Signed up for Klaviyo? Dozens of advertisers may have seen your password
Security researchers at Melurna told TechCrunch that Klaviyo’s sign-up form was misconfigured from at least Feb 2024 to Nov 2025, potentially sending new customers’ emails and passwords to third-party advertisers and tech trackers embedded on its site, including Google, Facebook, HubSpot, Microsoft/LinkedIn, and X. Klaviyo said it fixed the issue and that fewer than 200 people were affected, based on active logs.
How this was made

The 30-second read
Why it matters
If regulators or customers treat this as a data breach involving credentials, Klaviyo may face additional disclosures, compliance costs, and reputational harm. Traders may also watch for any further reporting on affected scope, log retention, and remediation effectiveness.
Market read
A confirmed credential-exposure risk event for a US-listed martech platform can trigger compliance and reputational repricing, even with a small claimed affected count.
What to watch
The article does not quantify downstream misuse, breach confirmation, or whether passwords were actually exposed to advertisers in a usable way; those details could materially change risk.
Background
Security research alleges Klaviyo’s sign-up form misconfiguration caused customer sign-up data to be shared with third-party trackers embedded on its site.
Ticker impact
Klaviyo confirmed a misconfigured sign-up web form (Feb 2024 to Nov 2025) that could share new customers’ emails and passwords with third-party advertisers.
Near-term downside risk from heightened scrutiny and potential follow-on disclosures; magnitude depends on any incremental details on affected scope and remediation.
The article discloses a confirmed configuration bug, includes sensitive data types (passwords), and notes uncertainty around how far back logs go and how many users were affected, which can drive risk repricing even without quantified financial impact.
Market effects
Highlights systemic risk from embedded trackers and misconfigurations in marketing-technology stacks, potentially pressuring peers’ security reviews and compliance messaging.
Primarily US-focused investor sentiment for SaaS and martech, with potential spillover to US-listed ad-tech and CRM vendors.
Could reinforce broader regulatory and enforcement attention on data handling and third-party pixel governance across jurisdictions.
Counterpoint
Klaviyo says it fixed the bug and claims fewer than 200 known individuals affected, which may limit financial damage if regulators accept remediation and scope.
Key entities
- companyKlaviyo
Marketing-technology firm whose sign-up form allegedly shared customer emails and passwords with third-party advertisers via embedded trackers.
- companyMelurna
Cybersecurity startup whose co-founder reported the misconfiguration findings to TechCrunch.
- companyFacebook
Third-party advertiser/tracker named as receiving sign-up data in the alleged misconfiguration.
- companyGoogle
Third-party advertiser/tracker named as receiving sign-up data in the alleged misconfiguration.
- companyHubSpot
Marketing platform named as receiving sign-up data in the alleged misconfiguration.

