Passwords in Plain Sight: Klaviyo's Data Leak Highlights Deeper Security Risks The latest security scare to hit the tech world involves marketing giant Klaviyo, whose sign up page inadvertently shared sensitive information – including passwords – with outside advertisers.
The incident occurred between February 2024 and November 2025.
An investigation into the data leak reveals that it was not a hacking attack or a malicious intent driven breach, but rather a misconfigured web form that allowed Klaviyo to share user sign up information with third party tech giants and advertisers, including Facebook, Google, HubSpot, Microsoft, and LinkedIn.