Canva hacked via vendor's Salesforce instance; Other customers affected as well (1) - DataBreaches.Net
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva 2026-10-2 19:39:38 Author: databreaches.net(查看原文) 阅读量:7 收藏

A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group.

Attack on Canva

A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked Canny, a vendor used by Canva. On August 29, Canny notified Canva that it was investigating unauthorized access. In a statement to Capital Brief, a Canva spokesperson stated, “The unauthorised access to Canny allowed access to limited enterprise customer information through its connection to our Salesforce account, including business contact details and contract information.”

According to TSDS’s spokesperson, after gaining access, “We spent 2 weeks inside Canny’s system exporting from people’s jira’s, salesforces, okta, hubspot, and over 72 hours inside Canva alone.” They reportedly obtained full admin access to the Salesforce instance and “exported everything.”

TSDS exported Canva data from August 26-28 and then emailed them that day.

“Canva or someone else had to have noticed before Canny sent out notices,” they added, because “Canny only sent out notices after we sent out ransoms. The only reason they even knew they had a data breach was due to the fact that we emailed them,” the spokesperson told DataBreaches.

But after emailing them, they heard nothing from Canva, which led them to list them on their new leak site.

“They know we have the data, and they know we had a demand, they just don’t care,” the spokesperson added.

DataBreaches asked whether Canny had tried to negotiate, and was told they had attempted to negotiate with TSDS but then ghosted them. The company is “poor and over-stretched” according to TSDS’s spokesperson.

“We still hold access to over 300 Jira instances, 30 of them being Fortune 500 companies. We still have access to over 50+ salesforce, jira, hubspot, zendesk instances of multi billion dollar companies. We’re about to do some crazy things soon,” they added, noting that they are sitting on 3.8 TB of data. “It also doesn’t help [them] that Canny stored the entire email client list of companies like Mercury[.]com and Proxyscrape[.]io, which we obviously exported too and have sold.”

According to the listing on their DLS, the Canva part of the data they acquired allegedly includes:

– Entire Salesforce org — 2M+ CRM records
– Platform / product data warehouse — 200M+ rows total export
– Enterprise license orders · ACV contracts · user seat allocations
– Customer accounts · billing attachments · order PDFs

Canva has not confirmed the detailed claims made by TSDS.

About TSDS

TSDS is a new group, but according to the spokesperson, “we’ve all been around for a long time, and we’re deeply capable.” They do not deploy ransomware in their attacks, telling DataBreaches:

We are NOT interested in ransomware, disrupting a company from functioning is not our goal.

We see what we do as bug bounty’s with higher stakes and bigger payouts.

The spokesperson claims they’ve been paid low-8-figure ransoms in the past month, and since opening their DLS, completed three transactions today.

In terms of time frames, their general procedure is to notify the target by email, then give them one week to respond and open negotiations. If there is no response, they add the target to the leak site and give them a specified amount of time to respond.  Canva, which was originally posted on the leak site with a 48-hour deadline was changed to a 60-hour countdown clock. There are less than 10 hours remaining as of this publication.

This wasn’t Canva’s first incident.

Those who have been following data breaches for years may recall that Canva disclosed a hacking incident in 2019 that affected 139 million people. No group ever publicly claimed responsibility for that attack, and there was never any mention of a ransom demand. Canva’s incident response updates are still publicly available on its website.

As far as DataBreaches knows, no potential class-action lawsuit was ever filed in federal court as a result of that incident.

Perhaps they hope their incident response this time will help them avoid litigation again.

DataBreaches emailed Canva to ask about their incident response. They did not reply.


Update: I have received several questions about this alleged incident.  I have obtained copies of Canny’s notifications to its clients on August 29 and August 30, and a screenshot showing when TSDS contacted entities about the attack. TSDS has also provided me with 3 GB of data from Canva that I can attempt to validate, if there are continued questions.


文章来源: https://databreaches.net/2026/09/23/canva-hacked-via-vendors-salesforce-instance-other-customers-affected-as-well/
如有侵权请联系:admin#unsafe.sh