Communauto Investigates Data Breach After Employee Misuses Automated Script
Montreal-based car-sharing company Communauto disclosed a potential data breach after an employee allegedly attempted to access and download customer records without authorization. The incident occurred between the night of September 3 and the early hours of September 4.
In an email to affected customers, Communauto confirmed that an unauthorized automated script was deployed by an employee, targeting personal information. While account passwords and payment details remained secure, exposed data included names, addresses, driver’s licence numbers, and if provided customer photographs and licence images.
The following day, police executed a search warrant at the employee’s residence, seizing computer equipment. Communauto’s vice-president of strategic development, Marco Viviani, stated that the breach impacted approximately 2% of users roughly "several thousand members" across Canada. At this stage, the company has found no evidence of external data disclosure but continues to monitor the web and dark web for potential leaks.
Law enforcement has not taken the employee into custody, and the investigation remains ongoing. Communauto has engaged a specialized consulting firm to track any signs of data exposure.
Source: https://www.cbc.ca/news/canada/montreal/communauto-data-breach-9.7344242
Communauto cybersecurity rating report: https://www.rankiteo.com/company/communauto
"id": "COM1789483063",
"linkid": "communauto",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Several thousand members '
'(approximately 2% of users)',
'industry': 'Car-sharing',
'location': 'Montreal, Canada',
'name': 'Communauto',
'type': 'Company'}],
'attack_vector': 'Insider Threat',
'customer_advisories': 'Email notification to affected customers',
'data_breach': {'data_exfiltration': 'No evidence of external disclosure '
'(ongoing investigation)',
'number_of_records_exposed': 'Several thousand',
'personally_identifiable_information': 'Names, addresses, '
'driver’s licence '
'numbers, photographs, '
'licence images',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal Information'},
'date_detected': '2023-09-04',
'date_publicly_disclosed': '2023-09-04',
'description': 'Montreal-based car-sharing company Communauto disclosed a '
'potential data breach after an employee allegedly attempted '
'to access and download customer records without authorization '
'using an automated script.',
'impact': {'data_compromised': 'Names, addresses, driver’s licence numbers, '
'customer photographs, licence images',
'identity_theft_risk': 'High',
'payment_information_risk': 'None'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'root_causes': 'Employee misuse of automated '
'script'},
'references': [{'date_accessed': '2023-09-04',
'source': 'Communauto Customer Advisory'}],
'response': {'communication_strategy': 'Email to affected customers',
'containment_measures': 'Search warrant executed at employee’s '
'residence, computer equipment seized',
'enhanced_monitoring': 'Monitoring web and dark web for '
'potential leaks',
'incident_response_plan_activated': 'Yes',
'law_enforcement_notified': 'Yes',
'third_party_assistance': 'Specialized consulting firm engaged '
'to track data exposure'},
'threat_actor': 'Employee',
'title': 'Communauto Data Breach Due to Employee Misuse of Automated Script',
'type': 'Data Breach',
'vulnerability_exploited': 'Unauthorized access via automated script'}