DTWdailytechwire
Tech Intelligence, Wired Daily
Policy

Marketing Platform Klaviyo Leaked Customer Passwords to Dozens of Ad Trackers

A misconfigured sign-up form exposed email addresses, passwords, and company details to Facebook, Google, LinkedIn, and other third-party advertisers for nearly two years.

AS
Arjun S. Mehta
AI Correspondent · Bengaluru
Aug 11, 2026
6 min read
Marketing Platform Klaviyo Leaked Customer Passwords to Dozens of Ad Trackers
Marketing Platform Klaviyo Leaked Customer Passwords to Dozens of Ad TrackersCredit: Timon Schneider / Getty Images

A Configuration Flaw at Scale

Between February 2024 and November 2025, every new customer who registered for Klaviyo may have unknowingly shared their account credentials with an array of advertising platforms. The marketing automation company, which manages over seven billion customer profiles for 205,000 paying clients, left its sign-up form configured in a way that allowed third-party tracking pixels to capture sensitive registration data.

Sam Jadali, co-founder of cybersecurity startup Melurna, identified the flaw while examining how major platforms handle user data during onboarding. The issue centered on how Klaviyo's website integrated common advertising trackers. These snippets of code, embedded to measure marketing performance and user behavior, were positioned to observe everything entered into the registration form, including plaintext passwords, email addresses, company names, website URLs, and phone numbers.

The data flowed to Facebook, Google, HubSpot, Microsoft, LinkedIn, X, and several other platforms whose tracking infrastructure was present on Klaviyo's pages. For companies building email and SMS campaigns through Klaviyo, this meant their initial account setup leaked directly to the same advertising ecosystems they likely planned to use for customer outreach.

The Tracker Problem Nobody Wants to Discuss

Tracking pixels have become ubiquitous infrastructure for digital marketing. They allow website owners to measure conversion rates, attribute ad spend, and retarget visitors across the web. But when these trackers sit on pages that collect sensitive information, configuration mistakes can turn analytics tools into accidental data conduits.

At DailyTechWire, we've tracked a pattern of similar incidents over the past three years. Healthcare providers, financial platforms, and SaaS companies have all filed breach disclosures after discovering that pixel trackers were sweeping up form data never intended for third-party eyes. Regulators in Europe and several U.S. states have begun treating these leaks as violations of privacy law, issuing fines and consent orders.

The technical mechanism is straightforward. Most tracking pixels fire events when users interact with a page, such as clicking a button or submitting a form. If the pixel script is configured to capture all page elements or if it runs before form data is encrypted and sent to the server, it can scoop up whatever the user just typed. In Klaviyo's case, the configuration allowed the tracker to observe form fields that should have been isolated from external observation.

Klaviyo described the issue as an "application configuration" problem, a phrasing that suggests the trackers themselves were operating as designed but were placed or triggered incorrectly within the site's architecture.

Scope and Notification Gaps

Klaviyo said fewer than 200 individuals were affected, based on logs the company still retains. That figure raises more questions than it answers. The vulnerability was active for at least 21 months, a period during which Klaviyo would have onboarded thousands of new customers. The company declined to specify how long it retains access logs or whether older records were purged, leaving open the possibility that the true number of affected users is far higher.

The company also said it notified known affected individuals but would not share a copy of that communication. There has been no public disclosure, no security advisory on Klaviyo's website, and no filing with regulators that would trigger broader awareness. For a company operating at Klaviyo's scale, with access to billions of customer profiles across its client base, the opacity around incident response is notable.

Most data breach notification laws in the U.S. hinge on whether "personal information" was accessed by unauthorized parties. Passwords and email addresses typically meet that threshold. The fact that this data went to ad platforms rather than malicious hackers may have influenced Klaviyo's legal assessment, but the distinction matters little to users whose credentials are now sitting in the data lakes of multiple tech giants.

What Happens to Leaked Passwords

Once a password leaves a secure environment, its lifecycle becomes unpredictable. Advertising platforms generally do not store form field data in the same way they store behavioral signals like clicks or page views. But the data passes through their infrastructure, often logged temporarily for debugging or compliance purposes.

If any of the affected users reused their Klaviyo password across other services, the exposure widens considerably. Credential stuffing attacks, in which stolen username and password pairs are tested against thousands of sites, remain one of the most common methods for account takeover. Even a small leak can seed large-scale attacks if the credentials are later aggregated with other datasets.

For Klaviyo's customers, the risk extends beyond personal accounts. The leaked data included company names, websites, and phone numbers, enough to build a profile of which businesses are using Klaviyo's platform and when they joined. Competitors, threat actors, or aggressive sales operations could find value in that intelligence.

The Defensive Posture Users Must Adopt

This incident underscores a reality that security teams have been repeating for years: users cannot rely on websites to protect their data from third-party trackers. Ad-blocking browser extensions, privacy-focused browsers, and script-blocking tools like uBlock Origin or Privacy Badger can prevent many trackers from loading in the first place.

For businesses evaluating marketing platforms, the Klaviyo case offers a checklist question: does the vendor's sign-up and login flow isolate sensitive form fields from analytics and advertising scripts? Many vendors now use techniques like hashing email addresses before sending them to trackers, or isolating password fields entirely from any client-side JavaScript. Klaviyo's configuration suggests those safeguards were either absent or improperly implemented.

Password managers, which generate unique credentials for every service, limit the damage when one password leaks. Two-factor authentication adds a second line of defense, though it does nothing to prevent the initial credential exposure.

A Pattern, Not an Anomaly

Klaviyo is not an outlier. In the past year alone, multiple healthcare providers have disclosed that Meta's pixel captured patient appointment details and prescription information. Tax preparation sites have leaked income data. Financial platforms have exposed account balances. Each incident follows the same script: a tracker was embedded on a page with sensitive forms, the configuration was not reviewed carefully, and data flowed out for months or years before discovery.

The regulatory response has been inconsistent. The European Data Protection Board has issued guidance stating that sending personal data to third-party trackers without explicit consent violates GDPR. Some U.S. states with comprehensive privacy laws, like California and Colorado, have begun treating these leaks as unauthorized disclosures. But enforcement remains patchy, and many companies continue to embed trackers on sensitive pages without conducting regular audits.

For platforms like Klaviyo, which operate at the intersection of marketing technology and data infrastructure, the stakes are especially high. Their customers trust them with enormous volumes of end-user data. A misconfigured tracker on their own website suggests a gap in internal security review processes, raising questions about how rigorously they audit the rest of their stack.

The Unasked Questions

Klaviyo fixed the configuration flaw, but the company has not explained how the misconfiguration occurred, why it persisted for nearly two years, or what changes have been made to prevent similar issues. There is no indication that the company conducted a broader audit of other pages where trackers might pose similar risks.

The affected advertising platforms have not commented on what data they received, how long they retained it, or whether they have purged the leaked credentials from their systems. Facebook, Google, LinkedIn, and the others operate under their own data retention policies, which vary by jurisdiction and product. Users affected by the Klaviyo leak have no direct recourse to demand deletion from those downstream recipients.

For now, the incident serves as another data point in a growing body of evidence that third-party trackers, however useful for marketing attribution, carry risks that most companies are not equipped to manage. The defaults are dangerous, the documentation is often vague, and the consequences of misconfiguration can remain hidden until a researcher decides to look.

Read next
Policy

Amazon Powers AI Growth With Natural Gas, Raising Climate Questions

Daniel R. Whitfield · 5 min
Policy

Portugal's Aptoide Returns to Google Play After a Decade, Breaking Android's Store Monopoly

Arjun S. Mehta · 5 min
Policy

Google Play Now Distributes Competitor App Stores After Court-Ordered Remedy

Daniel R. Whitfield · 5 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.