A data breach involving Canva has affected 424 organizations and institutions operating in Türkiye, exposing personal information and corporate documents, according to the country's Personal Data Protection Authority, known by its Turkish abbreviation KVKK.
Canva Pty Ltd, the company acting as the data controller, notified the authority after unauthorized access took place through a third-party system used by the platform. According to the initial assessment, threat actors exploited a connection involving a data processor and managed to take data out of the system.
While 424 organizations and institutions in Türkiye were directly affected, the total number of individuals whose personal information was exposed has not yet been determined.
The compromised information included names, business email addresses, workplace locations and corporate telephone numbers belonging to employees of companies using Canva.
The breach also extended to business documents that companies had shared with Canva, where applicable. These included customer order forms, data protection agreements, master service agreements, invoices and other routine business correspondence between the parties.
The Personal Data Protection Board said in a decision dated Sept. 16 that its detailed examination of the incident was continuing.
The official notification also mentioned communication channels for people seeking further information about the breach.
Individuals who want to find out whether they were affected or obtain additional details can contact Canva through the platform's official help center.