
Due to the third-party data leak in Canva, invoices, contracts and employee information of 424 institutions in Türkiye were seized.
AI-generated summary
It was announced by KVKK that unauthorized access was provided to the Canva platform through a third-party tool. The incident directly affected 424 institutions in Türkiye.
The data leak in the online design platform Canva affected 424 institutions in Türkiye; company invoices and contracts leaked out.
Canva is facing a serious data security crisis that directly impacts enterprise users. According to the official statement published by the Personal Data Protection Authority (KVKK), unauthorized access was achieved to a third-party tool used on the platform. Critical documents and employee data of 424 institutions and organizations operating in Turkey were affected by the leak.
According to the official information provided to KVKK by Canva Pty Ltd, the attack occurred not directly from the company's main servers, but through an integrated third-party service. It was determined that a threat actor gained unauthorized access through the connection established with the data processor and exported sensitive information in the system.
Although the exact number of real people affected by the breach has not yet been determined, it has been confirmed that the data of 424 different organizations based in Türkiye was leaked. Security experts emphasize that it once again reveals the great risk that such third-party supply chain attacks pose to corporate data.
The data captured by cyber attackers is not limited to basic contact information; It also includes critical documents concerning companies' trade secrets and operational processes:
Employee Information: Name, surname, work e-mail address, workplace location and work phone numbers of employees of corporate customers.
Business Documents: Customer order forms, invoices, and contracts shared with Canva.
Legal and Administrative Documents: Data protection agreements (DPA), master service agreements and routine business correspondence between institutions.
KVKK states that individuals and organizations who want to learn details about the violation can contact Canva directly. Companies are taking steps to check whether the sensitive documents they upload to the platform are within the scope of leakage.

The Ministry of Family and Social Services, KADEM and Turkcell signed a training protocol aimed at empowering women in artificial intelligence and digital security. The program, which will be implemented in 81 provinces, aims for women to take an active role in digital transformation.

After Meta introduced a daily usage limit for young users, Snap CEO Evan Spiegel announced that they could support similar regulations. Anti-addiction measures are being discussed throughout the industry.

OpenAI launched ad displays in Türkiye for users using ChatGPT's free and Go packages. While ads based on chat context do not affect paid subscriptions, a minimum budget requirement of $25 per day has been introduced for advertisers.

Apple announced the official repair fees for the iPhone 18 Pro and Pro Max models, which will be available in Türkiye on September 18. While screen replacement costs start from 18 thousand TL, prices go up to 97 thousand TL in other damage categories.

iPhone 18 Pro switched to under-screen Face ID technology. However, tests reveal that matte and frosted screen protectors block infrared sensors, making the biometric unlocking process unsuccessful. It is recommended that users turn to transparent glass protectors.
In the US Senate, the bill requiring an emergency kill button for artificial intelligence models was blocked by Senator Rand Paul. Paul argued that hasty regulations could kill innovation.