Communauto, the Montreal‑based car‑sharing service, disclosed on Tuesday that a potential data breach originated from an internal employee who attempted to retrieve customers' personal information. The incident was identified early on September 15, 2026, prompting the company to alert authorities and begin an internal review.

According to the company's statement, the employee sought access to data that includes identifiers such as names, email addresses and phone numbers linked to user accounts. The unauthorized request triggered security alerts, leading to the immediate suspension of the employee's access rights and the activation of the firm’s incident‑response protocol.

Communauto confirmed that no evidence suggests the information was copied, transmitted or used beyond the initial access attempt. Nevertheless, the company is notifying affected members, offering guidance on protecting their accounts, and working with cybersecurity specialists to assess any residual risk. The firm also reiterated its commitment to the privacy safeguards outlined in its user agreement and to compliance with Quebec’s data‑protection regulations.

The breach underscores the challenges that shared‑mobility providers face in balancing employee privileges with data security. While the investigation remains ongoing, Communauto said it will review internal controls, reinforce training on data handling, and consider additional technical measures to prevent similar incidents. The company has not disclosed any further details pending the outcome of the inquiry.