A Klaviyo website bug may have leaked customer passwords and signup details to outside advertisers. Here’s what happened, who may be affected, and how you can protect your accounts online.
Table of Contents
What Happened?
Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, discovered the problem while studying Klaviyo’s signup page.
The issue was present from at least February 2024 through November 2025, though researchers said it may have lasted longer.
Klaviyo confirmed that the problem came from an application configuration issue and said it has since been fixed.
The company said fewer than 200 known individuals were affected, based on its available active logs. However, Klaviyo did not say how far back those logs go, so the full number of affected customers remains unclear.
Leaks like this matter because passwords and contact details can later be used in phishing attempts or unauthorized login attempts.
They are also a reminder that your information may already have appeared in other leaks without you realizing it.
If you are unsure whether your information was leaked, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Klaviyo Data Was Leaked?
The issue could have affected people who created a Klaviyo account while the signup page was misconfigured.
According to the research, information entered into the signup form may have included:
- email addresses
- passwords
- company names
- company website addresses
- phone numbers
The information may have been sent to third-party services whose tracking tools were running on Klaviyo’s website.
These companies included Facebook, Google, HubSpot, Microsoft, LinkedIn, X, and other advertising and technology providers.
Klaviyo said it notified the known individuals affected. However, it has not publicly shared a complete number covering the entire period.
Passwords are especially important because many people reuse them across different websites.
If a leaked password is later obtained by criminals, they may try it on your email, shopping,
How the Klaviyo Website Bug Leaked Signup Data
Researchers linked the leak to third-party website trackers, sometimes called pixels.
A pixel is a small piece of code that helps companies understand how visitors use a website or respond to advertising.
These tools are common, but they need to be configured carefully.
In Klaviyo’s case, the signup form was misconfigured. As a result, information entered into the form could be sent to outside tracking services.
That information may have included passwords along with other signup details.
Klaviyo described the problem as an application configuration issue.
The available information does not suggest that criminals broke into Klaviyo’s systems to steal the data.
Instead, the information appears to have been shared unintentionally through the website’s tracking setup.
Futureproof monitors your information for data leaks 24/7 and guides you with clear steps to keep it safer from scams.
Run a free check
At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
