Skip to main content

My account was accessed via a IP in the US (i am UK based).  They managed to access my account and add 500k profiles and send 2 coinbase phishing campaigns from my account.   I had 2 factor authentication set up and have absolutely no idea how this happened.  How can I stop it from happening again.  I was lock out of my account and lost the majority of my profile list.  I had 80k profiles.

Thank you for reaching out ​@Sah , This breach could result from compromised login credentials or a vulnerability in your security setup. Update your password immediately, review API keys for misuse, and enable IP whitelisting if supported. Ensure 2FA is using an authenticator app rather than SMS for added security. If the issue persists, contact Klaviyo support to investigate and secure your account further. Feel free to reach out for implementation help if needed.