Klaviyo, a prominent marketing automation platform, recently disclosed a security incident involving the unauthorized exposure of user passwords. The breach resulted in a scenario where certain advertisers were inadvertently granted access to view the login credentials of other users.
The incident stemmed from a flaw in access control management within the platform’s administrative interface. Under specific conditions, advertisers were able to access authentication data belonging to other accounts, a configuration error that compromised internal data protections.
Klaviyo has implemented a fix for the vulnerability and is currently in the process of notifying all affected users. In the wake of this exposure, the company strongly urges all users to reset their passwords and enable two-factor authentication (2FA). Strengthening platform-wide access controls and internal security governance has become an urgent priority for the company.