[ THREAT ARCHIVE :: 2019 ]
EXPOSURE SCALE: 137,000,000 RECORDS
Canva 2019 Security Incident — What Was Leaked & How to Check If You're In It
In May 2019, threat actor Gnosticplayers breached graphic design platform Canva, downloading database tables containing 137 million customer records.
INCIDENT YEAR: 2019
ATTACK VECTOR: OAuth API Infrastructure Intrusion
SEVERITY RATING: HIGH
> COMPROMISED DATA ATTRIBUTES IN THIS BREACH:
[✓] Usernames
[✓] Real Names
[✓] Email Addresses
[✓] Bcrypt Hashes
[✓] City & Country Data
> TECHNICAL POST-MORTEM & VECTOR ANALYSIS
- The attacker gained unauthorized administrative access to Canva’s AWS production cluster.
- Passswords were protected with bcrypt (cost factor 10), which prevented immediate mass cracking for strong passwords.
> VERIFY IF YOUR CREDENTIALS APPEARED IN THIS DUMP
Query the DARKLEDGER multi-source engine to check if your email, username, or phone number was indexed in the Canva 2019 Security Incident dataset.
> STEP-BY-STEP REMEDIATION PLAYBOOK
- Check if your designer or marketing email was registered on Canva in 2019.
- Verify if your bcrypt hash has been cracked in rainbow table lists.
> FREQUENTLY ASKED QUESTIONS ABOUT THIS BREACH
Q: Was payment data leaked in the Canva breach?
Canva stated that no credit card or financial transaction records were exfiltrated during the incident.