Breach directory
Canva Data Breach (2019)
Canva was breached on a Friday in May 2019 and said so the same day, one of the fastest disclosures in this directory. Its 137 million accounts came with bcrypt password hashes, the good kind.
- Accounts exposed
- 137,272,116
- When it happened
- May 2019
- Added to Have I Been Pwned
- Aug 2019
- Data exposed
- Email addresses, names, usernames, geographic locations (city and country), passwords
- Passwords stored as
- bcrypt, individually salted, on 61 million accounts per ZDNet
- Disclosed
- Same day, by Canva, in a statement to ZDNet
Breach data from Have I Been Pwned by Troy Hunt, licensed under CC BY 4.0.
Was your email address in the Canva breach?
Type the address on your Canva account. If it was in the Canva breach the result says so, alongside every other breach holding the same address.
What happened
ZDNet broke the story on 24 May 2019, hours after the attack. Its source was the intruder, who claimed data on 139 million Canva users and said Canva had noticed the intrusion and shut its database server while the download was still running. ZDNet obtained a sample of some eighteen thousand accounts, Canva staff among them, and confirmed it with users named in it before contacting the company.
Canva’s statement to ZDNet, sent the same day, confirmed access to usernames and email addresses, said passwords were individually salted and hashed with bcrypt, and asked everyone to change theirs as a precaution. Most companies in this directory learned of their breach from a reporter, years later.
ZDNet had tracked the same seller since February 2019 across 44 companies, and Canva was the forty-fifth. Have I Been Pwned added 137,272,116 unique email addresses in August 2019.
In May 2019, the graphic design tool website Canva suffered a data breach that impacted 137 million subscribers. The exposed data included email addresses, usernames, names, cities of residence and passwords stored as bcrypt hashes […]
What was exposed
Five fields in the Canva data breach: email address, username, real name, geographic location (the city and country Canva had on file) and, for the 61 million accounts that had set one, a bcrypt password hash, per ZDNet. Accounts opened through Google sign-in carried a Google token in place of a hash.
Together those fields matter more than any one of them. A real name, a city and an email address are exactly what a convincing “someone shared a design with you” message needs, and Canva sends millions of those legitimately, so the fake ones blend in. Reused handles turn the username into a thread to your other accounts.
How the passwords were stored
Canva hashed passwords with bcrypt, each with its own salt, which is the storage this directory would wish on every breach in it. bcrypt is deliberately slow: where SHA-1 lets a graphics card test billions of guesses a second, bcrypt allows thousands, and the per-password salt means each account has to be attacked on its own.
That protects strong passwords well. It does not protect “canva2019” or a pet’s name, because an attacker only needs the common guesses against each hash, and a few thousand guesses per account is affordable across 61 million of them. So the honest reading of the Canva breach: a long, unique password very likely never came out of its hash; a short or reused one should be assumed known, which is why Canva asked everyone to change theirs on the day.
Timeline
May 2019
Attack, dated 24 May 2019 by ZDNet's same-day report. Canva sees the download in progress and shuts the database server.
May 2019
Canva's statement to ZDNet the same day: usernames and email addresses accessed, passwords salted and hashed with bcrypt, change them anyway.
Aug 2019
Have I Been Pwned adds 137,272,116 unique email addresses from the Canva breach.
Disclosure lag
Hours. Canva users heard from the press and from the company on the day of the attack, which almost never happens.
What to do now
If the Canva password was reused anywhere, change it there; on Canva itself the company forced the point in 2019. Then read any Canva-branded email with suspicion. The record hands a sender your real name, your city and your address, and BleepingComputer has documented Canva share notifications used as phishing bait. Do not follow the link in such an email; open canva.com yourself.
Your username was public on Canva anyway, so the new exposure is that it now sits next to your email address in a searchable file. Finally, run the free LeakNix check on the address: it shows every breach holding it, not only Canva, and which of them exposed a password.
Questions about the Canva breach
Was the Canva breach in May 2019?
- Yes. ZDNet reported it on 24 May 2019, the day it happened, and Canva confirmed it the same day. Have I Been Pwned added the 137,272,116 affected addresses in August 2019.
Were passwords exposed in the Canva data breach?
- For about 61 million accounts, yes, as bcrypt hashes with individual salts, which are slow to crack. Google sign-in accounts had no password in the data. A strong, unique password was probably never recovered; a weak or reused one should be treated as known.
What should I do if my email was in the Canva breach?
- Change the password anywhere you reused it, be wary of emails that look like Canva share notifications, and check the address against other breaches, since an address in the Canva breach is usually in several.
Related breaches
The Canva data breach record here (137,272,116 accounts, May 2019) is from Have I Been Pwned under CC BY 4.0, with no endorsement of LeakNix implied.
LeakNix