Key Takeaways

  • Klaviyo leaked passwords to Facebook, Google, LinkedIn, X and other ad giants for nearly two years
  • Company claims fewer than 200 affected but refuses to disclose log retention or bug duration
  • No public breach notification despite sharing credentials with advertising giants
  • Pixel tracker architecture makes this inevitable, not accidental

A marketing technology giant entrusted with seven billion customer profiles spent at least twenty-two months feeding new users' passwords directly into the advertising surveillance machine. Not metadata. Not hashed identifiers. Plaintext passwords. Klaviyo's sign-up form, misconfigured from February 2024 through November 2025, transmitted every credential — email, password, company name, website, phone number — to whichever tracker happened to sit on the page. Facebook. Google. HubSpot. Microsoft. LinkedIn. X. The list reads like a who's who of companies that already know too much about everyone.

Security researcher Sam Jadali found the leak. His startup Melurna tested the form and watched the data flow. Klaviyo confirmed the fix but little else. A spokesperson called it an "application configuration issue" and claimed fewer than two hundred people were affected, based on "readily available active logs." That phrase does heavy lifting. It admits nothing about archived logs, backup retention, or the true window of exposure. The bug likely predates February 2024. Klaviyo won't say how far back its logs reach. It won't say how long the bug actually lived. It notified the known victims but refuses to show TechCrunch the notification. No public disclosure. No regulator filing. Just a quiet patch and a carefully worded statement.

This is not a novel failure. Misconfigured tracking pixels have caught hospital systems, tax preparation services, and consumer brands in recent years. Each pixel is a tiny spy placed voluntarily on a page. When developers forget to exclude form fields from the data stream, the spy reads everything. Passwords. Social security numbers. Medical symptoms. The architecture guarantees recurrence. Companies embed dozens of trackers for attribution, retargeting, analytics, and vanity metrics. Each additional pixel expands the blast radius of a single mistake. Klaviyo hosted trackers from direct competitors in the marketing stack. HubSpot received Klaviyo sign-ups. Microsoft received Klaviyo sign-ups. The data didn't just leak; it landed in the laps of rivals.

Klaviyo's scale magnifies the negligence. Two hundred five thousand paying customers. Seven billion profiles under management. A company that processes this volume of commercial communication treats its own authentication boundary as an afterthought. The password field should never have been readable by client-side JavaScript, let alone transmitted to third-party endpoints. Basic security hygiene — scoping tracker access, implementing Content Security Policy, automating form-field exclusion — would have prevented this. Klaviyo either lacked the competence or the discipline to apply it.

The response pattern is familiar. Minimize the count. Narrow the timeframe. Cite "active logs" as if forensic completeness follows from convenience. Refuse transparency. Hope the news cycle moves on. But passwords change the calculus. A leaked email address enables spam. A leaked password enables account takeover, credential stuffing, and lateral movement across every service where the user reused it. Klaviyo cannot know the downstream damage. Neither can Facebook, Google, or LinkedIn. They simply ingested the feed.

Regulators have fined companies for pixel leaks under GDPR and state breach laws. The FTC has acted on unfair practices when data flows contradicted privacy promises. Klaviyo's silence on public disclosure suggests legal counsel has not yet forced its hand. That may change. But the deeper problem remains structural. The advertising ecosystem demands total visibility. Trackers are designed to hoover behavior. When a password field sits on the same DOM, the hoover catches it. No amount of vendor vetting or contractual prohibition fixes the root cause. The only fix is architectural: stop loading third-party code on authentication surfaces. Period.

Klaviyo's customers — the 205,000 businesses paying for email and SMS campaigns — should ask what else runs on Klaviyo's pages. What trackers sit on the campaign builder? The analytics dashboard? The contact import wizard? The same configuration discipline that failed on the sign-up form likely governs the entire property. A company that leaks passwords to X cannot be trusted with campaign data, segmentation logic, or subscriber lists.

The industry treats these episodes as bugs. They are not bugs. They are the predictable output of a business model that treats user data as exhaust gas — a byproduct to be captured, packaged, and sold. Klaviyo's sign-up page was a funnel. The trackers were the intended recipients. The only error was including the password field in the payload. Next time it will be a different field. A different company. A different tracker. The architecture guarantees it.