
Passwords are supposed to be the one thing companies never share. Klaviyo apparently missed that memo. According to TechCrunch, the Boston-based marketing giant spent at least 21 months inadvertently sending new users’ sign-up data, including their plaintext passwords, directly to third-party advertisers embedded on its own website.
The finding comes from Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, who shared his results ahead of a talk at the Def Con security conference in Las Vegas. Jadali found that Klaviyo’s sign-up page was misconfigured between at least February 2024 and November 2025, though he suspects the window was wider. Anyone who created an account during that period may have had their information captured by tracking pixels sitting on the same page.
And the list of recipients is not small. The leaked data, which included email addresses, passwords, company names, website addresses, and phone numbers, was passed to some of the biggest names in advertising technology: Facebook, Google, Microsoft, LinkedIn, HubSpot, X, and others. These companies embed tracking pixels on partner and vendor sites to measure ad performance and user behavior. When a form is misconfigured, those pixels can scoop up whatever a user types into it, including credentials.
Klaviyo confirmed the bug was fixed, but its response raises more questions than it answers. A company spokesperson attributed the problem to an “application configuration issue” and claimed fewer than 200 people were affected, based on “readily available active logs.” That qualifier matters. Klaviyo would not say how long it retains logs, which means its 200-person estimate could be a floor, not a ceiling. The company also refused to share a copy of the notification it allegedly sent to affected users, and it never issued a public disclosure.
That silence is a problem. Klaviyo manages over seven billion customer profiles for 205,000 paying clients. Its entire business is built on the promise that it can be trusted with customer data. A form that quietly routes passwords to ad networks is not a minor glitch, it’s a structural failure of the kind that regulators have been watching closely.
This is not an isolated story. Misconfigured tracking pixels have triggered data breach disclosures and regulatory enforcement actions across healthcare, retail, and financial services in recent years. Meta pixel incidents alone resulted in lawsuits and HIPAA investigations. The pattern is consistent: companies install third-party trackers for analytics or advertising, those trackers end up on pages they shouldn’t touch, and sensitive user data leaks out before anyone notices.
The practical takeaway for users is blunt. Ad-blockers and script-blocking browser extensions would have stopped these pixels from running in the first place. Tools like uBlock Origin or privacy-focused browsers are not just about avoiding annoying ads. They are a real defense against this exact class of vulnerability. If a tracker can’t load, it can’t steal your password.
Klaviyo has fixed the bug. But the company still hasn’t explained why it took so long, who knew what and when, or why it chose not to tell the public.