VMTech
Discuss a project

Klaviyo fixes sign-up configuration issue involving tracker data

Klaviyo fixes sign-up configuration issue involving tracker data

Klaviyo has fixed an application configuration issue on its sign-up page after security research found that information entered by new customers, including passwords, could be shared with third-party trackers embedded on the site. The Boston-based marketing technology company said fewer than 200 individuals are known to have been affected, based on its readily available active logs.

Security researcher Sam Jadali, co-founder of cybersecurity startup Melurna, said the sign-up form was misconfigured from at least February 2024 through November 2025, and possibly for longer. Melurna presented the findings ahead of a Def Con security conference talk in Las Vegas.

What information could have been shared

Tests by Melurna indicated that people using the affected form may have had their email address and password shared with third parties whose tracking technologies were present on Klaviyo’s website. The data could also include a company name, website address and phone number.

The organizations named in the research include Facebook and Google, HubSpot, Microsoft and its LinkedIn subsidiary, and X. Klaviyo confirmed that it remediated the issue and described it as an application configuration problem. It said known affected individuals had been notified, but did not state how far back its logs extend or how long the bug was active.

Why tracker configuration matters

Website and application trackers, often called pixels, are commonly used to understand visitor activity, measure campaigns and identify technical problems. Their presence on a page also makes configuration controls important: if a tracker is allowed to collect form content, sensitive data entered by a user can be transmitted beyond the service operating the form.

The incident is notable because Klaviyo provides email, text-message and other campaign tools to 205,000 paying customers and says it manages more than seven billion customer profiles. The reported exposure concerned prospective customers using its own registration process rather than the profiles managed through its platform.

Controls for registration pages

Organizations should treat sign-up, login and account-recovery pages as high-sensitivity areas when deploying analytics and advertising tags. Reviewing which scripts run on those pages, what fields they can observe, and whether data is transmitted externally can reveal risks that are not visible in routine campaign reporting.

A practical business implication is to keep password and other sensitive form fields outside all third-party collection paths, test those controls after website changes, and maintain logs sufficient to determine scope and notify affected users if a configuration failure occurs.

#cybersecurity#dataprivacy#websecurity#martech
Open analytics
On the site 0 views
min read 3 10.08.2026
Instagram

Klaviyo fixes sign-up configuration issue involving tracker data

Open the post on Instagram ↗