Communauto, the Montreal‑based car‑sharing company, announced on September 15, 2026 that it had identified a potential data breach involving an employee who attempted to view customers' personal information. The company said the unauthorized access attempt was detected through internal monitoring systems, prompting an immediate investigation and the decision to inform the public.

According to the statement released by Communauto, the employee in question sought to retrieve data that includes personal details of the service’s users. The firm emphasized that the access attempt was not part of any authorized activity and that it was halted as soon as the irregular behavior was flagged. No further specifics about the scope of the data or the number of affected customers were provided in the announcement.

Communauto indicated that it has taken steps to secure its systems and prevent similar incidents in the future. The company said it is reviewing its internal controls and access protocols to reinforce safeguards around sensitive customer information. It also noted that the employee involved has been identified, though it did not disclose any disciplinary actions or legal proceedings that may follow.

The breach discovery came after routine internal checks flagged the unusual request. Communauto’s response included notifying relevant privacy authorities in Quebec, as required by provincial regulations governing personal data protection. The firm reassured users that it remains committed to protecting their privacy and that it will continue to monitor its networks for any further irregularities.

While the incident highlights the challenges organizations face in managing internal data access, Communauto has not indicated whether any external parties were involved or whether the attempted access resulted in any data being copied or transferred. The company urged customers to remain vigilant and to report any suspicious activity related to their accounts.

Communauto’s announcement marks the latest example of a Canadian firm confronting internal data security concerns, underscoring the importance of robust oversight mechanisms within technology‑driven services.