Canva disclosed that attackers accessed data through a compromised connection involving Canny, a product-feedback vendor and data processor, affecting information associated with 424 organizations and institutions in Türkiye. The intrusion reached Canny’s environment and data available through its connection to Canva’s customer-relationship tool; Canva said its own platform was not compromised and that user accounts, passwords, designs, and other user content remain secure. The company revoked Canny’s access, notified affected customers and regulators where required, and Türkiye’s Personal Data Protection Board (KVKK) is investigating; the number of affected individuals has not been disclosed.
The extortion group calling itself The Seven Deadly Sins (TSDS) claimed it accessed Canva through Canny’s Salesforce integration beginning in late August, obtained administrative access, and exported data before making a ransom demand. TSDS alleged the theft included more than 2 million Salesforce CRM records and over 200 million data-warehouse rows, including enterprise orders, contracts, customer and billing records, and PDFs, while also claiming compromises of other SaaS environments. Those claims, including the asserted scale and scope of stolen data, remain unverified.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
TSDS claimed it sent Canva a ransom demand on August 28 after allegedly extracting data from the company's accessible Salesforce and data-warehouse environments. A TSDS spokesperson separately told DataBreaches that the group attacked Canva on that date, although the claims were unverified.
The Seven Deadly Sins (TSDS) claimed it compromised Canva feedback vendor Canny beginning on August 26 and used its integration to obtain administrator access to Canva's Salesforce environment. TSDS alleged it remained in the environment for more than 72 hours and exported Salesforce and product-data records; these claims were not independently verified.
Canva removed Canny's access following the incident and said it notified affected customers and regulators where required. Türkiye's Personal Data Protection Authority was notified, and the Personal Data Protection Board opened an investigation.
Canva disclosed that attackers exploited a compromised connection involving a Canny data processor and extracted data accessible through Canny's connection to Canva's customer-relationship tool. The company said the incident potentially affected information associated with 424 organizations and institutions in Türkiye, while its own platform, user accounts, passwords, designs, and other user content were not compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.