Montreal’s Communauto is warning customers of a potential personal data breach that took place in early September, the car-sharing company announced Monday.
Communauto says an employee allegedly deployed, without authorization, a script to view and download subscriber files during the night of September 3-4, 2026. Customers who did not receive a message from Communauto have not been identified as having been affected by the incident.
“We commend the immediate response of our teams,” said Marco Viviani, Vice President, Strategic Development at Communauto. “We also sincerely thank the police services for their rapid intervention and collaboration. We are continuing our analyses and have chosen to inform the affected members in the interest of transparency.”
The information gathered includes customers’ names, dates of birth, addresses, phone numbers, driver’s licence information, and the contact information of the person listed as their emergency contact. Communauto also reported that images or PDFs of users’ driver’s licences, other supporting documents submitted as part of the registration process, and photos used for identity verification purposes may have been accessed.
About 2 per cent of users were affected by the potential breach, according to Communauto.
Communauto says it blocked the employee’s access after detecting the activity, notified police and secured its systems.
An investigation was carried out the following day involving the suspected employee and all of their computer equipment.
Communauto reassures users that payment information and account passwords were not affected by the incident, as the person involved did not have access to that information.
The company advises users to remain vigilant against phishing attempts and other schemes aimed at obtaining additional personal information.
The investigation is ongoing.




