Data breach
Canva
- Records
- 137,485,336
- Breach date
- 24 May 2019Estimated
- Added
- 1 December 2024
What was exposed
5 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses1
- Names1
- Password hashes1
- Usernames1
- Websites1
- CountriesReported, not counted
- CitiesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The investigation team estimates that roughly 137.5 million user records tied to the online design platform Canva were exposed in a breach dating to May 24, 2019. Canva, which is based in Sydney, detected the attack while it was still underway and shut it down the same day. A hacker using the alias GnosticPlayers later told ZDNet that the stolen data covered about 139 million accounts. According to Canva's own incident notice, the attacker reached a profile database holding usernames, names, email addresses, country information, and optionally a city or homepage URL from public profiles.
The company says passwords stored for username-and-password logins were individually salted and hashed with bcrypt, a method designed to make the original passwords very hard to recover. For roughly four million accounts, that protection did not hold. In January 2020, Canva said it learned that a list containing about four million passwords stolen in the May 2019 breach had been decrypted and shared online.
Breach Timeline
May 24, 2019: Canva detects a malicious attack on its systems while it is in progress and stops it. The company says it reported the incident to authorities, including the FBI.
Late May 2019: GnosticPlayers contacts ZDNet about the breach. Canva notifies users and encourages password resets, and the company later resets OAuth tokens for people who signed in with Google.
January 11, 2020: Canva becomes aware that a list of roughly four million account passwords stolen in the May 2019 breach has been decrypted and shared online.
January 12, 2020: Canva resets the passwords of all users who had not changed their passwords since May 24, 2019, requiring them to set new ones at their next login.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames (nicknames), email addresses, names, encrypted passwords, and website URLs.
Canva's incident notice adds further detail. It says the profile database contained usernames, names, email addresses, country, and optionally user-supplied city and/or homepage URL data from public profiles. Passwords for username-and-password logins were stored individually salted and hashed with bcrypt. Canva also says the attacker accessed Google tokens used by people who signed up through Google rather than setting a password.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most direct risk comes from the decrypted passwords. Canva has said that around four million account passwords from this breach were cracked and circulated, so anyone whose password was in that list could face unauthorized access to their Canva account if they never changed it.
Even without a cracked password, the exposed names, email addresses, and location details are useful to scammers. They can be used to send convincing phishing emails that appear legitimate because they contain real personal details. If a person reused the same password on Canva and other sites, attackers who crack the bcrypt hashes could try those credentials elsewhere, a technique known as credential stuffing. The stolen Google tokens were a third concern, though Canva says it reset them after the breach.
What Is Canva Doing in Response?
Canva says it stopped the attack while it was happening, reported the incident to authorities including the FBI, and notified affected users. It encouraged users to change their passwords as a precaution and reset Google login tokens. When decrypted passwords surfaced in January 2020, the company invalidated unchanged passwords, forced resets for anyone who had not changed theirs since May 24, 2019, and notified affected users directly.
What Should You Do If You Were Affected?
Change your Canva password if you have not done so since May 2019. Canva says users who had not changed theirs were forced to reset in January 2020.
If you use the same password anywhere else, change those accounts too. Password reuse is what turns one breach into many.
Be cautious with emails referencing Canva or your account. Attackers can use real names and email addresses to craft believable messages, so avoid clicking unexpected links or entering credentials through emailed pages.
Watch for unusual activity on your Canva account and any account that shares its login details.
In the news
- Canva Security Incident – May 24 FAQscanva.com (opens in a new tab)
- Sophos News: Millions of Canva users' data stolen as GnosticPlayers strikes againnews.sophos.com (opens in a new tab)
- ZDNet: The scariest hacks and vulnerabilities of 2019zdnet.com (opens in a new tab)
- Mozilla Monitor: Canva Data Breachmonitor.mozilla.org (opens in a new tab)
