Categories: Technology

Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers


Klaviyo has fixed a website configuration bug that may have exposed new customers’ sign-up data, including passwords, to third-party trackers embedded on its site.

The company says fewer than 200 people are known to have been affected based on its readily available active logs. That figure is not a final total, because Klaviyo has not said how far back those logs extend or exactly how long the misconfiguration remained live.

What the Klaviyo sign-up bug may have exposed

TechCrunch reported that security researcher Sam Jadali, co-founder of Melurna, found the Klaviyo sign-up form was misconfigured from at least February 2024 through November 2025 and possibly longer. Melurna’s testing found that sign-up data may have been shared with trackers operated by companies including Meta, Google, HubSpot, Microsoft, LinkedIn, and X.

The information reportedly included email addresses, passwords, company names, website addresses, and phone numbers. The reporting describes a browser-side data exposure involving trackers, not evidence that attackers breached Klaviyo’s customer database.

Klaviyo attributed the bug to an “application configuration issue” and said it notified the people it identified as affected. The company did not tell TechCrunch how far back its active logs go, meaning the fewer-than-200 figure cannot be treated as the total number affected across the full period identified by Melurna.

The reporting concerns Klaviyo’s own account-registration form, rather than consumer sign-up forms run by retailers using the platform. For businesses whose credentials may have been exposed, the immediate concern is account takeover, particularly when a password was reused or MFA was not enabled.

What Klaviyo customers and IT teams should do now

Anyone who created a Klaviyo account during the reported window should change the password. If the same credential was used elsewhere, reset those accounts too because password reuse can enable credential-stuffing attacks.

Teams should use a password manager to generate unique credentials and review whether MFA is enabled. Klaviyo’s account-security guidance recommends both unique passwords and MFA.

Organizations should also review third-party scripts on registration and login pages and verify that sensitive fields are excluded from analytics and advertising data flows.

Klaviyo’s Activity Log gives administrators a searchable record of edits and other account changes, but it covers activity inside an account rather than data sent from the public registration page.

Until Klaviyo discloses its log-retention window or a complete incident timeline, fewer than 200 people are currently known to be affected while the full scope remains unresolved.

Also read: Fake The Odyssey downloads are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.



Source link

24timenews.com

Recent Posts

Hadco Experiences Welcomes Visitors to Explore a New Side of Trinidad and Tobago | News

HADCO Experiences is inviting travellers to uncover a different side of Trinidad, one of the…

37 minutes ago

Rare 1958 Ferrari 250 GT Cabriolet Has $5 Million Estimate

RM Sotheby’s lists the 1958 Ferrari 250 GT Cabriolet Series I with a $4–5 million…

1 hour ago

1 in 5 people may carry this hidden genetic heart risk

New findings from more than 20,000 patients across three major NIH studies suggest that elevated…

1 hour ago

Complimentary UAE Entry Visas for Indian Tourists in Abu Dhabi, ETTravelWorld

The Department of Culture and Tourism - Abu Dhabi (DCT Abu Dhabi) has launched a…

11 hours ago

This Lamborghini Diablo Restomod Has No Roof, A V12, And A Manual

This year at Monterey Car Week, Eccentrica is taking its bonkers Lamborghini Diablo restomod to…

11 hours ago

New GLP-1 pill delivers up to 12% weight loss in 36 weeks

A new oral approach to GLP-1 treatment helped adults with obesity or overweight lose as…

11 hours ago