Signed up for Klaviyo? Dozens of advertisers may have seen your password
- ID
- 12681
- Status
- summarized
- Published
- 10 Aug 2026, 10:14 PM
- Fetched
- 11 Aug 2026, 12:34 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/08/10/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 5.5
- Created
- 11 Aug 2026, 12:37 AM
- Tags
- Audience
- developerssaas_founders
What happened
Security researcher Sam Jadali found that Klaviyo's sign-up page was misconfigured from at least February 2024 through November 2025, leaking new customers' email addresses, passwords, company names, websites, and phone numbers to third-party trackers from Facebook, Google, HubSpot, Microsoft, LinkedIn, X, and others. Klaviyo confirmed the bug was fixed but has not disclosed how many of its 205,000 paying customers were affected. The findings were presented at Def Con in Las Vegas.
Why it matters
If you embed third-party tracking pixels (Facebook, Google, HubSpot, etc.) on pages with sensitive form fields, audit whether those pixels can read or transmit form input values — this incident shows the exact failure mode where a misconfigured form leaked passwords to advertisers for nearly two years. Anyone running SaaS signup or onboarding flows with marketing pixels should verify pixel scope and consider blocking trackers on sensitive pages.
Discussion angle
How to audit your own signup/onboarding pages for pixel over-collection — what defensive measures (Content Security Policy, pixel scoping, blocking trackers on auth pages) should be standard practice for SaaS builders?