{"id":256798,"date":"2026-08-10T14:14:43","date_gmt":"2026-08-10T14:14:43","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/10\/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password-techcrunch\/"},"modified":"2026-08-10T14:14:43","modified_gmt":"2026-08-10T14:14:43","slug":"signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/10\/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password-techcrunch\/","title":{"rendered":"Signed up for Klaviyo? Dozens of advertisers may have seen your password | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Newly revealed security research found that until recently, marketing tech giant <a href=\"https:\/\/www.klaviyo.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Klaviyo<\/a> was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers.<\/p>\n<p class=\"wp-block-paragraph\">Sam Jadali, a security researcher and co-founder of cybersecurity startup <a href=\"https:\/\/www.melurna.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Melurna<\/a>, told TechCrunch that the web form on Klaviyo\u2019s sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer.<\/p>\n<p class=\"wp-block-paragraph\">The startup\u2019s tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company\u2019s website.<\/p>\n<p class=\"wp-block-paragraph\">This sign-up data included the customer\u2019s email address and password, as well as their company\u2019s name, website address, and phone number. This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsidiary LinkedIn; social media site X; and others.<\/p>\n<p class=\"wp-block-paragraph\">The startup shared its findings with TechCrunch ahead of its talk at the Def Con security conference in Las Vegas.<\/p>\n<p class=\"wp-block-paragraph\">Klaviyo confirmed to TechCrunch that it fixed the website bug, but questions linger about the incident, including how many people were affected by the data leak over the years. The Boston-based <a href=\"https:\/\/techcrunch.com\/2021\/04\/19\/klaviyo-ec1\/\" target=\"_blank\" rel=\"noopener\">marketing giant<\/a> allows its 205,000 paying customers to send advertising campaigns across email, text messages, and other channels. Klaviyo\u2019s website says it manages over seven billion customer profiles.<\/p>\n<p class=\"wp-block-paragraph\">The bug underscores the data risks that third-party trackers can pose to website users when not using defensive tools, <a href=\"https:\/\/techcrunch.com\/2026\/06\/04\/filtr-is-a-new-privacy-tool-that-blocks-ads-in-almost-every-iphone-and-mac-app\/\" target=\"_blank\" rel=\"noopener\">like ad-blockers<\/a>. Klaviyo is the latest company in recent years to have been caught out by inadvertently sharing data with outsiders.<\/p>\n<p class=\"wp-block-paragraph\">Website trackers, known as \u201cpixels,\u201d allow website and app owners to collect information about their visitors and users, often for understanding how their apps are used and for identifying bugs. These trackers can be misconfigured to also share personal information entered into any web page that they are on.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In the past few years, security lapses stemming from misconfigured pixel trackers have resulted in companies <a href=\"https:\/\/techcrunch.com\/2024\/04\/25\/kaiser-permanente-health-plan-millions-data-breach\/\" target=\"_blank\" rel=\"noopener\">filing data breach disclosures<\/a> and <a href=\"https:\/\/techcrunch.com\/2023\/04\/17\/pixel-tracking-hipaa-startups\/\" target=\"_blank\" rel=\"noopener\">regulators taking enforcement action<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">When reached by TechCrunch, Klaviyo spokesperson Danielle Zanatta confirmed that the bug was related to an \u201capplication configuration issue.\u201d Zanatta said the number of known individuals affected was fewer than 200 people, \u201cbased on our readily available active logs.\u201d Klaviyo would not say how far back it stores logs, or for how long the bug was active on its website.<\/p>\n<p class=\"wp-block-paragraph\">Klaviyo said it notified the known individuals affected, but would not provide a copy of the communication that the company allegedly shared with affected customers when asked by TechCrunch.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s unclear why the company did not publicly disclose the incident.\u00a0<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/08\/10\/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers. Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, told TechCrunch that the web form on Klaviyo\u2019s sign-up page was misconfigured between at least February [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":256799,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-256798","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/256798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=256798"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/256798\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/256799"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=256798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=256798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=256798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}