Montreal-based carsharing company Communauto warned customers about a potential security breach that occurred involving users’ personal information in an email Monday. According to the email, the company detected unusual activity on its network associated with an internal user account during the night of Sept. 3 to 4. “Our investigation determined that an automated script had been deployed without authorization by an employee in an attempt to access and download customer records. As soon as this activity was detected, we blocked the affected access and secured our systems,” the email reads. Information that may have been compromised includes customers’ names, dates of birth, addresses, phone numbers, driver’s licenses, and the contact information of the person listed as users’ emergency contact. The company also said images or PDFs of users’ driver’s licenses, other supporting documents submitted as part of registration, or photos for identity verification purposes could also have been accessed. In an email statement to CTV News, Communauto said approximately “a few thousand” of its users may have been affected; only those members were emailed. Communauto said law enforcement has been notified about the breach and the investigation is ongoing, adding that “a search warrant was executed the following day to seize all computer equipment located at the residence of the individual suspected of being responsible for the incident.” The investigation has currently found no indication that the information involved has been disclosed or misused. As a precaution, Communauto is asking users to remain vigilant for unsolicited emails, phone calls, and text messages, particularly those requesting personal information, payment, urgent action, or encouraging users to click on a link or open an attachment. The company said that while this incident did not compromise users’ Communauto passwords, affected email addresses could potentially be used in phishing attempts or other schemes designed to obtain additional information. Users are asked to ensure Communauto passwords are strong, unique, and not reused across other websites or services. It also advises users to use multi-factor authentication on Communauto platforms to add an extra layer of protection. As an additional precaution, the company has also deployed independent cybersecurity experts to monitor publicly accessible internet sources and the dark web for any activity that may be linked to this incident. The company will contact users with any relevant additional information if the results of the investigation change its understanding of the incident or the measures it recommends they take. “We have also initiated a review of our security measures and are implementing the necessary actions to reduce the risk of a similar incident occurring in the future.”