Canva confirmed that a security incident at third-party feedback platform Canny exposed limited enterprise customer business contact and contract information after Canny notified Canva on 29 August 2026. Canny was connected to Canva’s Salesforce environment. Canva says its own platform, accounts, passwords, designs, and content were not compromised, that it removed Canny’s access immediately, and that it notified affected customers. Türkiye’s data-protection authority (KVKK) later stated that 424 organisations and institutions in Türkiye were affected, with employee names, business emails, workplace details, phones, and in some cases order forms, DPAs, MSAs, and invoices in scope.
Separately, ransomware group TSDS (Seven Deadly Sins) has claimed Canva on a leak site. That actor listing is not the same as Canva’s confirmed Canny/Salesforce third-party incident and should be read as an unverified claim unless Canva ties it to the same event. Canonical BreachHistory record for the confirmed third-party case: canva-canny-salesforce2026. Primary reporting: Capital Brief, Türkiye Today / KVKK, and TEISS.
What happened in the Canva Canny third-party breach
Canny told Canva on 29 August that it was investigating unauthorized access to Canny’s systems. Because Canny connected into Canva’s Salesforce account, the unauthorized party could reach information that lived in that integration path — primarily larger enterprise customers handled by Canva’s sales team, according to Canva’s statement to Capital Brief.
Canva’s spokesperson language has been consistent across outlets: unauthorized access to Canny allowed access to limited enterprise customer information through the Salesforce connection, including business contact details and contract information; Canva removed Canny’s access; customers were notified; the Canva platform itself was not compromised; accounts, passwords, designs, and content remain secure and were not accessed.
That is a classic vendor–CRM blast radius story. The design tool millions of people open every day is not the system of record that was reached. The sales and feedback tooling that sits beside it was. Enterprise buyers often underestimate how much contract and contact data rides in those adjacent SaaS pipes.
What Türkiye’s KVKK added to the census
On the regulator side, KVKK’s public summary — reported by Türkiye Today — put a concrete organisational count on the Canva data breach for one country: 424 organisations and institutions in Türkiye. The total number of individuals whose personal information was exposed had not yet been determined at that reporting. Compromised information included names, business email addresses, workplace locations, and corporate telephone numbers belonging to employees of companies using Canva.
Where companies had shared business documents with Canva, those could also be in scope: customer order forms, data protection agreements, master service agreements, invoices, and other routine business correspondence. KVKK said a detailed examination was continuing in a decision dated 16 September 2026, and pointed people to Canva’s official help channels for individual status questions.
The 424-organisation figure is a regulator-attested slice, not a global headcount of every Canva enterprise customer worldwide. Global affected-customer totals beyond Türkiye had not been published as a single number in the sources used for this write-up. Treat “424” as the Türkiye census, not as proof that only 424 companies on Earth were touched.
What was not compromised — per Canva
Canva has been explicit about negatives, and those negatives matter for consumer panic triage:
- Canva’s own platform and systems were not compromised
- Canva accounts and passwords were not accessed
- Designs and creative content were not accessed
- The exposure path was third-party Canny via Salesforce-connected enterprise data
If you are a free or pro consumer designer wondering whether your brand kit or password vault inside Canva was dumped, Canva’s attested answer is no. If you are an enterprise procurement or security contact who appears in Salesforce-linked sales records, you are in the risk class Canva is notifying.
How the Canva Salesforce–Canny path works in practice
Feedback tools like Canny typically sync feature requests, account identifiers, and CRM context so product teams can prioritise roadmaps. When that sync is live into Salesforce, a compromise of the feedback vendor can become a compromise of CRM fields the vendor was allowed to see. Canva’s statement does not publish a full Salesforce object inventory for the public, but “business contact details and contract information” is enough for defenders to assume names, work emails, titles, company names, and commercial documents were plausible field classes — matching what KVKK later enumerated for Türkiye.
Root-cause detail inside Canny (stolen admin credentials, vulnerable app, compromised OAuth token, insider, or something else) had not been published in the Canva-facing notices summarised here. What is verified is unauthorized access at Canny, a Salesforce connection as the bridge, Canva’s removal of that access, and customer/regulator notification.
Security teams mapping blast radius should ask a boring question of every design, marketing, and product vendor: which CRM objects does your feedback or NPS tool read, and can that read path be killed in minutes?
TSDS / Seven Deadly Sins leak-site claim — keep it separate
Trade monitoring has also surfaced an unverified ransomware/extortion listing that names Canva under the TSDS (Seven Deadly Sins) brand. Actor leak-site marketing is not a substitute for Canva’s Canny confirmation. Unless and until Canva or a regulator ties that listing to the same intrusion — or confirms a separate compromise — BreachHistory readers should treat TSDS as a separate, unverified claim.
Mixing the two stories is how rumour becomes “Canva was ransomware’d and every design leaked.” Canva’s confirmed incident is third-party Canny access to limited enterprise CRM-side data. The TSDS claim, if it continues, should be tracked on its own facts.
Who is at risk after the Canva Canny breach
Enterprise customers Canva notified. Assume business contacts and contract-related documents associated with your account may be with an unauthorized party. Expect BEC and contract-phishing that references real MSA or invoice details.
Employees named in Türkiye’s 424 organisations. Names, work emails, workplaces, and phones are in the KVKK field list. Smishing and vishing that quote your employer and Canva are likely.
Legal and privacy teams. DPAs and MSAs in attacker hands reveal negotiation positions, subprocessors, and liability language. Watch for fake “amendment” emails that look like Canva legal ops.
Consumer Canva users who were not enterprise sales contacts. Per Canva, platform accounts, passwords, and designs were not accessed. Still ignore phishing that claims your designs were stolen in “the Canva breach.”
Salesforce and Canny admins at other companies. If you use the same feedback-to-CRM pattern, assume attackers will try the same integration path elsewhere. Rotate tokens and review connected-app scopes.
What Canva said — and what remains open
Canva’s public lines emphasise limited enterprise information, Salesforce as the connection point, immediate removal of Canny access, customer notification, and an intact core platform. Capital Brief characterised the incident as potentially significant for enterprise security teams that care about contracts and corporate correspondence even when creative files stay safe.
Open questions include the global count of affected enterprises outside Türkiye, whether any contract PDFs beyond the listed document types were taken, how long unauthorized access lasted inside Canny before 29 August, and whether TSDS’s separate claim intersects this event. Do not invent answers. Watch Canva notices and KVKK follow-ups.
Industry context: third-party feedback tools as CRM doors
2025–2026 breach reporting has been full of CRM-adjacent compromises: marketing sync tools, support desk connectors, conversational AI plug-ins, and feedback widgets that inherit Salesforce or HubSpot privileges. The Canva Canny data breach fits that pattern cleanly. Attackers do not need to crack a design monolith if a smaller vendor with a live CRM token is softer.
For CISOs buying creative SaaS, put feedback and roadmap tools in the same risk tier as CRM itself. Demand logging of every Salesforce connected app, quarterly access reviews, and the ability to revoke without waiting for the vendor’s business hours. Canva’s “we immediately removed Canny’s access” is the control you want pre-negotiated in the contract — not discovered during an incident call.
Compare other supply-chain and third-party incidents in the BreachHistory catalog: the recurring lesson is that “our production database is fine” and “customer commercial data is fine” are different sentences. Canva said the first. Enterprise customers still have work to do on the second.
Action items after the Canva third-party breach
- If Canva contacted you, treat the notice as authoritative for your organisation’s exposure and open a vendor-risk ticket.
- Warn finance and legal that MSA, DPA, invoice, and order-form details may be known to attackers; verify any contract “updates” by phone on a known-good number.
- Brief employees whose work emails or phones may appear in sales records — especially in Türkiye’s 424 organisations — about Canva-branded phishing.
- Do not reset Canva passwords solely because of social posts claiming designs leaked; follow Canva’s official guidance if you were notified.
- Inventory connected apps on your own Salesforce (or HubSpot) instance that resemble Canny — feedback, NPS, productboard-style tools — and revoke stale OAuth.
- Ask Canva and Canny (via official channels) for field inventories relevant to your tenant if you are an affected enterprise.
- Update your DPIA / vendor register to reflect third-party feedback tools as CRM-equivalent processors.
- Track TSDS claims separately until confirmed; do not merge them into your Canny incident report without evidence.
What to do if you only use Canva as a consumer
You are not in the primary enterprise contact/contract exposure class Canva described. Still delete unexpected “Canva security: re-authenticate to save your designs” emails. Open Canva from a bookmark. Enable MFA on your Canva account as ordinary hygiene. Do not upload identity documents to any site that cites this breach as a reason to “verify ownership of your brand kit.”
Canonical record and sources
- BreachHistory — Canva / Canny Salesforce 2026
- Capital Brief — Canva enterprise customer data exposed in third-party breach
- Türkiye Today — KVKK: 424 organisations in Türkiye
- TEISS — Canva reports data breach impacting more than 420 organisations
Timeline of the Canva Canny incident
On or before 29 August 2026. Unauthorized access occurs in Canny’s environment (exact start not published in Canva’s customer-facing quotes summarised here).
29 August 2026. Canny informs Canva it is investigating unauthorized access. Canva removes Canny’s access to its Salesforce-connected data and begins customer notification steps.
Mid-September 2026. KVKK’s process yields a public Türkiye impact figure of 424 organisations and institutions, with a field list covering employee business contacts and selected commercial documents. Canva’s statements continue to stress that the design platform itself was not breached.
September 2026 news cycle. Capital Brief, Türkiye Today, TEISS, and other trade outlets circulate the confirmed third-party narrative. Parallel monitoring notes an unverified TSDS leak-site claim naming Canva — kept distinct in this write-up.
Phishing patterns to expect
- “Your Canva Enterprise MSA needs urgent re-signature after the Canny incident.”
- “Finance: updated bank details for Canva invoice [number matching a real invoice style].”
- “Salesforce connected-app review required — approve Canny re-auth.”
- “KVKK follow-up: upload employee list to confirm you are not in the 424.”
Every one of those can abuse real company names and work emails. Train staff to use official Canva help-centre paths only. Regulators do not ask you to upload full employee rosters to random forms that arrive by SMS.
Enterprise buyer checklist for feedback-tool risk
Before the next renewal, ask creative and product vendors five questions: which CRM objects the feedback tool can read; whether tokens are scoped least-privilege; how fast access can be revoked; whether the vendor will support your incident response with a field-level inventory in 72 hours; and whether contract PDFs are stored in the feedback tool or only referenced by ID. Canva’s breach shows why those questions are not theoretical.
Also push internal product teams that “just connected Canny for roadmap voting” through the same security review as a new Salesforce admin. The business value of feedback aggregation is real. So is the CRM door it opens.
Contract documents as phishing fuel
When DPAs, MSAs, invoices, and order forms leave a vendor’s control, attackers gain more than names and emails. They gain clause numbers, renewal dates, pricing artefacts, and the exact tone of how Canva and a customer write to each other. That material makes business-email-compromise dramatically more convincing. A fake “amendment to Schedule B” that mirrors real language from a stolen MSA will clear busy legal inboxes that delete generic Canva spam.
Finance teams should assume invoice templates and bank-detail change requests will spike for any organisation Canva notified. Use out-of-band verification. Freeze vendor bank-detail changes unless confirmed through a channel established before August 2026. The Canva data breach is as much a payments-fraud story for enterprises as it is a privacy story for employees whose work phones appear in the file.
Privacy counsel in Türkiye and elsewhere should map which employee populations appear in Salesforce contact objects tied to Canva. KVKK’s 424-organisation figure is a starting map for one country, not a global exclusion list.
Why “designs are safe” still needs user education
Canva’s strongest public reassurance — designs and passwords untouched — is easy to lose in headline noise. Social posts that say “Canva breached” without the Canny qualifier will drive password-reset phishing against ordinary users. Security awareness teams at companies that use Canva for marketing should send a short internal note: enterprise contacts may be exposed; creative files are not, per Canva; ignore reset links that cite this news.
That message is kinder than silence. Silence lets attackers define the incident for your staff.
Salesforce connected-app hygiene that would have helped
Regardless of Canny’s internal root cause, every Salesforce customer can reduce parallel risk now: enumerate connected apps weekly during incident seasons; require admin approval for new OAuth scopes; alert when a connected app suddenly exports unusual object volumes; store contract PDFs in a document system with its own DLP rather than attaching every MSA to CRM notes a feedback tool can read. None of those controls rewrite Canva’s incident. All of them shrink the next vendor’s blast radius.
If your security questionnaire for creative SaaS still only asks about SOC 2 and encryption at rest, add a line about CRM integration scope. The Canva Canny Salesforce breach is the worked example.
Closing note
The Canva Canny third-party breach is verified on Canva’s own confirmation: August 29 notice from Canny, Salesforce-connected limited enterprise contact and contract data exposed, platform and designs not compromised, customers notified, and a KVKK-attested 424-organisation impact in Türkiye with named business-contact and document fields. Keep any TSDS leak-site claim in a separate unverified bucket. Harden CRM connected apps, brief legal and finance, and follow the canonical BreachHistory record for updates.