Canva and Personal Data Protection Authority: Canva breach affects data linked to 424 organizations in Türkiye

Canva and Personal Data Protection Authority: Canva breach affects data linked to 424 organizations in Türkiye

Canva Data Breach Exposes Sensitive Information of 424 Turkish Organizations

A recent data breach at Australian graphic design platform Canva has compromised sensitive information tied to 424 organizations in Türkiye, as confirmed by the country’s Personal Data Protection Authority (KVKK).

The breach stemmed from unauthorized access to a third-party tool used by Canva as a data controller. A threat actor exploited a connection with the platform’s data processor, extracting personal and business-related data belonging to employees of Canva’s customers.

While the exact number of affected individuals in Türkiye remains unclear, the exposed data includes:

  • Personal details (first and last names, work email addresses, workplace locations, and business phone numbers)
  • Business documents (customer order forms, contracts, invoices, data protection agreements, and master service agreements)
  • Routine correspondence conducted through Canva’s platform

The incident highlights the risks of third-party integrations in data processing, with potential implications for corporate security and compliance. The KVKK’s notice did not specify the timeline of the breach or the identity of the threat actor.

Source: https://www.dailysabah.com/business/economy/canva-breach-affects-data-linked-to-424-organizations-in-turkiye

Canva TPRM report: https://www.rankiteo.com/company/canva

Personal Data Protection Authority TPRM report: https://www.rankiteo.com/company/data-protection-authority

"id": "datcan1789743795",
"linkid": "data-protection-authority, canva",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'location': 'Türkiye',
                        'name': '424 organizations in Türkiye',
                        'type': 'Businesses'}],
 'attack_vector': 'Third-party tool exploitation',
 'data_breach': {'data_exfiltration': 'Yes',
                 'file_types_exposed': ['Customer order forms',
                                        'Contracts',
                                        'Invoices',
                                        'Data protection agreements',
                                        'Master service agreements'],
                 'personally_identifiable_information': ['First and last names',
                                                         'Work email addresses',
                                                         'Workplace locations',
                                                         'Business phone '
                                                         'numbers'],
                 'sensitivity_of_data': 'High (personal and business-related '
                                        'data)',
                 'type_of_data_compromised': ['Personal details',
                                              'Business documents',
                                              'Routine correspondence']},
 'description': 'A recent data breach at Australian graphic design platform '
                'Canva has compromised sensitive information tied to 424 '
                'organizations in Türkiye, as confirmed by the country’s '
                'Personal Data Protection Authority (KVKK). The breach stemmed '
                'from unauthorized access to a third-party tool used by Canva '
                'as a data controller. A threat actor exploited a connection '
                'with the platform’s data processor, extracting personal and '
                'business-related data belonging to employees of Canva’s '
                'customers.',
 'impact': {'brand_reputation_impact': 'Potential corporate security and '
                                       'compliance implications',
            'data_compromised': 'Personal and business-related data',
            'systems_affected': 'Canva’s platform and third-party tool'},
 'lessons_learned': 'Highlights the risks of third-party integrations in data '
                    'processing',
 'post_incident_analysis': {'root_causes': 'Unauthorized access to a '
                                           'third-party tool'},
 'references': [{'source': 'Personal Data Protection Authority (KVKK)'}],
 'regulatory_compliance': {'regulatory_notifications': 'KVKK notice issued'},
 'title': 'Canva Data Breach Exposes Sensitive Information of 424 Turkish '
          'Organizations',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Unauthorized access to a third-party data '
                            'processor'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.