OnTrac parcel delivery company has disclosed a significant security incident, revealing that hackers breached its corporate network and potentially accessed sensitive information belonging to its customers. The intrusion was detected on March 23, with an internal investigation showing that attackers accessed certain files between March 20 and 22.
The affected company, OnTrac, specializes in “last-mile” e-commerce deliveries, operating at over 100 locations across 35 states, covering approximately 70% of the U.S. population. The firm has around 7,000 independent delivery contractors on its books. Despite the severity of the breach, there is currently no evidence to suggest that customer information has been misused or leaked.
According to OnTrac’s statement, hackers likely accessed a range of personal details, although the company has redacted specific data elements in notification samples shared with authorities. The incident has prompted an investigation, with OnTrac working closely with external specialists to assess the scope of the breach and re-secure affected systems. This suggests that the company may have negotiated with attackers – typically involving a ransom payment – to prevent further information from being leaked.
OnTrac is offering customers a 12-month credit monitoring and identity protection service, provided by CyberScout, in response to the incident. This service includes free access to enhanced credit reporting and identity theft alerts for affected individuals. The company recommends that recipients of the notification review their credit reports and account statements carefully, considering placing a free fraud alert or credit freeze if they deem it necessary.
While OnTrac’s efforts are aimed at minimizing potential harm, the incident highlights the ongoing threat posed by network breaches. Companies must continually monitor their systems for vulnerabilities and work with external specialists to identify areas of weakness. By doing so, organizations can reduce the likelihood of such incidents occurring in the future.
The incident serves as a reminder that security is an ongoing process – not just a one-time task. It’s crucial that companies prioritize regular security audits and penetration testing to ensure their systems are secure. For individuals affected by this breach, it’s essential to remain vigilant and take proactive steps to protect themselves from potential identity theft or financial loss.
Source: Bleeping Computer — 2026-07-24