Klaviyo said a misconfigured account-registration form on its own website exposed some new customer sign-up data, including passwords, to embedded third-party advertising trackers. The browser-side leakage reportedly affected users registering from at least February 2024 through November 2025 and may have shared email addresses, passwords, company names, website addresses, and phone numbers, according to reporting and statements cited by TechRepublic and SC Media.
The issue was discovered by Melurna co-founder Sam Jadali, and Klaviyo said it has fixed the bug and notified identified affected users. The company said fewer than 200 people were confirmed impacted based on available logs, but the total scope remains unclear because Klaviyo has not disclosed its log-retention period or the full duration of exposure; the incident did not involve a compromise of Klaviyo’s customer database, but it raises account-takeover risk for affected users, particularly where passwords were reused or MFA was not enabled.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Reporting says the browser-side exposure on Klaviyo's sign-up page persisted through at least November 2025, with trackers such as Meta, Google, HubSpot, Microsoft, LinkedIn, and X potentially able to access submitted registration data. The full duration remains unclear because Klaviyo did not disclose complete log-retention details or a full incident timeline.
Security researcher Sam Jadali found Klaviyo's own account-registration form was misconfigured from at least February 2024, allowing embedded third-party trackers to potentially receive sensitive sign-up data including email addresses, passwords, company names, website addresses, and phone numbers.
Klaviyo said it fixed the website configuration bug on its own sign-up page and attributed the issue to an application configuration problem. The company also said it notified the affected people it could identify and that fewer than 200 individuals are known to have been impacted based on available logs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.