Menu
Browse

Cyber Incident Victim: Klaviyo

Date

Feb 2024

Location

United States of America

Status

Resolved

Updated

2026-08-14 07:18

Timeline
Occurred
Feb 2024
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Undetermined
Summary

Klaviyo’s signup form was misconfigured, allowing user registration data to be sent to third‑party trackers and advertising platforms. The exposed information included email addresses, passwords, company names, website addresses and phone numbers, reaching services such as Facebook, Google, Microsoft, LinkedIn, HubSpot and X. A researcher identified the issue, after which the company fixed the error and reported that active logs showed fewer than 200 affected individuals, while acknowledging that the total number of users impacted and the length of log retention remain unclear.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Klaviyo, a major marketing technology company, was found to have accidentally shared new customers’ sensitive data, including passwords and email addresses, with third-party advertisers because of a configuration error in its signup form. According to a report published by TechCrunch, the flaw drew the attention of media outlets and experts. Sam Jadali, a researcher and co-founder of the cybersecurity startup Melurna, discovered that the signup form on Klaviyo’s website had been misconfigured for at least the period from February 2024 to November 2025, and possibly even longer. During this period, data from users who registered on the site was transmitted to various third-party trackers embedded on the website and major advertising platforms.

Cyber Incident Image

Researchers say the security gap exposed not only users’ email addresses and passwords, but also valuable information such as company names, website addresses and phone numbers. According to ixbt.com and TechCrunch, this sensitive data reached major technology and marketing platforms including Facebook, Google, Microsoft and its subsidiary LinkedIn, as well as HubSpot and the social network X. Based in Boston, Klaviyo helps more than 205,000 paying customers manage advertising campaigns through email, text messages and other channels. According to information on the company’s official website, its system manages more than seven billion customer profiles.

Representatives of the Melurna startup shared their findings with TechCrunch before presenting them at the Def Con security conference in Las Vegas. Klaviyo’s management subsequently confirmed that the website error had been fixed. Klaviyo spokesperson Danielle Zanatta told TechCrunch that the issue was caused by an "application configuration problem," and that fewer than 200 affected individuals have been identified based on the active logs available. However, the company declined to disclose how long the logs are retained or when the error actually became active, and experts note that the incident once again demonstrated the risks posed by third-party trackers known as "pixels" when protective tools such as ad blockers are not used.

Sources
Sources available to members
1 source