Canva data breach (2019)
The serial hacker GnosticPlayers breached Australian design platform Canva in May 2019, stealing data on roughly 137 million users including emails, names, locations and bcrypt-hashed passwords.
- Victim
- Canva
- records
- 137.3M
- users
- 137.3M
On 24 May 2019, the Australian online design platform Canva suffered a data breach affecting roughly 137 million users, carried out by the prolific serial attacker known as GnosticPlayers.
What happened
The breach was disclosed in an unusual way: the attacker, operating under the alias GnosticPlayers, contacted ZDNet directly on the morning of 24 May 2019 to boast about having breached Canva and exfiltrated user data β initially claiming around 139 million accounts. Canva detected the intrusion the same day and cut off the attacker's access while the exfiltration was still in progress.
GnosticPlayers was already infamous. Since early 2019 the actor had listed data from more than 30 companies β over 900 million stolen records in total β on dark-web marketplaces, including Dubsmash, 500px and Zynga. Canva was among the largest single hauls in that spree.
What was exposed
Have I Been Pwned catalogued 137,272,116 accounts. The exposed records included email addresses, usernames, real names, and cities of residence. For users who did not sign in via Google or Facebook social login, passwords stored as bcrypt hashes were also taken.
Crucially, payment card and financial data were not affected β Canva does not store full card numbers β and bcrypt's deliberate slowness meant the passwords were not trivially recoverable in bulk. Even so, in January 2020, a subset of about 4 million accounts with successfully cracked passwords was dumped online for free.
Impact
- Roughly 137 million users had personal data exposed, making it one of the largest breaches of 2019.
- Canva reset passwords, notified affected users, encouraged enabling two-factor authentication, and invalidated credentials when the 4-million-account dump appeared.
- The company's transparent, same-day response and use of bcrypt limited the practical damage and was generally well-received by the security community.
Why it matters
Canva is a study in breach handling done relatively well under pressure: rapid detection, prompt public disclosure, and password storage (bcrypt) that blunted the impact even when the database leaked. It also illustrates the era of industrial-scale credential brokers like GnosticPlayers, who aggregated breaches across dozens of consumer platforms to feed credential-stuffing and resale markets β reinforcing why unique passwords and MFA matter even when a provider hashes correctly.
Timeline
A hacker using the alias GnosticPlayers contacts ZDNet, claiming to have breached Canva that morning and exfiltrated data on roughly 139 million users.
Canva detects the attack and shuts it down, then begins notifying users and prompts password changes.
Canva publicly confirms the breach, stating passwords were stored as bcrypt hashes and that payment card data was not affected.
About 4 million Canva account records with passwords cracked from the breach are released for free online; Canva invalidates affected passwords.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Canva
- zdnet.comhttps://www.zdnet.com/article/canva-security-breach-affects-139-million-users/
- theregister.comhttps://www.theregister.com/2019/05/24/canva_data_breach/
- en.wikipedia.orghttps://en.wikipedia.org/wiki/GnosticPlayers
- canva.comhttps://www.canva.com/security/