threat_intelligence212 wordsRead on Arc Codex

Klaviyo data leak: Customer sign-up info, including passwords, shared with advertisers

Marketing tech giant Klaviyo was inadvertently sharing new customer sign-up information, including passwords, with outside advertisers due to a misconfigured web form. Melurna Co-founder Sam Jadali discovered the issue, which affected users between at least February 2024 and November 2025, though the exact duration is unknown. This incident highlights the ongoing data risks associated with third-party trackers embedded on websites, with further coverage provided by TechCrunch.The misconfiguration on Klaviyo's sign-up page allowed any third-party trackers present on the site to potentially access and share sensitive customer data. This data included email addresses, passwords, company names, website addresses, and phone numbers. Advertisers and tech giants such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X were among those who could have received this information.Klaviyo has since confirmed the bug has been fixed, stating that fewer than 200 individuals were affected based on available logs. However, the company has not disclosed how far back its logs are stored or the precise timeframe the vulnerability was active, nor has it publicly announced the incident.TechCrunch Source: Data Security Klaviyo data leak: Customer sign-up info, including passwords, shared with advertisers (Adobe Stock) Related Events Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.