Communauto, the Montreal‑based car‑sharing service, announced on September 15 that a potential data breach occurred after one of its employees attempted to access customers’ personal information. The company said the employee’s request triggered an incident that could have exposed private data, prompting an immediate internal review and notification of authorities.
According to the statement, the employee made an unauthorized effort to retrieve customer records, which revealed a weakness in the firm’s data‑handling controls. While Communauto did not specify the exact type of information that may have been accessed, it emphasized that the breach stemmed from the internal request and did not involve external intrusion.
Communauto has informed affected customers of the possible exposure and advised them to remain vigilant for any unusual activity related to their accounts. The company also reported the matter to Quebec’s privacy regulator, complying with provincial requirements for data‑protection incidents.
In response, Communauto said it is strengthening access controls, reviewing employee training, and enhancing audit procedures to limit future unauthorized access. The firm reiterated its commitment to safeguarding personal data and indicated that further updates will be provided as the investigation proceeds.
The car‑sharing provider, which operates a fleet of vehicles across Montreal and other Canadian cities, has not disclosed whether any particular group of users was impacted. It stressed that the incident is being handled in accordance with legal obligations and that customer privacy remains a top priority.
Communauto said the investigation is ongoing and that it will cooperate fully with regulatory bodies to determine the scope of the breach and any remedial actions required.
