avenvale.Breach library
Historical report · 2019English edition

Canva 2019 breach: what to do next

Start here

Check how you signed in

If you used a Canva password, replace it wherever it remains in use. If you used a social login, review that provider’s sign-in security and connected-app access without assuming its password was exposed here.

Read the action guide

What was reported

HIBP reports that the 2019 Canva breach included contact and profile data. Password hashes were included for users who did not rely on social sign-in.

Email addressesGeographic locationsNamesPasswordsUsernames

Selected reported fields. This is not confirmation that your information was involved.

What matters here

The sign-in method matters: the source distinguishes Canva passwords from social logins. That distinction does not mean a connected Google or Facebook account was breached by this event.

Understand the informationEmail or password exposed?

Related reports

Sources & context

Report metadata: Have I Been Pwned · CC BY 4.0. Avenvale provides the explanation and suggested response.

By Avenvale · Published · Updated

Public information, not a personal exposure check. A historical record does not establish current account access or a completed removal.