Canny and Canva: Canva enterprise customer data exposed in third-party breach

Canny and Canva: Canva enterprise customer data exposed in third-party breach

Canva Enterprise Customer Data Exposed in Third-Party Breach via Canny

On 29 August, Australian design platform Canva disclosed a security breach involving Canny, a third-party customer feedback tool integrated with its Salesforce account. The unauthorized access exposed limited enterprise customer data, including business contact details and contract information, primarily affecting larger corporate clients managed by Canva’s sales team.

Canva confirmed that its core platform, databases, and user accounts remained secure, with no compromise of passwords, designs, or content. The company revoked Canny’s access immediately and notified affected customers. The incident highlights risks in third-party vendor integrations, particularly for enterprises handling sensitive corporate data.

Canny, the compromised feedback platform, first alerted Canva to the breach, prompting the investigation. While the full scope of the exposed data remains unclear, the breach underscores the growing threat of supply-chain attacks in enterprise security. No further details on the attacker’s identity or motives have been released.

Source: https://www.capitalbrief.com/article/canva-enterprise-customer-data-exposed-in-third-party-breach-b926931e-7c1b-4c1e-9f55-a3354cb0a1ed/

Canny cybersecurity rating report: https://www.rankiteo.com/company/cannyhq

Canva cybersecurity rating report: https://www.rankiteo.com/company/canva

"id": "CANCAN1789935961",
"linkid": "cannyhq, canva",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Enterprise customers (larger '
                                              'corporate clients)',
                        'industry': 'Design/Technology',
                        'location': 'Australia',
                        'name': 'Canva',
                        'size': 'Large',
                        'type': 'Company'}],
 'attack_vector': 'Third-party vendor integration (Canny)',
 'customer_advisories': 'Notified affected enterprise customers',
 'data_breach': {'personally_identifiable_information': 'Business contact '
                                                        'details',
                 'sensitivity_of_data': 'Limited (no passwords, designs, or '
                                        'content)',
                 'type_of_data_compromised': 'Business contact details, '
                                             'contract information'},
 'date_detected': '2024-08-29',
 'date_publicly_disclosed': '2024-08-29',
 'description': 'Australian design platform Canva disclosed a security breach '
                'involving Canny, a third-party customer feedback tool '
                'integrated with its Salesforce account. The unauthorized '
                'access exposed limited enterprise customer data, including '
                'business contact details and contract information, primarily '
                'affecting larger corporate clients managed by Canva’s sales '
                'team. Canva confirmed that its core platform, databases, and '
                'user accounts remained secure, with no compromise of '
                'passwords, designs, or content. The company revoked Canny’s '
                'access immediately and notified affected customers.',
 'impact': {'data_compromised': 'Business contact details and contract '
                                'information',
            'systems_affected': 'Salesforce account integrated with Canny'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Highlights risks in third-party vendor integrations and '
                    'supply-chain attacks in enterprise security',
 'post_incident_analysis': {'root_causes': 'Third-party vendor (Canny) '
                                           'compromise'},
 'references': [{'source': 'Canva Disclosure'}],
 'response': {'communication_strategy': 'Notified affected customers',
              'containment_measures': 'Revoked Canny’s access immediately'},
 'title': 'Canva Enterprise Customer Data Exposed in Third-Party Breach via '
          'Canny',
 'type': 'Third-party breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.