Klaviyo inadvertently shared customer passwords with Facebook, Google
This digest was compiled by AI from multiple sources — links to the originals are below.

Klaviyo inadvertently shared customer sign-up information, including passwords, with advertisers due to a misconfigured web form. The issue, discovered by Melurna co-founder Sam Jadali, affected fewer than 200 individuals between at least February 2024 and November 2025. Advertisers such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X could have accessed the data.
The Misconfiguration
Klaviyo's sign-up page contained a misconfiguration that allowed any third-party tracker embedded on the site to capture and share customer data. The vulnerability was discovered by Melurna co-founder Sam Jadali and was active from at least February 2024 to November 2025. The exact start and end dates remain unknown due to limited log retention by Klaviyo.
Exposed Information
The shared data included email addresses, passwords, company names, website addresses, and phone numbers. Advertisers such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X were among those potentially receiving the information. Klaviyo stated that fewer than 200 individuals were affected based on available logs.
Company Response
Klaviyo confirmed that the bug has been fixed but did not publicly disclose the incident. The company has not revealed how long it stores logs or the precise timeframe the vulnerability was exploited. No announcement was made, and affected users have not been notified as of reporting.
What's Next
The misconfiguration has been corrected, but Klaviyo's lack of public disclosure leaves questions about data handling and notification practices. It remains unclear whether any third parties actually accessed or misused the exposed data.
1 source
Klaviyo inadvertently shared customer passwords with Facebook, Google



