Skip to content
Canva breach hit 424 organizations in Türkiye, data authority says

Canva breach hit 424 organizations in Türkiye, data authority says

Turkiyetoday September 17, 2026

A data breach involving Canva has affected 424 organizations and institutions operating in Türkiye, exposing personal information and corporate documents, according to the country's Personal Data Protection Authority, known by its Turkish abbreviation KVKK.

Canva Pty Ltd, the company acting as the data controller, notified the authority after unauthorized access took place through a third-party system used by the platform. According to the initial assessment, threat actors exploited a connection involving a data processor and managed to take data out of the system.

While 424 organizations and institutions in Türkiye were directly affected, the total number of individuals whose personal information was exposed has not yet been determined.

A Canva spokesperson said: "Canny, a third-party tool Canva uses to collect product feedback, recently informed us of unauthorized access to its systems. Importantly, Canva's platform and systems were not compromised, and Canva accounts, passwords, designs and content remain secure. The unauthorized access to Canny may have allowed access to some limited routine business and information through its connection to our customer relationship tool. We immediately removed Canny's access and have taken the appropriate steps to notify affected customers and regulators where required." Breach reached employee and corporate records

The compromised information included names, business email addresses, workplace locations and corporate telephone numbers belonging to employees of companies using Canva.

The breach also extended to business documents that companies had shared with Canva, where applicable. These included customer order forms, data protection agreements, master service agreements, invoices and other routine business correspondence between the parties.

The Personal Data Protection Board said in a decision dated Sept. 16 that its detailed examination of the incident was continuing.

Canva users directed to official support channels

The official notification also mentioned communication channels for people seeking further information the breach.

Individuals who want to find out whether they were affected or obtain additional details can Canva through the platform's official help center.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Tools (1)