top of page
background.jpg

​

Canva Data Breach: Corporate Documents of 424 Organizations in Türkiye Exposed

Sep 21
2 min read

The Turkish Personal Data Protection Authority (GDPR) issued a statement regarding a data breach involving Canva. The breach reportedly exposed employees’ names, business email addresses, workplace locations, phone numbers, as well as certain corporate documents.


A significant data breach occurred at online graphic design platform Canva. According to the notification published by the Turkish Personal Data Protection Authority (GDPR), data associated with 424 organizations in Türkiye was affected.


The breach occurred as a result of unauthorized access through a third-party tool, leading to the exfiltration of certain personal data. In addition to information such as names and phone numbers, contracts, invoices, and corporate documents uploaded to Canva were exposed. The affected data also included customer order forms, data protection agreements, master service agreements, and other routine business correspondence. Such information may be highly sensitive for organizations.


The data breach notification stated that data associated with 424 organizations in Türkiye was affected, while the exact number of individuals impacted by the breach has not yet been determined.

GDPR stated that affected individuals may contact Canva for further information regarding the breach. Users can reach Canva through its Help Center or via email at privacy@canva.com.

 

According to the data breach notification submitted to GDPR by Canva Pty Ltd, acting as the data controller:


  • The breach occurred as a result of unauthorized access to a third-party tool used by the data controller. It is believed that the threat actor exfiltrated certain personal data through the connection with the data processor.

  • Data associated with 424 organizations in Türkiye was affected, while the number of affected individuals has not yet been determined.

  • The compromised personal data included employees’ names, business email addresses, workplace locations, and business phone numbers. Where shared with the data controller, customer order forms, contracts, invoices, data protection agreements, master service agreements, and other routine business correspondence were also affected.

  • Affected individuals can obtain further information about the breach through Canva’s Help Center or by contacting privacy@canva.com.


Some of the measures we should take to protect against this type of attack include:


  • Access permissions granted to third-party applications and integrations should be restricted.

  • MFA (Multi-Factor Authentication) should be enabled for corporate accounts.

  • Sensitive corporate documents should only be stored on authorized and trusted platforms.

  • The principle of least privilege should be applied to users and applications.

  • The security and data-processing practices of third-party services should be regularly reviewed and audited.

  • Suspicious sessions and data access activities should be logged and monitored.

  • Incident response and access revocation procedures should be established and kept ready for potential data breaches.


For more information, you can contact our experts at  info@zerosecond.ae.


 
 
 

Comments


bottom of page