Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers

    August 11, 2026

    5 Best AI Tools & How To Use AI In 2026

    August 11, 2026

    With a feel for physics, AI models simulate a wider range of real-world scenarios | MIT News

    August 11, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers
    Cybersecurity

    Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers

    InfoForTechBy InfoForTechAugust 11, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Klaviyo has fixed a website configuration bug that may have exposed new customers’ sign-up data, including passwords, to third-party trackers embedded on its site.

    The company says fewer than 200 people are known to have been affected based on its readily available active logs. That figure is not a final total, because Klaviyo has not said how far back those logs extend or exactly how long the misconfiguration remained live.

    What the Klaviyo sign-up bug may have exposed

    TechCrunch reported that security researcher Sam Jadali, co-founder of Melurna, found the Klaviyo sign-up form was misconfigured from at least February 2024 through November 2025 and possibly longer. Melurna’s testing found that sign-up data may have been shared with trackers operated by companies including Meta, Google, HubSpot, Microsoft, LinkedIn, and X.

    The information reportedly included email addresses, passwords, company names, website addresses, and phone numbers. The reporting describes a browser-side data exposure involving trackers, not evidence that attackers breached Klaviyo’s customer database.

    Klaviyo attributed the bug to an “application configuration issue” and said it notified the people it identified as affected. The company did not tell TechCrunch how far back its active logs go, meaning the fewer-than-200 figure cannot be treated as the total number affected across the full period identified by Melurna.

    The reporting concerns Klaviyo’s own account-registration form, rather than consumer sign-up forms run by retailers using the platform. For businesses whose credentials may have been exposed, the immediate concern is account takeover, particularly when a password was reused or MFA was not enabled.

    What Klaviyo customers and IT teams should do now

    Anyone who created a Klaviyo account during the reported window should change the password. If the same credential was used elsewhere, reset those accounts too because password reuse can enable credential-stuffing attacks.

    Teams should use a password manager to generate unique credentials and review whether MFA is enabled. Klaviyo’s account-security guidance recommends both unique passwords and MFA.

    Organizations should also review third-party scripts on registration and login pages and verify that sensitive fields are excluded from analytics and advertising data flows.

    Klaviyo’s Activity Log gives administrators a searchable record of edits and other account changes, but it covers activity inside an account rather than data sent from the public registration page.

    Until Klaviyo discloses its log-retention window or a complete incident timeline, fewer than 200 people are currently known to be affected while the full scope remains unresolved.

    Also read: Fake The Odyssey downloads are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Network Forensics: Techniques, Tools & Best Practices

    August 10, 2026

    Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

    August 10, 2026

    Google Restores Blogger Sites After Malware False Positives

    August 10, 2026

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    August 9, 2026

    Runaway AI Agents, Cyberattacks, and Power Shifts Define the Week in Tech

    August 9, 2026

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    August 9, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026209 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026209 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.