- Klaviyo inadvertently shared new customers' sign-up information, including passwords, with third-party advertisers and tech giants due to a misconfigured web form.
- The security flaw exposed sensitive data such as email addresses, company names, and phone numbers to companies like Meta, Google, and Microsoft from February 2024 through November 2025.
- Klaviyo confirmed fixing the application configuration issue and notified fewer than 200 affected individuals, though the total impact and duration of the leak remain unclear.