databreaches.net 23 Sept 2026, 20:59 UTC

Canva Data Exposed Through Canny Salesforce Breach, Hackers Claim

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
The Seven Deadly Sins

THREAT actors calling themselves “The Seven Deadly Sins” claim they accessed Canva data through Canny, a vendor connected to Canva’s Salesforce account. According to the group, it attacked Canny on 28 August 2026, while Canny notified Canva on 29 August that it was investigating unauthorised access. Canva told Capital Brief that the incident exposed “limited enterprise customer information”, including business contact details and contract information, through the Salesforce connection.

The group claims it had administrator access to Canny’s Salesforce instance and spent more than 72 hours inside Canva’s systems, exporting data between 26 and 28 August. Its leak-site listing alleges that the material includes Canva’s entire Salesforce organisation, more than 2 million CRM records, a 200-million-row platform and product data warehouse export, enterprise licence and contract information, user-seat allocations, customer accounts, billing attachments and order PDFs.

Canva has not confirmed these detailed claims, and the group’s account has not been independently verified. The attackers say they demanded payment and listed Canva after receiving no response; at publication, fewer than 10 hours remained on a 60-hour countdown. Canny reportedly attempted negotiations but then stopped responding. The group also claims access to other organisations’ systems, but those allegations remain unconfirmed.

View full article

Article by CyberSIXT