Skip to main content
CanvaSecurity incident

Third-party data breach linked to Canva affects 424 organizations in Türkiye

What happened

Canva suffered a data breach affecting 424 organizations in Türkiye after a third-party tool it uses, Canny, experienced unauthorized access to its systems.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

A data breach involving Canva has affected 424 organizations and institutions operating in Türkiye, exposing personal information and corporate documents, according to the country's Personal Data Protection Authority, known by its Turkish abbreviation KVKK. Canva Pty Ltd, the company acting as the data controller, notified the authority after unauthorized access took place through a third-party system used by the platform. According to the initial assessment, threat actors exploited a connection involving a data processor and managed to take data out of the system. While 424 organizations and institutions in Türkiye were directly affected, the total number of individuals whose personal information was exposed has not yet been determined. A Canva spokesperson said: "Canny, a third-party tool Canva uses to collect product feedback, recently informed us of unauthorized access to its systems. Importantly, Canva's platform and systems were not compromised, and Canva accounts, passwords, designs and content remain secure. The unauthorized access to Canny may have allowed access to some limited routine business and contact information through its connection to our customer relationship tool. We immediately removed Canny's access and have taken the appropriate steps to notify affected customers and regulators where required." Breach reached employee and corporate records The...

Keep reading with a free account

The rest of this article, and every signal for Canva, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Location
Turkey

Companies

  • CannyRelated companycanny.io

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Unauthorized access to third-party tool Canny, used by Canva to collect product feedback, which may have allowed access to routine business and contact information through its connection to Canva's customer relationship tool. Compromised...

Extraction

Confidence
90%
Detected
Sep 18, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Canva and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Canva this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/989d2d25-bc9c-49cf-b7b7-6c8fee461895 returns this record as JSON. POST /v1/companies/enrich returns every signal for canva.com.

{
  "signal_id": "989d2d25-bc9c-49cf-b7b7-6c8fee461895",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-18T06:18:05+00:00",
  "company": {
    "name": "Canva",
    "domain": "canva.com"
  },
  "data": {
    "url": "https://www.turkiyetoday.com/business/third-party-data-breach-linked-to-canva-affects-424-organizations-in-turkiye-3228330",
    "title": "Third-party data breach linked to Canva affects 424 organizations in Türkiye - Türkiye Today",
    "excerpt": "A data breach involving Canva has affected 424 organizations and institutions operating in Türkiye, exposing personal information and corporate documents, according to the country's Personal Data Protection Authority, known by its Turkish abbreviation KVKK. Canva Pty Ltd, the company acting as the data controller, notified the authority after unauthorized access took place through a third-party system used by the platform. According to the initial assessment, threat actors exploited a connection involving a data processor and managed to take data out of the system. While 424 organizations and institutions in Türkiye were directly affected, the total number of individuals whose personal information was exposed has not yet been determined. A Canva spokesperson said: \"Canny, a third-party tool Canva uses to collect product feedback, recently informed us of unauthorized access to its systems. Importantly, Canva's platform and systems were not compromised, and Canva accounts, passwords, designs and content remain secure. The unauthorized access to Canny may have allowed access to some limited routine business and contact information through its connection to our customer relationship tool. We immediately removed Canny's access and have taken the appropriate steps to notify affected customers and regulators where required.\" Breach reached employee and corporate records The...",
    "summary": "Canva suffered a data breach affecting 424 organizations in Türkiye after a third-party tool it uses, Canny, experienced unauthorized access to its systems.",
    "location": "Türkiye",
    "planning": false,
    "image_url": "https://img.turkiyetoday.com/images/2026/9/17/turkiyes-data-authority-reveals-canva-breach-affecting-424-organizations-3228330_20260917122344.jpeg",
    "confidence": 0.9,
    "published_at": "2026-09-18T06:18:05Z",
    "location_data": [
      {
        "region": "Western Asia",
        "country": "Turkey",
        "continent": "Asia",
        "fuzzy_match": false
      }
    ],
    "vulnerability": "Unauthorized access to third-party tool Canny, used by Canva to collect product feedback, which may have allowed access to routine business and contact information through its connection to Canva's customer relationship tool. Compromised information included names, business email addresses, workplace locations, corporate telephone numbers, and business documents.",
    "article_sentence": "A data breach involving Canva has affected 424 organizations and institutions operating in Türkiye, exposing personal information and corporate documents, according to the country's Personal Data Protection Authority, known by its Turkish abbreviation KVKK.",
    "related_company_name": "Canny",
    "related_company_domain": "canny.io"
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.