Communauto reveals employee-initiated data breach affecting thousands of members
Car-sharing firm Communauto disclosed that an employee used an unauthorized script to download personal data of roughly two percent of its users.
Communauto announced that an internal employee deployed an unauthorized automated script during the night of Sept. 3-4, pulling personal records of about two percent of its customers nationwide. The data included names, mailing addresses, driver’s licence numbers and any uploaded photographs. Law enforcement executed a search warrant at the employee’s residence the next day, confiscating the relevant computer hardware.
The company emphasized that account passwords and payment information remained secure. To detect any potential exposure, Communauto engaged a consulting firm to scan the open and dark web. Affected members were urged to stay alert for suspicious communications and to enable multi-factor authentication.
Why it matters
A breach of personal data by one outlet highlights security risks for users of shared-mobility services.
In this story
