Skip to main content

KlarnaKlarna identity-verification flaw let recycled phone numbers access prior owners' accounts, initially feared to expose up to 288,000 logins

In November 2025, Klarna disclosed that its login system failed to promptly detect when mobile carriers reassigned phone numbers to new customers, in a small subset of cases letting the new number's owner access the previous owner's account. Internal Slack messages reviewed by Business Insider showed Klarna initially estimated up to 288,000 customer logins could be affected, with a potential legal cost of up to $41.8 million. Klarna's own investigation and public statement (November 7, 2025) concluded actual confirmed impact was far smaller - fewer than a few thousand accounts - and that only names, emails and addresses were exposed, not payment card data. Klarna implemented one-time-passcode login as a fix.

Scoring Impact

TopicDirectionRelevanceContribution
Data Security-againstprimary-1.00
User Privacy-againstsecondary-0.50
Overall incident score =-0.102

Score = avg(topic contributions) × significance (low ×0.5) × confidence (0.54)× agency (negligent ×0.5)

Evidence (2 signals)

Confirms Statement Nov 21, 2025 documented

Business Insider: Internal Klarna messages show scramble to fix recycled-phone-number data leak, feared up to 288,000 logins exposed

Business Insider reviewed internal Slack messages showing Klarna's initial worst-case internal estimate of up to 288,000 exposed customer logins and a potential $41.8M legal exposure, before the confirmed impact was found to be far smaller.

Partial Statement Nov 7, 2025 verified

Klarna official statement: update on recent incident reported in the media

Klarna's own press statement confirmed the recycled-phone-number vulnerability and the OTP-based fix, while disputing the scale of the initial internal worst-case estimate and stating actual confirmed impact was far smaller (no card data exposed).

Related: Same Topics