involved people entering sensitive information at the exact moment they created an account.

The case also points to a familiar, often underestimated issue in online advertising infrastructure. Website trackers, often called pixels, are commonly used to measure traffic, understand how apps are used and find bugs. If they are configured poorly, though, they can also capture data typed into web forms and send it to outside services.

In this case, the concern is not that Klaviyo was hacked in the usual sense. It is that the company’s own website setup may have unintentionally shared sign-up data with embedded third-party tools. For users and companies, that distinction matters, because it shows how data exposure can happen through ordinary site functions rather than through a more visible breach.

Pixel tracker leaks remain a broader security problem

The research behind the disclosure fits a pattern seen in recent years. Security lapses tied to misconfigured pixel trackers have already led some companies to file data breach disclosures and, in other cases, face regulatory enforcement.

That makes the Klaviyo case part of a wider debate over how much information websites should send to third parties by default. For users, the risk is simple: details entered into a form may travel further than expected. For companies, the fallout can include reputational damage, notification obligations and questions about internal controls.

The report also underlines the limits of relying on trackers without defensive tools. The source notes that ad-blockers and similar protections can reduce exposure, while the absence of those tools may leave users more vulnerable to unintended sharing.

For now, Klaviyo says the bug has been corrected and that it contacted the people it knows were affected. But several public questions remain, including why the company did not disclose the incident publicly and how many people may have been affected over time.


Improve SEO for a small/medium business website for $50