TechNewsReel
Live

Communauto Data Breach Linked to Unauthorized Employee Script

The Montreal-based car-sharing service reports that an insider accessed sensitive driver's license data for thousands of members.

TechNewsReel Newsroom · September 15, 2026

Montreal-based car-sharing service Communauto has confirmed a data breach involving the theft of sensitive customer information by one of its own employees. The incident underscores the persistent danger of insider threats in platforms managing government-issued identification.

Between September 3 and 4, 2026, an employee deployed an unauthorized automated script designed to access and download customer records. According to an email sent to customers, Communauto's internal investigation determined the script was used specifically to harvest member data. Law enforcement responded quickly, executing a search warrant at the employee's residence the following day to seize computer equipment.

The breach affected approximately 2% of the company's user base, which Communauto described as "some thousand members" across Canada. The compromised data is highly sensitive, including names, home addresses, driver's license numbers, and photos of the users or their licenses. However, the company confirmed that account passwords and payment information were not affected by the script.

The Scale of the Risk

Communauto is a dominant player in the Quebec market, serving approximately 50,000 customers in the province alone. The nature of the stolen data—specifically the combination of license numbers and photographs—creates a significant security vulnerability for the affected users. Unlike passwords, which can be reset, government ID numbers are static, leaving victims at a heightened risk of identity theft and sophisticated, targeted phishing attacks.

Industry Implications

This incident highlights a critical failure in internal access controls. When employees have the ability to deploy automated scripts against production databases without immediate detection or restriction, the risk of data exfiltration increases. For the car-sharing industry, which requires the collection of high-stakes verification documents to ensure safety and legality, this breach serves as a warning that the greatest threat often comes from within the perimeter rather than from external hackers.

Current Status and Monitoring

In response to the breach, Communauto has hired a specialized consulting firm to monitor the open web and the dark web for any evidence that the stolen records have been leaked or sold. While the company has taken steps to secure its systems, the full extent of the data's movement remains unknown. Marco Viviani, Vice-president of strategic development, stated, "At this stage, we hope that no data was disclosed externally."

Sources

Get a notification when a big story breaks. A few a day at most — no spam.