← Back to Blog

NovelCrafter Security Incident: What Actually Leaked

NovelCrafter Security Incident: What Actually Leaked

You opened the email expecting a changelog. Instead the subject line was about a security incident, and the first thing your eye did was skip every paragraph looking for one word: manuscript.

It isn't there. That's the good news, and it's real news, not a hedge. But the email is still worth reading twice, because what it actually describes is a thing most writers have never thought about: your novel doesn't live in one company's hands. It lives in the hands of every vendor that company has ever hired.

What happened, in one paragraph

On August 28, 2026, an unauthorized party accessed an internal system at Canny — the third-party platform NovelCrafter used to run its public feedback and feature-request boards. Canny began notifying its customers that same week. NovelCrafter then emailed anyone who used the service between August 2023 and August 28, 2026, telling them that the username, email address, and avatar they'd used to sign up may have been exposed. Passwords were never shared with the feedback platform. Stories, outlines, and Codex content were never shared with it either, so none of that was in the exposed set. NovelCrafter shut down the feedback boards the day it sent the email and pointed users to its Discord instead — and as of this writing, the board at novelcrafter.canny.io is closed to the public, which matches what the email said it would do.

This was not a breach of NovelCrafter's servers. That distinction matters, and I'd rather state it clearly than let it sit as an insinuation: nobody got into the place your chapters are stored.

What was actually exposed — and what wasn't

The exposed fields were identity-level, not content-level. VRChat, which was hit by the same Canny incident and published an unusually detailed public writeup, lists what was likely accessed for affected accounts: usernames, public account images, email addresses, account IDs, and account activity dates on the feedback site. That writeup also reports that Canny completed its investigation with an outside forensics firm, found no further unauthorized activity after August 28, and has no evidence that the information involved has been published or shared.

So the realistic damage is this: someone may now know that the email address you use is attached to a person who writes novels with AI assistance, along with whatever username you picked and whatever avatar you uploaded.

That sounds minor. It mostly is. It is also precisely the raw material for a convincing phishing email — one that knows your handle, knows which writing tool you use, and arrives in the same week you're expecting a message about a security incident. The dangerous part of an email-and-username leak is never the email and username. It's the second email, the one that looks like it came from the vendor.

Worth noting how differently the same incident landed for a different Canny customer. Canva, which also used Canny, had connected it to its Salesforce account — and so the same intruder reached business contact details and contract information for enterprise customers, per Capital Brief's reporting. Canva said it immediately removed Canny's access and that its own platform, accounts, passwords, designs, and content were not accessed. Same vendor, same week, same intruder; blast radius determined entirely by how much each company had wired into it.

Why a feedback tool had your email in the first place

Because that's how software is built now, and it isn't a scandal. A small team shipping a writing app doesn't build a feedback board, a help desk, an email sender, an analytics pipeline, a payment processor, and an error tracker. It rents six companies. Each one gets the slice of your account it needs to do its job, and each one is a separate set of servers with a separate security posture you will never see.

Which gives us the sentence I'd put on the wall: your manuscript's attack surface is every vendor your writing app has ever hired. You evaluated NovelCrafter. You did not evaluate Canny. You didn't know Canny existed until the email arrived.

This is not a niche risk anymore. Verizon's 2025 Data Breach Investigations Report, which analyzed over 22,000 security incidents including 12,195 confirmed breaches, found that third-party involvement in breaches doubled to 30%. Not 30% of attacks came through vendors in some theoretical model — 30% of confirmed breaches involved a third party, up from 15% the year before. The supply chain is now the front door.

And notice what you, the writer, can do about any of it: nothing. You can pick a careful vendor. You cannot audit your vendor's vendors, you won't be told which ones they use, and you'll learn the list one disclosure at a time.

The version of this that would actually hurt

Here's the scenario I keep thinking about, because it's the same incident with one component swapped.

Imagine Priya, fourteen months into a trilogy. Book one is done at 103,000 words. Book two sits at 61,000. Her Codex has 212 entries — every house, every salt-magic rule, the whole web of who knows that her protagonist's sister sold harbor manifests to the customs office. She pays a cloud suite somewhere in the $4–$20/month range, which is what NovelCrafter's tiers actually run, plus her own API spend on top.

In the real August incident, Priya's bad week costs her about two hours: she rotates the password she'd reused on two other sites, turns on 2FA, and starts treating any email about her writing tool as hostile until proven otherwise. Annoying. Survivable. Nothing of hers is on the open internet.

Now swap the compromised vendor. Not the feedback board — the storage layer, or the sync service, or the backup provider. Same attacker, same Friday, same forensics firm. This time what's sitting in the exposed bucket is 164,000 words of unpublished trilogy and a 212-entry bible that spoils every reveal in book three. There is no rotating that. You cannot change your manuscript the way you change a password. The entire value of an unpublished novel is that it's unpublished, and that's a property you only get to lose once.

Nothing about the August incident suggests that happened or was close to happening. The point is structural: the difference between the inconvenient version and the career-shaped version was which contractor got hit, and that was never up to Priya.

What to do this week

None of this requires new software. Four things, in order of how much they actually buy you:

  1. Rotate the password on the account named in the email, and anywhere you reused it. The email says passwords weren't shared with the feedback platform — believe it, and rotate anyway. Reuse is the mechanism that turns an email-only exposure into an account takeover somewhere else.
  2. Turn on 2FA on the email address itself. Your email is the recovery path for everything else, including every writing tool you've ever signed up for. If you harden one thing this week, harden that.
  3. Treat every message about this incident as a phish until you've verified it independently. Don't click links in security emails about security emails. Go to the vendor's site or Discord yourself. An attacker holding usernames and tool affiliation is holding the two details that make a fake notice convincing.
  4. Get a copy of your manuscript out, today. Export the full draft and the story bible to plain files on your own disk, and put a second copy somewhere that isn't the same cloud. Do this whether or not anything is wrong — it's the same drill that saved people's work when PlotDrive announced it was shutting down, and a vendor's bad month is as good a prompt as a wind-down notice. In NovelMage the step is already done, because the files were never anywhere but your drive to begin with.

That fourth one is the only one that changes your exposure rather than your cleanup time.

Where local-first changes the arithmetic

The honest version of the local-first argument isn't that desktop software is immune to attack. It's narrower and harder to argue with: the only data that can't leak is the data nobody kept. A vendor can't lose your manuscript to an intruder if the vendor never had a copy of it.

That's the shape of NovelMage. It's a desktop app for Windows, macOS, and Linux, and your manuscripts stay on your machine — there are no NovelMage servers holding chapter text, so there's no bucket of customer drafts for anyone to reach through a compromised contractor. You point it at a local model through Ollama or LM Studio and the whole loop runs with the network off: the prose never leaves the room. Prefer a frontier model? Bring your own Claude, GPT, or Gemini key, and only the specific prompt text goes to that provider — not your project, not your Codex, not fourteen months of archive. It's $99.99 once, usable on up to 3 devices, with a 7-day free trial that doesn't ask for a card.

If your current setup is working and your collaborators live in it, a vendor's feedback-board slip is not a reason to move 164,000 words this month — fix the password, keep writing.

But if the email made you notice that you'd never once asked where your draft physically sits, that instinct is worth following. The same reflex is worth having about everyone downstream of your manuscript, including the humans — it's the question behind whether your agent is running your pages through AI. You can download NovelMage and run a chapter through it offline before you decide anything, with your Wi-Fi switched off, which is its own kind of proof.

Frequently Asked Questions

Were NovelCrafter manuscripts or Codex content exposed in the Canny incident?

No. The compromised system belonged to Canny, the third-party feedback platform, and manuscripts, outlines, and Codex entries were never shared with it. NovelCrafter's notification email states that stories and content were not impacted and that passwords were not shared with the feedback platform. What may have been exposed was limited to the username, email address, and avatar used on the feedback boards.

Do I need to change my NovelCrafter password?

The email says passwords weren't involved, and there's no public evidence contradicting that. Change it anyway if you reused it anywhere else, since a known-good email address is the starting point for credential-stuffing attempts on other sites. Enabling 2FA on your email account does more for you than the password rotation itself.

Who else was affected by the Canny incident?

Canny serves many companies, and the exposure differed by how much each had connected. VRChat published a public writeup of its own affected accounts, and Canva disclosed that enterprise customer contact and contract information was reachable through Canny's connection to its Salesforce account. NovelCrafter users were affected only at the feedback-board identity level.

Does using a local AI model actually prevent this kind of exposure?

It prevents the manuscript-shaped version of it. With a local model through Ollama or LM Studio and a desktop app like NovelMage, your draft is never uploaded anywhere, so no vendor — first-party or third-party — holds a copy to lose. It does not protect your email address from a mailing-list provider or your card number from a payment processor; those still live with someone. The claim is about your pages, not your whole identity.

What should I ask a tool before trusting it with an unpublished novel?

Two questions, and neither is about features. First: where does the chapter text physically sit — my disk, or your servers? Second: when I run a generation, what exactly gets transmitted, and to whom? A tool that answers "on your machine" and "only the prompt, to the model provider you chose" has a structurally smaller failure mode than one that answers "our cloud" — regardless of how good either company's security team is.

Share this article

Loading comments...