Back to Blog
high severity May 24, 2019 · 2 min read

Canva — 137 Million Accounts, and Why "Passwords Exposed" Overstates It (2019)

If you have an account with Canva, here’s what’s now in circulation.

Canva hashed with bcrypt, and many users had no password at all because they signed in with Google or Facebook. This is the breach our own test suite cites as the example of a page that wrongly said "plaintext password leaked".

A bcrypt hash beside a social-login token

What happened

In May 2019 the graphic design platform Canva was breached, affecting 137,272,116 subscribers. The exposed data comprised email addresses, usernames, names, cities of residence and — for users not signing in through a social login — passwords stored as bcrypt hashes. The seller GnosticPlayers claimed responsibility and listed the data among the 2019 Dream Market batches.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The label that was wrong, and why we know

The HIBP catalogue records a data class called Passwords for this breach. That class means a password field was present in the dump. It says nothing about how the password was stored.

GalaxyWarden got this wrong once, publicly. Our own regression suite (tests/test_breach_record_count_is_derived.py) records the defect: a page rendered "Plaintext password leaked · Canva" from that data class. Canva's passwords were bcrypt. The label was false, and it was false in the direction that causes real harm — it tells a reader their password is public when it is not, which pushes them toward panic and away from the actions that would actually help.

There is a second layer here that automated pages routinely miss: a large share of Canva users had no password in the dataset at all, because they authenticated through Google or Facebook. For those accounts there was never a Canva password to leak, and "change your Canva password" is advice about something that does not exist.

What was actually at risk

Strip out the password panic and a real exposure remains: name, username, email address and city of residence, for 137 million people, many of them running small businesses, freelance design practices or social-media presences under a brand name.

City-level location paired with a real name and a working email address is a solid foundation for targeted fraud — particularly invoice and client-impersonation scams aimed at freelancers, who expect unsolicited mail from strangers and are professionally obliged to open it.

The identity-chain implication

Design-tool accounts sit at an awkward junction: registered under a real name for billing, used to produce work published under a brand or handle. The Canva dataset therefore links a legal name and a home city to a creative identity that may be deliberately separate from it.

For a creator whose brand is public but whose location is not, that is the entire distinction collapsing in one row — and no password change repairs it, because no password was involved.

What to do now

What You Should Do

  1. Check whether you used a social login — if so there was no Canva password, and the reused-password question does not apply to you
  2. If you did set a password, change it only where reused; bcrypt makes bulk recovery impractical
  3. Freelancers and small businesses: treat unexpected client or invoice mail as suspect, since name plus city plus email is exactly the fraud pretext this data supports
  4. Check the same address against Dubsmash, MyFitnessPal and MyHeritage from the same 2019 listings
  5. Review whether your billing name is linked to a brand identity you intended to keep separate

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Canva customer?
Canva is one breach. Your email is probably in others.
137.3M subscribers accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed May 24, 2019
Last reviewed July 22, 2026
Affected 137.3M subscribers
Data exposed Email addressesUsernamesNamesGeographic locationsPasswords
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email