Third-party data breach associated with Canva impacts 424 organizations in Turkey.

0
1
Third-party data breach associated with Canva impacts 424 organizations in Turkey.

A significant data breach involving Canva has reportedly compromised 424 organizations in Türkiye, raising concerns about the security of personal and corporate information. The Turkish Personal Data Protection Authority (KVKK) has confirmed that sensitive data has been exposed due to unauthorized access through a third-party system associated with the platform. While these organizations are directly affected, the scale of individual data exposure is still being assessed.

Details of the Breach

Canva Pty Ltd, which serves as the data controller, reported the security incident to the KVKK following discoveries of unauthorized access. According to preliminary investigations, cybercriminals exploited vulnerabilities in a third-party data system linked to Canva, enabling them to extract information from the platform. The precise number of individuals whose data has been exposed remains unspecified, although it affects a significant number of corporate entities.

The breach has led to the exposure of various types of information, including employee names, business email addresses, workplace locations, and corporate phone numbers. Additionally, sensitive business documents shared with Canva have also been compromised. These documents include customer orders, data protection agreements, master service agreements, invoices, and standard business communications.

Canva’s Official Response

In response to the breach, a spokesperson from Canva stated, “Canny, a third-party tool we use for product feedback, recently notified us about unauthorized access to its systems. It is important to note that Canva’s platform and its user accounts remain secure. The compromised access to Canny may have allowed unauthorized access to limited routine business information, but we acted promptly to revoke this access.”

This statement emphasizes that while data was exposed via a third-party connection, the core Canva systems themselves were not compromised. Canva has taken immediate steps to notify affected clients and regulatory bodies to ensure compliance and transparency.

Steps and Precautions for Users

The Personal Data Protection Board is conducting an in-depth examination of the breach, and updates are expected as the investigation continues. For individuals and companies concerned about their data security, Canva has set up official support channels to help users ascertain their exposure and seek additional information regarding the breach. Users are encouraged to visit Canva’s help center for detailed guidance and answers to queries related to the incident.

As the cybersecurity landscape continues to evolve, this incident serves as a pertinent reminder for organizations to continuously assess their third-party data risks and invest in robust cybersecurity measures.რმ

LEAVE A REPLY

Please enter your comment!
Please enter your name here