Canva breach affects data linked to 424 organizations in Türkiye
A Canva app is shown in the App Store, Raleigh, North Carolina, U.S., May 22, 2025. (Shutterstock Photo)


A recent data breach at Australian graphic design platform Canva has affected information linked to 424 organizations or institutions in Türkiye, according to the country's data protection authority.

According to Canva's notification, the breach occurred after unauthorized access to a third-party tool used by the company as a data controller.

The threat actor is believed to have extracted certain personal data through a connection with the data processor.

The number of individuals impacted by the breach in Türkiye has not yet been determined, the private broadcaster CNBC-e said, citing a notice from the Personal Data Protection Authority (KVKK).

The affected data included various details belonging to employees of Canva's customers.

According to the KVKK notice, the exposed information included first and last names, work email addresses, workplace locations and business telephone numbers.

The breach was not limited to employees' contact information, the authority said.

Customer order forms, contracts, invoices, data protection agreements and master service agreements shared with Canva were also among the affected data, to the extent that they had been provided to the platform.

Other routine business correspondence conducted by companies through Canva may also have been affected, according to the notice.