Klaviyo, a marketing technology company, faced a security issue where its sign-up form unintentionally shared customer information with third-party advertisers and tech platforms.
The Misconfigured Sign-Up Form
Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, identified a configuration error on Klaviyo’s website sign-up page. This problem allowed sign-up data to be transmitted to embedded third-party trackers.
The misconfiguration affected users who signed up between at least February 2024 and November 2025, though it may have persisted longer.
Information Shared with Advertisers
Anyone who used the affected form could have seen their details transmitted to companies whose trackers were present on the Klaviyo site. The transmitted data included the customer’s email address, password, company name, website address, and phone number.
This information reached advertising and technology platforms including Facebook, Google, HubSpot, Microsoft and its subsidiary LinkedIn, the social media site X, and others.
Klaviyo’s Confirmation and Fix
Klaviyo confirmed the issue was fixed after the discovery. The company described the problem as an application configuration issue.
Spokesperson Danielle Zanatta reported that fewer than 200 individuals were known to be affected, based on active logs. The firm notified these people directly but did not provide further details on the outreach or the period the logs covered.
Public disclosure of the incident did not occur, and the reason remains unclear.
Risks from Third-Party Trackers
The incident highlights dangers associated with website trackers known as pixels. These tools normally collect visitor data for analytics and bug detection but can be set up to transmit any personal information entered on the page.
Past cases of misconfigured trackers have led to data breach reports and regulatory actions against various companies. Klaviyo joins other recent examples of organizations that inadvertently exposed user data through their websites.

