← Klaviyo

2022 Klaviyo — phishing-led employee account compromise; crypto-customer marketing lists exfiltrated

2022 Unknown records affected Share on X

Data compromised

Marketing list fields for targeted crypto-related customer accounts per Klaviyo

Technical writeup

Klaviyo stated attackers phished employee credentials and exported marketing-list data for a focused set of cryptocurrency-industry customers; the company forced rotations and published an incident blog.

Root cause

Phishing leading to employee session/account compromise

References