Cyber Incident Victim: Communauto
Date:
Jan 2021
Location:
Canada
Summary
A Montreal-based car-sharing service experienced a cyberattack resulting in unauthorized access to servers and encryption of data. While customer passwords and credit card information remained secure, the attackers successfully exfiltrated names, physical addresses, and email addresses from compromised systems. The incident disrupted operations during a peak seasonal period but did not compromise financial data or authentication credentials.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Communauto, a Montreal-based car-sharing service established in 1994, experienced a cyberattack during the 2020-2021 holiday season, with public disclosure occurring on January 9, 2021. Attackers compromised multiple company servers, locking access to systems and encrypting data through unauthorized means. The intrusion resulted in partial data exfiltration, though critical financial information remained secure. Specifically, the attackers failed to access user passwords or credit card numbers stored by Communauto. However, they successfully extracted personally identifiable information including customer names, physical street addresses, and email addresses. The breach timeline suggests sustained attacker activity during a period of reduced organizational staffing typical of holiday operations.

The incident represented a significant operational security failure for Communauto, though the full technical scope of compromised infrastructure remained unspecified in initial disclosures. Company representatives confirmed the attackers employed encryption-based attacks that disrupted server functionality, indicating potential ransomware involvement despite no explicit ransom demand being mentioned. While payment systems and core authentication credentials remained uncompromised, the theft of contact information and residential addresses exposed users to heightened phishing and physical security risks. Communauto provided no detailed public timeline for system restoration or specific containment measures beyond acknowledging the breach's occurrence and limited data impact. No customer-facing service interruptions were explicitly documented in the immediate aftermath reporting.
