New research reveals that until recently, Klaviyo was inadvertently sharing users' sign-up information, including passwords, with third-party advertisers. The misconfiguration affected customers between February 2024 and November 2025.
The security flaw meant that sensitive data like email addresses, company names, websites and phone numbers could be exposed to tech giants such as Facebook, Google, HubSpot, Microsoft, LinkedIn and X. Klaviyo has fixed the issue but questions remain about the extent of the breach.
This incident highlights the risks posed by misconfigured tracking pixels on websites, which can share personal data without user consent. With over 205,000 paying customers, Klaviyo’s bug is a stark reminder of the vulnerabilities in our digital world.
The company has confirmed that fewer than 200 people were affected but refused to disclose more details or provide communications with those impacted. It's unclear why such an incident wasn't made public sooner.
This case underscores the importance of robust data handling practices and the need for transparency in tech companies when it comes to user privacy.







