Canva hacked via vendor’s Salesforce instance; Other customers affected as well
Executive Summary
Canva was breached through a compromised Salesforce instance belonging to a vendor. The attacker group, The Seven Deadly Sins, targeted the platform on Aug 28, demanding payment. The breach exposed customer data and impacted other clients of the vendor’s Salesforce environment. DataBreaches.net reported the incident and identified the group’s new leak site.
Intelligence Metadata - Source Publisher: DataBreaches.net - Published Date: 2026-09-23T20:59:47+00:00 - Category: data-breaches
Original Description: A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked... Source
"A man is not where he lives but where he loves."
— Unknown