Observed Signal · May 28, 2021 · Data Breach · Source: OnlineMarketing.de · Impact: 2/5 · Sentiment: Negative

Klarna data leak exposed thousands of user accounts

Executive Signal Summary

A human error during a Klarna app update briefly exposed other users' accounts and personal data. The bug caused some users to access data such as phone numbers, purchase histories, and addresses, and the app was taken offline about 30 minutes after the issue was detected. Klarna stated the incident was fixed after roughly 31 minutes and is auditing which users were affected; authorities were informed. Klarna denied that credit card or bank details were exposed unencrypted, though some users asserted they could see such information. The company noted that publicly visible data were not considered 'sensitive' under GDPR, while stressing the seriousness of the incident and its commitment to restoring consumer trust.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Significant data exposure incident affecting Klarna users; substantial but not industry-shifting.

SIGNAL RADAR

Track Klarna Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Data leak in Klarna app allowed access to other users' accounts and data due to a human error during an update.
  • Bug fixed after about 31 minutes; app briefly offline to prevent further damage.
  • Klarna stated around 9,500 customer accounts were affected; a spokesperson claimed up to 90,000 were affected.
  • Authorities were informed; Klarna denied unencrypted exposure of credit card or bank details.
  • Publicly visible data included personal information; Klarna said these were not 'sensitive' under GDPR.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: OnlineMarketing.de•Published: May 28, 2021
Original Coverage Title: “Klarna: Tausenden User-Daten für andere einsehbar | OnlineMarketing.de”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

PrivacyAug 10, 2026

Klaviyo leak exposed some sign-up passwords to advertisers

Security research by Melurna found that a misconfigured sign-up web form on Klaviyo’s site allowed new-customer sign-up information — including email addresses, passwords, company name, website and phone number — to be shared with third-party trackers and advertisers. The misconfiguration was present between at least February 2024 and November 2025, researchers told TechCrunch. Affected third parties reportedly included Facebook, Google, HubSpot, Microsoft/LinkedIn and X. Klaviyo said it fixed the issue and told TechCrunch the number of known affected individuals was fewer than 200 based on active logs; the company would not disclose how far back logs go or publicly share the customer notification. The findings were shared with TechCrunch ahead of a Def Con talk by the researchers.

Read assessment
Security / Data BreachJun 24, 2026

LastPass Customer Data Stolen via Klue Breach

Password manager LastPass is handling a data breach after attackers accessed customer information by compromising a third‑party market intelligence platform, Klue. Klue detected unauthorized activity on 2026-06-12 and says attackers likely used old, compromised credentials for an integration service. Through that access, attackers viewed LastPass support tickets containing customer names, phone numbers, email addresses, home addresses, support-case details and sales-relevant information; payment data included in support tickets may also have been exposed. LastPass says its internal systems and user vaults were not compromised, and it is notifying affected users by email. Actions taken include suspending Klue employees’ access to LastPass data, rotating API access tokens, and planning additional protections. Users are advised to monitor payment activity and consider changing associated email addresses to reduce phishing risk.

Read assessment
Market Research & Consumer Panel (data breach at market intelligence provider)Jun 22, 2026

Klue hack exposes customer data across cybersecurity firms

Market intelligence provider Klue disclosed a cyberattack that allowed hackers to exfiltrate customer data from connected cloud systems. Klue said intruders gained access on June 12 using a “compromised legacy credential” tied to an integration tool that links customers’ cloud data (such as Salesforce) to Klue. The cybercrime group Icarus claimed responsibility and threatened to publish the stolen data if a ransom is not paid. Multiple Klue customers — including Gong, Jamf, HackerOne, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, Insurity and Huntress — have confirmed data theft of business contact and some account information. Klue engaged CrowdStrike for incident response and disconnected integrations to block further access. The company has not disclosed how many customers were affected or how the credentials were obtained.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.