Skip to main content
Breach Signal

Breach report

Consumer Tech

Canva

Australian tech unicorn Canva suffers security breach

A hacker known as GnosticPlayers breached Australian design platform Canva in May 2019, stealing data on roughly 139 million users, including names, email addresses, locations and bcrypt-hashed passwords.

Reported by ZDNet

Records exposed

139M

About 139 million users

Scale vs. largest on file

When
2019
How they got in
Database intrusion by hacker GnosticPlayers
Sector
Consumer Tech

On May 24, 2019, the online graphic design service Canva confirmed it was investigating a security incident after a hacker using the name GnosticPlayers contacted the technology site ZDNet claiming to have stolen records on about 139 million users. The Sydney-based company, then valued at more than $2 billion and one of Australia's best-known startups, said it had detected the attack while it was in progress and shut it down.

According to the hacker and data samples reviewed by reporters, the stolen information included usernames, real names, email addresses, and the city and country users had listed. Around 61 million of the records contained password hashes. Canva said those passwords had been salted and hashed with bcrypt, an algorithm designed to make cracking slow and expensive. Users who signed in with Google accounts did not have Canva passwords stored in the database. Canva said payment card details were not accessed.

GnosticPlayers was already notorious. Earlier in 2019 the same actor had offered hundreds of millions of accounts stolen from dozens of other websites for sale on a dark web marketplace, and later that year claimed responsibility for the breach of Zynga's Words With Friends. The hacker told reporters that Canva had noticed the intrusion and closed off access before the full data dump could be completed.

Canva emailed users, encouraged them to change their passwords as a precaution, and said it had notified authorities. The company faced scrutiny under Australia's Notifiable Data Breaches scheme, which had taken effect the previous year, but no major penalty was announced. Because the passwords were protected with bcrypt, security experts viewed the immediate risk of account takeover as lower than in many comparable leaks, although email addresses and names remained valuable for phishing.

The Canva incident was one of the largest breaches of 2019 and one of the biggest ever involving an Australian company. It illustrated two lessons at once: that strong password hashing substantially limits the damage when a database is stolen, and that fast-growing consumer platforms with enormous user bases are prime targets for serial hackers who monetize data in bulk. For users, it reinforced the practice of using unique passwords so that even a cracked credential cannot unlock other accounts.

More from the wire

More in Consumer Tech.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.