Skip to content
Data breachResolved

Canva data breach (2019)

The serial hacker GnosticPlayers breached Australian design platform Canva in May 2019, stealing data on roughly 137 million users including emails, names, locations and bcrypt-hashed passwords.

Victim
Canva
records
137.3M
users
137.3M

On 24 May 2019, the Australian online design platform Canva suffered a data breach affecting roughly 137 million users, carried out by the prolific serial attacker known as GnosticPlayers.

What happened

The breach was disclosed in an unusual way: the attacker, operating under the alias GnosticPlayers, contacted ZDNet directly on the morning of 24 May 2019 to boast about having breached Canva and exfiltrated user data β€” initially claiming around 139 million accounts. Canva detected the intrusion the same day and cut off the attacker's access while the exfiltration was still in progress.

GnosticPlayers was already infamous. Since early 2019 the actor had listed data from more than 30 companies β€” over 900 million stolen records in total β€” on dark-web marketplaces, including Dubsmash, 500px and Zynga. Canva was among the largest single hauls in that spree.

What was exposed

Have I Been Pwned catalogued 137,272,116 accounts. The exposed records included email addresses, usernames, real names, and cities of residence. For users who did not sign in via Google or Facebook social login, passwords stored as bcrypt hashes were also taken.

Crucially, payment card and financial data were not affected β€” Canva does not store full card numbers β€” and bcrypt's deliberate slowness meant the passwords were not trivially recoverable in bulk. Even so, in January 2020, a subset of about 4 million accounts with successfully cracked passwords was dumped online for free.

Impact

  • Roughly 137 million users had personal data exposed, making it one of the largest breaches of 2019.
  • Canva reset passwords, notified affected users, encouraged enabling two-factor authentication, and invalidated credentials when the 4-million-account dump appeared.
  • The company's transparent, same-day response and use of bcrypt limited the practical damage and was generally well-received by the security community.

Why it matters

Canva is a study in breach handling done relatively well under pressure: rapid detection, prompt public disclosure, and password storage (bcrypt) that blunted the impact even when the database leaked. It also illustrates the era of industrial-scale credential brokers like GnosticPlayers, who aggregated breaches across dozens of consumer platforms to feed credential-stuffing and resale markets β€” reinforcing why unique passwords and MFA matter even when a provider hashes correctly.

Timeline

  1. A hacker using the alias GnosticPlayers contacts ZDNet, claiming to have breached Canva that morning and exfiltrated data on roughly 139 million users.

  2. Canva detects the attack and shuts it down, then begins notifying users and prompts password changes.

  3. Canva publicly confirms the breach, stating passwords were stored as bcrypt hashes and that payment card data was not affected.

  4. About 4 million Canva account records with passwords cracked from the breach are released for free online; Canva invalidates affected passwords.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Canva
  2. zdnet.comhttps://www.zdnet.com/article/canva-security-breach-affects-139-million-users/
  3. theregister.comhttps://www.theregister.com/2019/05/24/canva_data_breach/
  4. en.wikipedia.orghttps://en.wikipedia.org/wiki/GnosticPlayers
  5. canva.comhttps://www.canva.com/security/

Related incidents

Data breachResolved

BtoBet data breach (2019)

In December 2019, a large collection of data from Nigerian gambling company Surebet247 was sent to HIBP. Alongside the Surebet247, database backups from gambling sites BetAlfa, BetWay, BongoBongo and TopBet was also included.

Victim
BtoBet
Records
444.2K
Data breachResolved

GameSprite data breach (2019)

In December 2019, the now defunct gaming platform GameSprite suffered a data breach that exposed over 6M unique email addresses. The impacted data also included usernames, IP addresses and salted MD5 password hashes.

Victim
GameSprite
Records
6.2M