Canva Enterprise Data Exposed in Canny Breach

A third-party software provider experienced a security incident that impacted some Canva business customer information.

Updated on Sept. 20, 2026 in Cybersecurity

Isometric editorial illustration of disconnected matte blocks representing a severed digital connection and system breach.
Canva discovered unauthorized access to its enterprise data via a third-party software provider, Canny, prompting an immediate isolation of its systems. AI Illustration. Upload story photo >

Live Poll

Do you trust that your company's sensitive data remains secure when shared with third-party software vendors?

On 29 August 2026, Canny notified Canva of unauthorized access to systems linked to Canva's Salesforce account. The breach exposed business contact and contract details for some enterprise customers.

Why it matters

The incident highlights the risks associated with third-party software integrations, where access to a connected platform can inadvertently expose sensitive enterprise data. Canva moved to isolate its systems to prevent further unauthorized access.

The unauthorized party utilized a connection to Canva's Salesforce account to obtain business contact and contract details. Canva's core product databases, user accounts, passwords, and creative designs were not compromised during the incident.

The players

Canva

Canva is a global online graphic design platform used for creating social media graphics, presentations, and other visual content.

Canny

Canny is a software provider that offers customer feedback and product roadmap management tools for businesses.

The details

The breach occurred through Canny's integration, allowing an external party to view specific enterprise-level customer data. Canva responded by immediately removing Canny's access to its internal systems upon discovery.

Timeline

  1. 29 August 2026: Canny informed Canva about the unauthorized system access.

The Tech Race

This breach underscores the critical vulnerability of modern API-based ecosystems where interconnected services create new attack surfaces. It follows the pattern of supply chain attacks identified by the Cybersecurity and Infrastructure Security Agency, proving that third-party integrations are now a primary target for unauthorized access.

Enterprise customers should review their account activity and third-party integration settings to ensure data access is limited to necessary services. While core passwords remain secure, business users should remain vigilant for phishing attempts using the exposed contact information.

The takeaway

Maintaining tight control over third-party API permissions is essential for modern businesses relying on software ecosystems. Regularly auditing these connections can help prevent unauthorized parties from exploiting service integrations to harvest corporate data.

Further reading

For more information on digital safety, visit our Cybersecurity section.

Live Poll

Do you trust that your company's sensitive data remains secure when shared with third-party software vendors?

Canva Enterprise Data Exposed in Canny Breach