XOOMAR
A close-up of a smartphone with a green screen placed on a laptop keyboard.
TechnologyAugust 14, 2026· 5 min read· By XOOMAR Insights Team

Klaviyo Leaked Users' Passwords to Facebook, Google, Microsoft

Share
Updated on August 14, 2026

If you created a Klaviyo account between at least February 2024 and November 2025, your password and other personal details were likely shared with dozens of third-party advertising giants, including Facebook, Google, and Microsoft, due to a website bug.

XOOMAR Intelligence

Analyst Take

58/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness96Source Trust90Factual Grounding91Signal Cluster20

According to TechCrunch, a misconfigured web form on the marketing tech giant's sign-up page inadvertently shared users' submitted information with any external trackers embedded on the site for a period of at least 21 months. The exposed data included a new user's email address, plaintext password, company name, website, and phone number.

The Marketing Platform That Leaked Data to Marketers

The irony is stark. A company dedicated to helping others manage customer data failed to secure its own.

Security researcher Sam Jadali and his cybersecurity startup, Melurna, discovered the flaw and disclosed it ahead of a talk at the Def Con security conference. Their tests indicated that the faulty configuration sent sign-up details to a who's who of the adtech and social media world. The list of unintended recipients included:

  • Facebook and Google (through their advertising trackers)
  • Marketing software firm HubSpot
  • Microsoft and its subsidiary LinkedIn
  • Social media site X

Klaviyo spokesperson Danielle Zanatta confirmed the incident was an "application configuration issue" and said it has been fixed. She stated that the number of known affected individuals was "fewer than 200 people," but this figure is based only on "readily available active logs." The company would not disclose how long it retains these logs or the total potential duration of the leak.

Zanatta said the number of known individuals affected was fewer than 200 people, "based on our readily available active logs."

This raises immediate questions about the true scope. Klaviyo claims it alerted the users it could identify but declined to provide TechCrunch with a copy of that notification. The company has not issued any public disclosure about the incident.

A Single Flaw, a Multi-Company Data Breach

This incident is less a traditional "hack" and more a passive, systemic leak, akin to how unintended data exposure often occurs through third-party components like the controversial Mac driverless docks that bypass Apple's ecosystem controls. Here’s how the risk multiplies:

The Leak Wasn't to One Place: The data wasn't stolen from a single database. It was broadcast to potentially dozens of separate corporate ecosystems. Once the information reached the servers of Facebook, Google, HubSpot, and others, it entered their logs, analytics pipelines, and data warehouses. Klaviyo has no control over or visibility into how those companies handle or retain that data.

The Role of Third-Party Trackers: The bug exploited the ubiquitous presence of marketing "pixels" and analytics scripts on websites. These tools, while useful for business insights, can become accidental data exfiltration channels when misconfigured. The Klaviyo flaw is a textbook example of a security failure caused by an oversight in how a sensitive form interacts with these invisible third-party observers.

A Pattern of Pixel Problems: Klaviyo is not alone. Similar misconfigured tracker incidents have led to major data breach disclosures and regulatory enforcement actions in recent years. It underscores a pervasive blind spot: companies often prioritize marketing functionality over the privacy and security implications of the tools they embed. For security professionals, tracking these shadow data flows is as critical as monitoring their own network perimeters, a discipline we’ve explored in integrating penetration test results into SIEM platforms.

What Klaviyo Customers and Their Users Must Do Now

The practical fallout extends beyond Klaviyo's direct sign-ups to the seven billion customer profiles it manages for its 205,000 paying clients.

For Anyone Who Signed Up for Klaviyo (Last Two Years):

Treat your Klaviyo password as compromised, regardless of whether you received a notification.

  1. Change Your Klaviyo Password Immediately. Log in and create a new, strong, unique password.
  2. Change That Password Everywhere Else. If you reused your Klaviyo password on any other service (email, banking, social media), change those passwords now. This is the primary risk: credential stuffing attacks.
  3. Enable Two-Factor Authentication (2FA) on your Klaviyo account. This is a non-negotiable step for any business-critical account.
  4. Audit Your Klaviyo Account. Look for unfamiliar logins, newly created API keys, or changes to your integrated stores and audience lists.

For Businesses That Use Klaviyo:

Your company data was not directly exposed by this flaw, but your operational security depends on your vendor's hygiene.

  • Demand Transparency. Ask your Klaviyo account representative for their official incident report, the full forensic timeline, and details of their remediation steps. Their "fewer than 200" figure requires scrutiny.
  • Review Your Own Security Posture. This incident is a reminder to enforce strict password policies and mandate 2FA for all team members accessing marketing platforms. Centralized, secure credential management is essential, a topic covered in our guide to stop texting your passwords to family or teams.

Klaviyo’s Unanswered Questions

The company's opaque response creates more problems than it solves. Key unresolved issues include:

  • The True Timeline: How long was the bug actually active? "At least February 2024 through November 2025" leaves room for it to have been in place far longer.
  • Full Scope: "Fewer than 200" relies on incomplete logs. What about users whose data was leaked outside that log-retention window?
  • Regulatory Risk: When sensitive information like passwords is shared without consent, it may trigger data breach notification laws. Klaviyo's decision not to disclose publicly could attract regulatory scrutiny.

This bug is a costly lesson in the fragility of the modern data ecosystem. A single configuration error on one form didn't just expose data to one company, it sprayed sensitive credentials across the entire digital advertising infrastructure. The cleanup, for users and for Klaviyo's reputation, is only beginning.

Why This Changes Everything

  • This security failure by a major marketing data company fundamentally undermines user trust in platforms that handle sensitive personal information.
  • The exposure of plaintext passwords is a severe breach that could lead to account takeovers, identity theft, and further credential-based attacks on users.
  • The incident highlights systemic weaknesses in data handling by third-party trackers and adtech integrations, putting millions of users at risk across the industry.
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

High-quality image of a tablet with a wireless keyboard in a tech showcase setting.Technology

Microsoft Merges Copilot Apps in AI Super App Launch

Microsoft has merged its consumer and enterprise Copilot apps into one interface, taking the first concrete step toward launching an AI-powered 'super app' and

Aug 13, 20267 min
Close-up of a RTX 2080 Super graphics card against a bright yellow backdrop, showcasing high-tech design.Technology

Orion Browser Cracks Google's Surveillance Monopoly

The Orion browser, a zero-telemetry alternative built on Apple's WebKit engine, has launched in beta for Linux, offering a direct challenge to Google's data-ext

Aug 14, 20266 min
Golden Bitcoin coins on a keyboard with colorful neon lighting. Modern cryptocurrency concept.Technology

AI API Price War Slashes 2026 Output Cost by 80%

LLM API pricing has collapsed, making cheap paid models like Qwen3.7 Flash at $0.03/M tokens a smarter strategic move than free tiers for most serious applicati

Aug 13, 202613 min
Close-up of retro Apple IIe computer logo featuring rainbow apple symbol, showcasing vintage technology design.Technology

iPhone Arms Users With Weapon Against AI Deepfakes

Apple is building a cryptographic feature called Apple Reference Image to let iPhone users prove their photos are original camera shots, not AI-generated deepfa

Aug 13, 20268 min
Abstract 3D render of blue and pink digital blocks. Perfect for technology-themed content.Technology

Google Pixel Reveals Its First Waterproof Folding Phone

In 2026, foldable phones like the Google Pixel and Samsung Galaxy models have become durable daily drivers, with waterproofing and hinges rated for 200,000 fold

Aug 13, 202612 min
Close-up of a man with glasses and binary code projection, symbolizing cyber security.Cybersecurity

Insider Demands $7,540 For Cache Of Corporate Secrets

A data analyst contractor was sentenced to two years in prison for stealing employee data and trying to extort $2.5 million, but the company paid just $7,540 to

Aug 14, 20267 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Apple's Lock Screen Alert Warns iPhone Users of Spyware Attack

Apple has escalated its spyware warnings by sending high-confidence threat notifications directly to the lock screens of iPhones targeted by sophisticated, stat

Aug 14, 20266 min
A simple black and white silhouette of a world map emphasizing continents against a stark background.Global Trends

Stolen Matisse Artworks Fester in São Paulo Suburb

A stash of stolen Matisse artworks recovered from a São Paulo suburb eight months after the theft illuminates the surprising illiquidity and logistical pitfalls

Aug 14, 20266 min
A person interacts with a colorful QR code display on a laptop in a modern indoor setting.Technology

Mac Users Buy Driverless Docks Against Apple's $150 Tax

A third-party driverless Mac dock uses USB4 to deliver perfect, lag-free dual displays for $150, making Apple's Thunderbolt premium look outdated.

Aug 14, 20266 min
Hand holding smartphone displaying digital wallet app interface, blurred monitor in background.Fintech

Revolut’s French Bank License Targets Core European Revenue

Revolut secured a French banking license, allowing it to directly offer loans and deposits in major Western European markets and compete with incumbent banks fo

Aug 14, 20265 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.