A car-sharing operator in Montreal has told its members that someone inside the company spent an evening copying customer records.
Viviani, a vice-president at the company, confirmed that police searched an employee’s home the day after the discovery. According to the service, its own monitoring systems raised the first alarm over member records on the night of September 3 to 4.
Local coverage of the case describes that employee as a suspect in the theft of personal information belonging to several customers. Payment details and passwords were not compromised, the company said, and outside specialists are now watching public sources and dark web marketplaces for signs that the records have surfaced for sale.
For a service built on trust, the timing is awkward. Car sharing asks members to hand over a driving licence, a home address, a payment method and a history of where they drove. That combination is worth more to a fraudster than a card number, because it survives cancellation and answers knowledge-based verification questions at banks and insurers.
Communauto has not said how many members were affected or what fields were taken. It has also not explained how one employee could pull records in bulk without an alert firing until hours later.
The breach lands in a crowded month for vehicle data. Quebec’s privacy regulator concluded in August that consent in connected cars is fundamentally broken, and California lawmakers have already killed a bill that would have forced automakers to limit what they collect.
The lesson is familiar. Access controls inside a mobility operator matter as much as the locks on its cars, and the person with legitimate credentials remains the hardest threat to spot.