Canva Enterprise Customers Exposed in Third-Party Security Breach
Canva has been caught up in a security breach at third-party software provider Canny. The incident allowed an unauthorized party to access information belonging to some of Canva's enterprise customers.
Canny, a customer-feedback platform used by Canva, informed the company on August 29 that it was investigating unauthorized access to its systems.
The unapproved access occurred through Canny's connection to Canva's Salesforce account. This gave the unauthorized party access to information related primarily to larger enterprise customers handled by Canva's sales team.
According to Canva, the accessed information included business contact details and contract information for affected customers.
Canva stated that it immediately removed Canny's access and notified affected customers. The company emphasized that its core product and databases were not compromised, and customer accounts, passwords, designs, and content remained secure.