Signed up for Klaviyo? Dozens of advertisers may have seen your password
techcrunch.com Aug 10, 2026

Signed up for Klaviyo? Dozens of advertisers may have seen your password

AI-summarised brief · reviewed before publication

Security research revealed that from February 2024 to November 2025, Klaviyo’s sign‑up form misconfigured third‑party trackers, inadvertently sending new customers’ email addresses, passwords, company names, websites, and phone numbers to advertisers such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X. The leak potentially affected fewer than 200 users, according to Klaviyo’s logs, though the full scope remains unclear. Klaviyo confirmed a fix and notified affected individuals, but did not disclose the notification content or the incident publicly.

💡 Why It Matters

  • · The incident exposes how embedded advertising pixels can become covert data channels, turning routine sign‑ups into privacy breaches.
  • · It underscores the need for stricter oversight of third‑party scripts on marketing platforms.