Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers
Klaviyo has fixed a website configuration bug that may have exposed new customers’ sign-up data, including passwords, to third-party trackers embedded on its site.
The company says fewer than 200 people are known to have been affected based on its readily available active logs. That figure is not a final total, because Klaviyo has not said how far back those logs extend or exactly how long the misconfiguration remained live.
What the Klaviyo sign-up bug may have exposed
TechCrunch reported that security researcher Sam Jadali, co-founder of Melurna, found the Klaviyo sign-up form was misconfigured from at least February 2024 through November 2025 and possibly longer. Melurna’s testing found that sign-up data may have been shared with trackers operated by companies including Meta, Google, HubSpot, Microsoft, LinkedIn, and X.
The information reportedly included email addresses, passwords, company names, website addresses, and phone numbers. The reporting describes a browser-side data exposure involving trackers, not evidence that attackers breached Klaviyo’s customer database.
Klaviyo attributed the bug to an “application configuration issue” and said it notified the people it identified as affected. The company did not tell TechCrunch how far back its active logs go, meaning the fewer-than-200 figure cannot be treated as the total number affected across the full period identified by Melurna.
The reporting concerns Klaviyo’s own account-registration form, rather than consumer sign-up forms run by retailers using the platform. For businesses whose credentials may have been exposed, the immediate concern is account takeover, particularly when a password was reused or MFA was not enabled.
What Klaviyo customers and IT teams should do now
Anyone who created a Klaviyo account during the reported window should change the password. If the same credential was used elsewhere, reset those accounts too because password reuse can enable credential-stuffing attacks.
Teams should use a password manager to generate unique credentials and review whether MFA is enabled. Klaviyo’s account-security guidance recommends both unique passwords and MFA.
Organizations should also review third-party scripts on registration and login pages and verify that sensitive fields are excluded from analytics and advertising data flows.
Klaviyo’s Activity Log gives administrators a searchable record of edits and other account changes, but it covers activity inside an account rather than data sent from the public registration page.
Until Klaviyo discloses its log-retention window or a complete incident timeline, fewer than 200 people are currently known to be affected while the full scope remains unresolved.
Also read: Fake The Odyssey downloads are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.

