Startups & Technology

Klaviyo Leaked User Passwords to Third-Party Advertisers

Klaviyo Leaked User Passwords to Third-Party Advertisers

The security lapse persisted from at least February 2024 through November 2025, exposing sensitive data to any third-party tracker active on the Klaviyo sign-up page. Beyond login credentials, the leaked information included company names, website URLs, and phone numbers. These trackers, commonly known as pixels, are typically used for site analytics but can capture private user input when improperly implemented.

Klaviyo spokesperson Danielle Zanatta attributed the incident to an application configuration issue and claims fewer than 200 individuals were impacted. However, the company has declined to clarify how long it retains logs or why the breach was not publicly disclosed. While the Boston-based firm manages over seven billion customer profiles for its 205,000 paying clients, it has refused to release copies of the notifications sent to the affected users. This incident mirrors a growing trend of corporate data exposure caused by over-reliance on third-party marketing scripts.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!