Klaviyo exposes passwords to advertisers in data breach
Klaviyo exposed users' passwords in plain text to third-party advertisers due to a bug in its website code from late June to July 2. The company invalidated exposed passwords and emailed users reset โฆ
A bug in marketing-automation platform Klaviyo accidentally exposed usersโ sign-up detailsโincluding passwordsโto third-party advertisers, the company confirmed on Tuesday. The flaw, now fixed, sent personal data and credentials to outside vendors for roughly a week before Klaviyo detected and shut it down.
The issue stemmed from Klaviyoโs website code. When someone signed up, the page briefly fired off a hidden tracking request that carried the new userโs email, phone number, and plain-text password to third-party analytics firms. Klaviyo stores passwords securely in its database, but the bug transmitted them unencrypted during the sign-up flow. Security researchers said the mistake highlights how even reputable platforms can leak credentials if session or tracking code isnโt rigorously audited.
Klaviyo did not say how many accounts were affected, but its incident report suggests the problem lasted from late June until July 2. A spokeswoman said the exposed passwords were immediately invalidated and users were emailed password-reset links. Outside experts reviewing the incident noted that plain-text transmission of passwords is unusual for a SaaS vendor of Klaviyoโs size and called for clearer disclosure of data-sharing practices during onboarding.
Klaviyo has hired a third-party forensic firm and plans to brief regulators in the U.S. and EU about the breach. Affected users should update their passwords and enable two-factor authentication. The episode underscores the ongoing risk of credential leakage in signup flows and may prompt regulators to scrutinize how marketing platforms handle personal data during onboarding.
Read Full Story at TechCrunch โ


