AI Weekly Malaysia

Back to items Summaries

Signed up for Klaviyo? Dozens of advertisers may have seen your password

ID
12681
Status
summarized
Published
10 Aug 2026, 10:14 PM
Fetched
11 Aug 2026, 12:34 AM
Provider
TechCrunch
Category
technology
Original URL
https://techcrunch.com/2026/08/10/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password/
Source URL
https://techcrunch.com/feed/

Summary

Score
5.5
Created
11 Aug 2026, 12:37 AM
Tags
Audience
developerssaas_founders

What happened

Security researcher Sam Jadali found that Klaviyo's sign-up page was misconfigured from at least February 2024 through November 2025, leaking new customers' email addresses, passwords, company names, websites, and phone numbers to third-party trackers from Facebook, Google, HubSpot, Microsoft, LinkedIn, X, and others. Klaviyo confirmed the bug was fixed but has not disclosed how many of its 205,000 paying customers were affected. The findings were presented at Def Con in Las Vegas.

Why it matters

If you embed third-party tracking pixels (Facebook, Google, HubSpot, etc.) on pages with sensitive form fields, audit whether those pixels can read or transmit form input values — this incident shows the exact failure mode where a misconfigured form leaked passwords to advertisers for nearly two years. Anyone running SaaS signup or onboarding flows with marketing pixels should verify pixel scope and consider blocking trackers on sensitive pages.

Discussion angle

How to audit your own signup/onboarding pages for pixel over-collection — what defensive measures (Content Security Policy, pixel scoping, blocking trackers on auth pages) should be standard practice for SaaS builders?

Top