Facebook and Google got a look at the passwords people typed into Klaviyo's signup form. Nobody got hacked. Someone just misconfigured a signup form. And that same mistake could be sitting on your form right now.
Here's what actually happened
Marketing automation company Klaviyo left its signup form misconfigured from around February 2024 through November 2025, possibly longer. Every new signup's email, password, company name, website, and phone number rode a tracking pixel embedded in the form straight to Meta, Google, HubSpot, Microsoft, LinkedIn, and X.
Security researcher Sam Jadali found it. He was testing Klaviyo's signup form through his security startup Melurna, and went to TechCrunch ahead of a scheduled DEF CON talk.
Klaviyo called it an "application configuration issue," said it fixed the bug, and claims it notified affected individuals. But it hasn't disclosed how long it retains logs — so that "under 200" figure could be the real scope, or just what's left in the logs. And there was no public disclosure. TechCrunch called this out directly: it's still unclear why the company didn't disclose.
This isn't just a Klaviyo problem
Tracking pixels swallowing entire form submissions is a pattern that keeps repeating. Put Klaviyo next to its predecessors and it gets scarier.
| Incident | Data exposed | Scale | How it surfaced |
|---|---|---|---|
| Klaviyo (reported 2026) | Email, password, company, phone | Under 200 (unverifiable) | Researcher disclosed before a DEF CON talk |
| Hospital Meta Pixel (2022–) | Medical condition, appointment topic, doctor, email | 6.4M+ across just 3 hospitals | Patient lawsuits, state AG investigation |
| Session replay study (Princeton, 2018) | Prescriptions, grades, passwords | 8,000 sites | University research sweep |
The hospital case still stings. A third of the top 100 hospital websites had Meta Pixel on their appointment and patient-portal pages, and the pixel passed form field names and click data straight to Meta. Novant Health (1.36M patients), Advocate Aurora Health (3M), and WakeMed (495K) all had patient data leak this way, and lawsuits are still ongoing.
Princeton's 2018 research found the same structure. Session replay scripts — tools that log every keystroke and mouse movement — were embedded on 8,000 top sites. Walgreens leaked prescription data. Gradescope leaked student grades. Researchers even found more than four third-party scripts intercepting autofilled browser passwords. Their conclusion: website operators themselves don't know what's leaking from their own sites.
Not this researcher's first find
Sam Jadali also uncovered DataSpii in 2019 — browser extensions that leaked data from Apple, Tesla, Blue Origin, and others to roughly 4 million people, covered extensively by the Washington Post, Wired, and Forbes. This is the second time he's caught a well-known company leaking passwords by accident.
You can check this in five minutes
Klaviyo's mistake didn't come from clever hacking — it came from nobody checking. So checking doesn't require clever hacking either.
- Watch the Network tab yourself
Submit a test value into your signup or login form, then open your browser's dev tools Network tab. Look at requests going to facebook.com, google-analytics.com, doubleclick.net, and similar domains. See if password or personal data values show up in them. - Audit your entire GTM container
If you use Google Tag Manager, go through every tag registered in it. Any tag nobody remembers adding or why is exactly the one to worry about. - Check your Meta Advanced Matching settings
Meta Pixel's manual Advanced Matching hashes data with SHA-256 before sending it. If it's enabled in Events Manager, check exactly which fields are mapped to be collected, and drop anything unnecessary. - Mask sensitive fields
If you run Hotjar, Microsoft Clarity, or similar session replay tools, confirm their built-in field masking is actually turned on. Password, ID number, and card number fields aren't masked by default — you have to check. - Put a recurring audit on the calendar
Don't check once and stop. Every new campaign or tool adds more tags. A quarterly recurring calendar block is the most reliable way to keep up.
Want to go deeper?
The original TechCrunch report Full timeline and Klaviyo's official response techcrunch.com
A response guide for Klaviyo users Practical checklist from changing your password to enabling MFA techrepublic.com
Princeton's session replay research How third-party tracking played out across 8,000 sites citp.princeton.edu
The hospital Meta Pixel scandal, explained What happened when the same pattern hit medical data hipaajournal.com
Keeping GTM GDPR-compliant A practical guide to tag audits and consent management secureprivacy.ai
Meta Pixel's official Advanced Matching docs Exactly what gets collected and how it's hashed developers.facebook.com


.png)
