Klaviyo
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
Klaviyo is a United States-based technology company operating in the email marketing and digital communications sector. The organisation provides a platform that enables businesses to manage customer relationships through email and other digital channels, with tools designed to support marketing campaigns, audience segmentation, and data-driven outreach. Its services are utilised across a diverse client base, including sectors such as cryptocurrency, where its mailing list capabilities have been applied for customer engagement and promotional communications. The company's market positioning centres on enabling brands to leverage first-party data for personalised marketing, serving as a conduit between businesses and their customer audiences through automated messaging infrastructure.
The organisation has experienced significant cybersecurity incidents that have exposed vulnerabilities in both its technical configurations and its internal security protocols. In February 2024, a misconfiguration in Klaviyo's signup form resulted in user registration data being transmitted to multiple third-party trackers and advertising platforms, including Facebook, Google, Microsoft, LinkedIn, HubSpot, and X. The exposed data encompassed email addresses, passwords, company names, website addresses, and phone numbers. A security researcher identified the flaw, and the company subsequently addressed the configuration error. Klaviyo reported that active logs indicated fewer than 200 affected individuals, though it acknowledged uncertainty regarding the total number of impacted users and the duration of log retention for the affected endpoint. A separate incident occurred in August 2022, when threat actors obtained employee credentials through phishing, gaining unauthorised access to internal support tools. The attackers targeted cryptocurrency-related client accounts, exfiltrating marketing lists from 38 customers that contained names, email addresses, phone numbers, and custom profile properties, along with two internal lists used for company updates. Law enforcement was notified, and a third-party cybersecurity firm assisted with the investigation following the breach.
The 2022 breach raised particular concerns about subsequent phishing and smishing campaigns, with reports indicating that threat actors attempted to acquire the stolen information for malicious purposes. This incident bore similarities to earlier attacks that targeted cryptocurrency users following comparable data exposures. Across both incidents, the compromised data has the potential to facilitate targeted social engineering attacks against affected individuals and organisations. The recurring nature of these security events highlights ongoing challenges in maintaining robust defences against both external phishing campaigns and internal configuration management, demonstrating the importance of continuous security monitoring and employee awareness training within organisations that handle large volumes of sensitive customer data.
Incidents
2 incidents linked to this organisation.