Observed Signal · Aug 10, 2026 · Security Incident · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Klaviyo leak exposed some sign-up passwords to advertisers
Security research by Melurna found that a misconfigured sign-up web form on Klaviyo’s site allowed new-customer sign-up information — including email addresses, passwords, company name, website and phone number — to be shared with third-party trackers and advertisers. The misconfiguration was present between at least February 2024 and November 2025, researchers told TechCrunch. Affected third parties reportedly included Facebook, Google, HubSpot, Microsoft/LinkedIn and X. Klaviyo said it fixed the issue and told TechCrunch the number of known affected individuals was fewer than 200 based on active logs; the company would not disclose how far back logs go or publicly share the customer notification. The findings were shared with TechCrunch ahead of a Def Con talk by the researchers.
A major MarTech provider inadvertently exposed sensitive sign-up data via third-party trackers, illustrating systemic privacy risks from embedded pixels and weakening trust in marketing automation and email platforms.
Track Klaviyo Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- A misconfigured Klaviyo sign-up web form sent new-customer sign-up data to third-party trackers between at least February 2024 and November 2025.
- Shared sign-up fields reportedly included users' email addresses, passwords, company name, website address, and phone number.
- Third parties that received the data included Facebook, Google, HubSpot, Microsoft (and LinkedIn), and X.
- Klaviyo confirmed it fixed the website bug and said fewer than 200 known individuals were affected based on readily available active logs.
- Security researcher Sam Jadali and his startup Melurna shared findings with TechCrunch ahead of a Def Con talk.
Connected Companies & Entities
8 Entities mapped“Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information o...”
“This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsi...”
“This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsi...”
“This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsi...”
“This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsi...”
“This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsi...”
“The startup shared its findings with TechCrunch ahead of its talk at the Def Con security conference in Las Vegas....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Klue hack exposes customer data across cybersecurity firms
Market intelligence provider Klue disclosed a cyberattack that allowed hackers to exfiltrate customer data from connected cloud systems. Klue said intruders gained access on June 12 using a “compromised legacy credential” tied to an integration tool that links customers’ cloud data (such as Salesforce) to Klue. The cybercrime group Icarus claimed responsibility and threatened to publish the stolen data if a ransom is not paid. Multiple Klue customers — including Gong, Jamf, HackerOne, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, Insurity and Huntress — have confirmed data theft of business contact and some account information. Klue engaged CrowdStrike for incident response and disconnected integrations to block further access. The company has not disclosed how many customers were affected or how the credentials were obtained.
LastPass Customer Data Stolen via Klue Breach
Password manager LastPass is handling a data breach after attackers accessed customer information by compromising a third‑party market intelligence platform, Klue. Klue detected unauthorized activity on 2026-06-12 and says attackers likely used old, compromised credentials for an integration service. Through that access, attackers viewed LastPass support tickets containing customer names, phone numbers, email addresses, home addresses, support-case details and sales-relevant information; payment data included in support tickets may also have been exposed. LastPass says its internal systems and user vaults were not compromised, and it is notifying affected users by email. Actions taken include suspending Klue employees’ access to LastPass data, rotating API access tokens, and planning additional protections. Users are advised to monitor payment activity and consider changing associated email addresses to reduce phishing risk.
Klue: 2022 Credential Used in Customer Data Breaches
Market research firm Klue confirmed that a credential issued in 2022 for a limited pilot was used by hackers in June 2026 to steal data from multiple corporate customers, including LastPass and several cybersecurity companies. Klue detected the intrusion on June 12, 2026, and disclosed the incident on June 23, 2026. Attackers leveraged access to Klue’s systems — which store OAuth tokens used to access customer data in other clouds and databases — to download data and extort impacted companies. Klue says the credential was originally provided to a third party for a pilot in 2022 but has not explained why it wasn’t revoked or what type of credential it was. A group calling itself Icarus claimed responsibility and threatened to publish the stolen data. Klue says it is conducting a comprehensive review of credential management, vendor access controls, monitoring and deployment security.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
