
Episode notes
A catch-up episode, recorded after the fact; developments after 23 September are flagged.
Canva's own platform wasn't breached, but enterprise customer contact details and contract documents were exposed through Canny, a customer-feedback tool Canva had connected to its Salesforce CRM.
Timeline. 28 August: Canny tells another customer, VRChat, that an unauthorised party accessed one of its internal systems; VRChat says forensics found no further activity after that date. 29 August: Canny tells Canva it is investigating unauthorised access; Canva removes Canny's Salesforce access immediately. 17 September: Türkiye's data protection authority publishes a notice (board decision dated 16 September) on Canva Pty Ltd's breach notification, saying 424 organisations in Türkiye are affected and the number of individuals is not yet determined; Turkish media report it, with a Canva statement. 21 September: Capital Brief reports the breach.
Data involved. Names, business email addresses, workplace locations and work phone numbers of enterprise customers' staff; and, where shared, order forms, data protection agreements, master service agreements, invoices and business correspondence. Canva says its accounts, passwords, designs and content were not affected. How Canny was breached has not been disclosed; no CVE is involved.
Later (from 23 Sep US time), unverified. DataBreaches.net reported a group calling itself The Seven Deadly Sins listed Canva on a leak site, and in a 26 Sep update said the group had supplied about 3 GB of alleged data, not independently validated. The group's claims of 2M+ Salesforce records and 200M+ warehouse rows are unverified. Whether Canva notified the OAIC is not public.
Lessons. Review every app connected to your CRM and what it can read. Be able to revoke a vendor's access in minutes. Business contact details are personal information under the Privacy Act, and leaked contracts and invoices set up invoice fraud — warn customers early. If you operate internationally, a foreign regulator may publish first.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: Türkiye Personal Data Protection Authority; Türkiye Today; Webtekno; VRChat; Capital Brief; BeyondMachines; DataBreaches.net.
