OnTrac notifies customers of data breach after network hack

OnTrac Parcel Delivery Company Hit with Network Hack, Customer Data Potentially Exposed

OnTrac, a private American parcel delivery company, has informed its customers that hackers breached its corporate network and may have accessed personal details belonging to its clients. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.

The exact nature of the data exposed is unclear, as OnTrac redacted the specific information in a notification sample shared with authorities. However, it’s likely that sensitive customer data such as names, addresses, and contact details may have been compromised. The breach affects customers who have used OnTrac’s services between March 20 and 22, which includes around 70% of the US population across 35 states.

OnTrac operates with over 7,000 independent delivery contractors and has a network of 102 locations throughout the country. In response to the security incident, the company contracted a third-party specialist to help determine the scope of the breach and took steps to re-secure affected data. It’s worth noting that OnTrac’s statement suggests a possible agreement between the firm and the attackers, which could imply a ransom payment was made to prevent customer information from being leaked.

While OnTrac assures customers that there is no evidence of any misuse or publication of stolen information resulting from this incident, exposed individuals are still at risk. To mitigate these risks, OnTrac is offering free access to a 12-month credit monitoring and identity protection service via CyberScout, with a 90-day enrollment deadline. Customers are advised to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if necessary.

The incident highlights the importance of robust security measures in protecting sensitive customer data. With no ransomware or data extortion threat groups taking responsibility for the attack at this time, it’s unclear whether OnTrac made any ransom payments to the attackers. The lack of transparency surrounding the incident raises questions about the company’s security posture and its ability to respond to cyber threats.

For individuals affected by the breach, it’s essential to take proactive steps to protect their sensitive information. By taking advantage of free credit monitoring services and closely reviewing account statements, customers can minimize potential risks associated with data exposure. As cybersecurity threats continue to evolve, staying vigilant and informed about potential incidents is crucial for maintaining online security and preventing identity theft.


Source: Bleeping Computer — 2026-07-24