← Klarna

2025 Klarna — cache configuration data exposure

2025 Unknown records affected Share on X

Data compromised

Names, dates of birth, addresses, ZIP codes, cities, states

Technical writeup

Klarna confirmed customer data leak Nov 2025. Incorrect cache configuration caused credit application form to serve cached data from other users—names, DOB, addresses, ZIP, city, state. 'Rare scenario' rather than system-wide breach; actual impact ~99% lower than initial 288K theoretical estimate. Company declined to disclose exact number affected.

Root cause

Incorrect cache configuration; improper cache key handling

References