Canva Data Breach Exposes Personal and Corporate Data of 424 Turkish Organizations
A data breach at Canva has compromised the personal and corporate information of 424 organizations and institutions in Türkiye, according to a disclosure by the country’s Personal Data Protection Authority (KVKK). The incident, reported by Canva Pty Ltd as the data controller, occurred after threat actors exploited a vulnerability in a third-party system connected to the platform.
The breach exposed employee records, including names, business email addresses, workplace locations, and corporate phone numbers. Additionally, sensitive business documents such as customer order forms, data protection agreements, master service agreements, and invoices were accessed by unauthorized parties. While the full scope of affected individuals remains unclear, the KVKK confirmed that its investigation is ongoing, with a decision issued on September 16.
Canva has directed users to its official support channels for further details on potential exposure. The breach highlights the risks of third-party integrations in data security.
Canva cybersecurity rating report: https://www.rankiteo.com/company/canva
"id": "CAN1789648331",
"linkid": "canva",
"type": "Breach",
"date": "1/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'location': 'Türkiye',
'name': '424 organizations and institutions in Türkiye',
'type': 'Organizations/Institutions'}],
'attack_vector': 'Third-party system vulnerability',
'customer_advisories': 'Canva directed users to its official support channels '
'for further details on potential exposure',
'data_breach': {'file_types_exposed': ['Customer order forms',
'Data protection agreements',
'Master service agreements',
'Invoices'],
'personally_identifiable_information': ['Names',
'Business email '
'addresses',
'Workplace locations',
'Corporate phone '
'numbers'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal and corporate data'},
'date_publicly_disclosed': '2023-09-16',
'description': 'A data breach at Canva has compromised the personal and '
'corporate information of 424 organizations and institutions '
'in Türkiye, after threat actors exploited a vulnerability in '
'a third-party system connected to the platform. The breach '
'exposed employee records, including names, business email '
'addresses, workplace locations, and corporate phone numbers, '
'as well as sensitive business documents such as customer '
'order forms, data protection agreements, master service '
'agreements, and invoices.',
'impact': {'brand_reputation_impact': 'High',
'data_compromised': 'Employee records (names, business email '
'addresses, workplace locations, corporate '
'phone numbers), sensitive business documents '
'(customer order forms, data protection '
'agreements, master service agreements, '
'invoices)',
'identity_theft_risk': 'High'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Highlights the risks of third-party integrations in data '
'security',
'post_incident_analysis': {'root_causes': 'Third-party system vulnerability'},
'references': [{'source': 'Personal Data Protection Authority (KVKK)'}],
'regulatory_compliance': {'regulations_violated': ['Personal Data Protection '
'Law (KVKK)'],
'regulatory_notifications': 'Reported to KVKK'},
'response': {'communication_strategy': 'Canva directed users to its official '
'support channels for further details'},
'title': 'Canva Data Breach Exposes Personal and Corporate Data of 424 '
'Turkish Organizations',
'type': 'Data Breach',
'vulnerability_exploited': 'Third-party system vulnerability'}