Skip to main content
← Back to market wire
FundingTechCrunch

Signed up for Klaviyo? Dozens of advertisers may have seen your password

A bug in the tech giant's website mistakenly shared users' sign-up information, including personal data and their password, to third-party companies.

Desk analysis

AI-assisted2 min read

Klaviyo's sign-up page was supposed to be the beginning of a business relationship. For some users, it became an unsolicited disclosure.

This was not a sophisticated intrusion. The company's own website shared sign-up information—including a password—with third-party companies. The distinction matters: nobody broke in. The front door was wired to broadcast.

The word 'dozens' is the quiet part. A sign-up form has no legitimate reason to tell dozens of outside companies anything. Yet the advertising ecosystem is built on the opposite assumption: every visitor is a signal, and every signal can be monetized. This is what happens when those pipes merge with something sensitive.

A password makes the situation materially worse. It is master-key logic. Once it appears in a data flow shared with other parties, all later assurances are moot. It can be logged, stored, copied, and replayed without leaving a trace at the source.

For every company running a comparable marketing stack, this incident is less a scandal than a diagram. The same tags that power personalization can power leaks. There is no clean line between 'our data' and 'their scripts' unless someone deliberately builds one.

Klaviyo can force password resets and patch the bug. The rest of the industry will continue as before. But the underlying mechanism—a website quietly handing secrets to parties the user never met—remains standard architecture. It will happen again.