Security News

Cybersecurity news aggregator

HIGH Vulnerabilities SC Media

Klaviyo data leak: Customer sign-up info, including passwords, shared with advertisers

A misconfigured web form on Klaviyo's sign-up page allowed third-party trackers embedded on the site to access and exfiltrate sensitive customer data, including passwords, email addresses, and phone numbers, to external advertisers. The vulnerability was active from at least February 2024 until November 2025. Klaviyo has confirmed the bug is fixed but has not disclosed full details of the incident's scope or duration.
Read Full Article →

Data Security Klaviyo data leak: Customer sign-up info, including passwords, shared with advertisers August 10, 2026 Share By SC Staff (Adobe Stock) Marketing tech giant Klaviyo was inadvertently sharing new customer sign-up information, including passwords, with outside advertisers due to a misconfigured web form. Melurna Co-founder Sam Jadali discovered the issue, which affected users between at least February 2024 and November 2025, though the exact duration is unknown. This incident highlights the ongoing data risks associated with third-party trackers embedded on websites, with further coverage provided by TechCrunch. The misconfiguration on Klaviyo's sign-up page allowed any third-party trackers present on the site to potentially access and share sensitive customer data. This data included email addresses, passwords, company names, website addresses, and phone numbers. Advertisers and tech giants such as Facebook, Google, HubSpot, Microsoft, LinkedIn, and X were among those who could have received this information. Klaviyo has since confirmed the bug has been fixed, stating that fewer than 200 individuals were affected based on available logs. However, the company has not disclosed how far back its logs are stored or the precise timeframe the vulnerability was active, nor has it publicly announced the incident. Source: TechCrunch SC Staff Related Encryption HP ThinPro vulnerability allows physical attackers to bypass disk encryption SC Staff August 10, 2026 A vulnerability in HP ThinPro 8 and 9 operating systems allows attackers with physical access to bypass TPM-backed full-disk encryption and recover the key securing the device's root partition. Data Security Israeli population registry data from 2005 resurfaces on dark web SC Staff August 10, 2026 A vendor, identified as "Gordon Freeman," advertised a 7.5 GB database allegedly containing national ID numbers, addresses, phone numbers, birth and death dates, and family links for nearly all Israeli citizens. Data Security Researchers bypass Spectre v2 mitigations SC Staff August 7, 2026 The attack exploits a time-of-neutralization to time-of-use (TONTOU) window in Spectre v2 defenses, where a gap exists between when the branch predictor is isolated and when it is used. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bit Block Cipher Ciphertext Cryptographic Algorithm or Hash Cryptographic Hash Functions Data Encryption Standard (DES) Digital Envelope Digital Signature Digital Signature Algorithm (DSA) Digital Signature Standard (DSS) You can skip this ad in 5 seconds

Share this article