Back Teiss Communauto data breach traced to employee's unauthorized script, company says
Montreal-based car-sharing company Communauto said an employee deployed an unauthorized automated script that attempted to access and download customer records, resulting in a data breach that affected roughly 2 percent of its members across Canada.
In an email sent to affected customers Monday evening, Communauto said its investigation determined the incident occurred during the night of Sept. 3 to 4. The company said an employee deployed the script without authorization in an attempt to access and download customer records. Montreal police executed a warrant the following day at the employee’s residence and seized computer equipment.
Communauto said account passwords and payment information were not affected, but that personal information, including customers’ names, addresses and driver’s license numbers, was. The company said photographs of customers or of their licenses attached to their files were also downloaded where they existed.
Marco Viviani, Communauto’s vice-president of strategic development, told CBC the breach affected 2 percent of the company’s users, characterizing the number as "some thousand members" nationwide. He said the company hired a specialized consulting firm to monitor the web and dark web for signs that the data had been exposed.
"At this stage, we hope that no data was disclosed externally," Viviani said. "Based on the information available to us, we did not believe it was necessary for anyone to be taken into custody, but we have not received any additional details since law enforcement became involved."
Communauto said it has retained independent cybersecurity experts to validate its findings, determine the scope of the incident and continuously monitor publicly accessible internet sources and the dark web for related activity, adding that its investigation and analysis remain ongoing. The company said members who did not receive an emailed breach notification were not among those whose information was potentially compromised.
Communauto advised affected members to remain cautious of unsolicited emails, phone calls and text messages, particularly those requesting personal information or payment, demanding urgent action, or encouraging them to click a link or open an attachment. The company recommended customers set up multi-factor authentication and ensure their account passwords are strong and unique. Members with questions the incident can the company at [email protected] .
Please take 30 seconds to register
Already have an account? Sign in
"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico
#teissLondon2018: On the internet, nobody knows you are a fridge
1 in 6 gamers disable all AV in the pursuit of the highest possible speeds
10 malicious Python Libraries discovered on PyPI Repository
126,000 affected by cyberattack on New Zealand patient portal Manage My Health
"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico
#teissLondon2018: On the internet, nobody knows you are a fridge
1 in 6 gamers disable all AV in the pursuit of the highest possible speeds
10 malicious Python Libraries discovered on PyPI Repository
126,000 affected by cyberattack on New Zealand patient portal Manage My Health
19-year-old claims he hacked into over 25 Tesla cars in 13 countries
2020 cybersecurity trends and resolutions
2025 in review: why cyber-security became a boardroom crisis
Closing the exposure window — unifying continuous threat exposure management
Closing the AI control gap - architecting security across users, applications, and agents
Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
