CriticalSecurity & Privacy
Signed up for Klaviyo? Dozens of advertisers may have seen your password
Marketing technology platform Klaviyo exposed customer credentials and sensitive company information to dozens of third-party advertisers and tech giants (Facebook, Google, Microsoft, LinkedIn, X) through a misconfigured web form spanning from February 2024 to November 2025, affecting an estimated 200+ users managing seven billion customer profiles. This incident highlights critical risks of unmanaged third-party trackers and pixels embedded on web properties, exposing enterprises to regulatory scrutiny, customer trust erosion, and potential compliance violations. IT organizations must recognize that vendor security vulnerabilities can cascade into organizational risk when customers' data passes through trusted service providers.

A bug in the tech giant's website mistakenly shared users' sign-up information, including personal data and their password, to third-party companies.