Canva Enterprise Data Exposed in Canny Security Breach
A third-party software provider exposed Canva business contact information following a system breach.
Updated on Sept. 20, 2026 in Cybersecurity

Live Poll
Do you trust that your company's sensitive data remains secure when shared with third-party software vendors?
On 29 August 2026, Canva confirmed that unauthorized parties accessed enterprise customer information through a connection maintained by third-party provider Canny. The breach involved data stored within Canva's Salesforce account, though the company reported that its core design platform and user content databases remained secure.
Why it matters
This incident highlights the security risks inherent in enterprise software integrations where third-party access to internal systems like Salesforce can bypass direct security perimeters. Companies are increasingly forced to balance functional interoperability with the potential for external service providers to serve as vectors for data exfiltration.
The unauthorized party accessed enterprise information via a compromised connection between Canny and Canva's Salesforce account. While contract data and business contact details were exposed, Canva confirmed that its primary product databases and user passwords were not part of the breach.
The players
Canva
A visual communication and design software company that provides a cloud-based platform for graphic design and team collaboration.
Canny
A third-party software provider that offers feedback management tools for product teams and integrates with enterprise CRM systems.
The details
The breach occurred through an integration link that permitted Canny to interface with Salesforce, a cloud-based customer relationship management (CRM) platform used for managing business contracts and contact details. Attackers leveraged this third-party bridge to pull sensitive data without ever infiltrating Canva's internal production architecture. Upon notification, Canva terminated all system access previously granted to Canny to prevent further data exposure.
Timeline
29 August 2026: Canny informed Canva that unauthorized parties had gained access to its systems.
The Tech Race
This event reflects the broader industry trend of supply chain compromises becoming a critical vulnerability vector for global enterprise software platforms. It highlights the competitive pressure to integrate third-party tools against the rising necessity of securing increasingly complex API-linked ecosystems.
Canva enterprise users whose business contact or contract details were exposed may see an increase in targeted phishing attempts or unsolicited business correspondence. Administrators should review their current third-party permissions and API configurations within their CRM environments to minimize unnecessary data access.
The takeaway
Enterprise security relies heavily on the strength of external integration points, making third-party auditing a non-negotiable component of cloud infrastructure defense. Security teams should monitor internal incident logs for any unusual activity originating from auxiliary software connectors to identify similar unauthorized access patterns early.
Further reading
For more context on how organizations manage third-party risk, visit Cybersecurity.
Live Poll
Do you trust that your company's sensitive data remains secure when shared with third-party software vendors?





