Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Klaviyo Leaked Customer Passwords to Google, Meta and X for Nearly Two Years, Researchers Find

Klaviyo, the Boston-based marketing platform used by more than 205,000 paying businesses, spent at least 21 months leaking new customers' passwords to some of the biggest advertising companies on the internet.
Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, found that Klaviyo's signup web form was misconfigured from at least February 2024 through November 2025, and possibly longer than that. Jadali shared his findings with TechCrunch ahead of a presentation at the Def Con security conference in Las Vegas.
The bug meant that when someone signed up for a Klaviyo account, their email address, password, company name, website, and phone number could be transmitted to any third-party tracker embedded on Klaviyo's site. TechCrunch reported those trackers belonged to Facebook, Google, Microsoft and its LinkedIn subsidiary, HubSpot, and X.
These trackers, often called pixels, are supposed to help companies measure ad performance and site traffic. They are not supposed to vacuum up passwords. When a pixel is misconfigured, it can scrape whatever data sits on the page it's tracking, including data typed into signup forms.
Klaviyo says it's fixed and small
Klaviyo confirmed to TechCrunch that it has patched the bug. Company spokesperson Danielle Zanatta described it as an "application configuration" problem and said fewer than 200 individuals were affected, based on the company's "readily available active logs."
That number should raise eyebrows on its own. Klaviyo would not tell TechCrunch how far back its logs actually extend, which means nobody outside the company can verify whether 200 is the real count or just the count Klaviyo happens to still have records for. A bug active for nearly two years, on a signup form used by a platform managing more than 7 billion customer profiles according to Klaviyo's own website, invites more scrutiny than a one-line spokesperson statement provides.
Klaviyo told TechCrunch it notified the affected individuals. It declined to provide a copy of that notification when asked. It's also unclear why Klaviyo never disclosed the incident publicly before Jadali's research forced the issue into the open.
Not disclosed, not a first-time problem industry-wide
There's no evidence Klaviyo tried to hide the bug maliciously. Misconfigured pixels are a known, recurring problem across the tech industry. Companies have filed data breach disclosures over similar tracker mishaps before, and regulators have taken enforcement action in past cases involving leaked personal data through third-party trackers, according to TechCrunch's reporting.
But "known industry problem" doesn't excuse the lack of transparency here. A password is not like a leaked email address or phone number. Passwords authenticate access to whatever else that address or password combination might unlock elsewhere, especially if reused across services. If Klaviyo genuinely believes only 200 people were affected, it should be willing to show its work: how far back the logs go, what timeframe was actually audited, and what the notification to affected customers said. So far it hasn't done any of that.
The financial angle nobody should ignore
The timing matters for another reason. Klaviyo reported second-quarter 2026 earnings on August 5, posting $370.6 million in revenue, up 26% year-over-year, according to Whalesbook's market coverage. Despite that growth, the company's stock came under pressure because gross margins compressed on rising text-messaging and carrier fees, and Klaviyo lowered its full-year non-GAAP operating income guidance to a range of $212 million to $218 million, citing acquisition integration costs and AI product spending.
A security lapse that surfaces the same week a company is already fielding tough investor questions about margins is not a good look, regardless of how many people were technically affected. Whether this incident triggers any regulatory inquiry remains an open question. No investigation has been announced by any regulator as of this writing, and Klaviyo has not said whether it expects one.
What's actually unresolved
The reporting from TechCrunch, and separately corroborated by Zamin.uz citing the same TechCrunch findings, is consistent on the core facts: the bug existed for at least 21 months, the leaked data included passwords, and Klaviyo says it's fixed now. What's missing from every account, including Klaviyo's own statement, is any independent verification of the "fewer than 200" figure, or clarity on when exactly the bug started.
Until Klaviyo releases its log retention policy or a third party audits the actual exposure window, customers who signed up during that nearly two-year stretch have no way to know if their credentials were among those leaked. Anyone who created a Klaviyo account between early 2024 and late 2025 and reused that password elsewhere would be wise to change it now.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.