TechNewsReel
Live

Communauto Data Breach: Employee Used Unauthorized Script to Steal Driver's Licenses

The Montreal-based car-sharing service reports that an insider exfiltrated sensitive data for thousands of members across Canada.

TechNewsReel Newsroom · September 15, 2026

Montreal-based car-sharing company Communauto has revealed a data breach caused by an internal employee who used an automated script to steal customer records. The incident, which occurred between September 3 and 4, 2026, underscores the persistent danger of insider threats within service-based platforms.

According to an email sent to customers, Communauto's investigation determined that an employee deployed an unauthorized automated script to access and download member data. The breach affected approximately 2% of the company's user base, described as "some thousand members" across Canada. In response to the discovery, law enforcement executed a search warrant at the suspect's residence the following day to seize computer equipment.

Compromised Data

The stolen information includes highly sensitive personally identifiable information (PII), specifically names, addresses, and driver's license numbers. The company noted that the breach potentially included photos of users or their licenses. However, Communauto confirmed that account passwords and payment information were not affected by the incident.

Operational Context

Communauto operates as a major car-sharing provider, maintaining a significant footprint with approximately 50,000 customers in Quebec alone. To mitigate the fallout, the company has hired a specialized consulting firm tasked with monitoring the open web and the dark web for any signs that the stolen records have been exposed or sold.

The Insider Threat Risk

This breach highlights a critical security vulnerability: the insider threat. While many companies focus on hardening external perimeters against hackers, this incident demonstrates how employees with legitimate system access can bypass those defenses. By using automated tools to exfiltrate government-issued IDs and personal details, a single trusted actor can compromise thousands of records in a matter of hours.

Next Steps

As the investigation continues, the primary concern remains whether the exfiltrated data has been shared externally. While law enforcement has seized the suspect's hardware, the company continues to monitor for data leaks. Users affected by the breach are advised to remain vigilant for identity theft attempts involving their driver's license information.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.