● Data Breaches

OnTrac Parcel Delivery Service Discloses Customer Data Breach Following Network Intrusion

July 24, 2026 · snewle
OnTrac Parcel Delivery Service Discloses Customer Data Breach Following Network Intrusion

OnTrac, a major American parcel delivery company, has informed customers that hackers infiltrated its corporate network and potentially accessed personal information. The OnTrac data breach was discovered on March 23, 2026, with subsequent investigation revealing that unauthorized parties had accessed certain files between March 20 and March 22.

The company, which specializes in last-mile e-commerce deliveries, operates across 102 locations in 35 states and serves approximately 70 percent of the U.S. population through more than 7,000 independent delivery contractors. OnTrac was formed in 2021 following the merger of OnTrac Logistics and LaserShip.

What Information Was Compromised in the Attack?

While OnTrac confirmed that customer names were exposed during the breach, the full extent of compromised data remains unclear. The company redacted specific data elements from the notification sample submitted to authorities, making it difficult to determine exactly what types of personal information may have been accessed by the attackers.

How Did OnTrac Respond to the Security Incident?

Following the discovery of the intrusion, OnTrac engaged a third-party cybersecurity specialist to assist in determining the scope of the breach. The company also implemented measures to ensure the accessed data was re-secured and prevent its distribution. The wording of OnTrac’s statement suggests a possible arrangement with the attackers, potentially involving a ransom payment, to prevent the stolen customer information from being leaked publicly.

OnTrac stated in its notification that it remains unaware of any fraud or publication of stolen information resulting from the incident, and the company has no reason to believe such misuse will occur.

What Protection Is Being Offered to Affected Customers?

To help mitigate potential risks for exposed customers, OnTrac is providing complimentary access to a 12-month credit monitoring and identity protection service through CyberScout. Affected individuals have a 90-day window to enroll in this protection service.

The company has also recommended that notification recipients review their credit reports and account statements regularly. For those who determine the risk to be significant, OnTrac suggests considering the placement of a free fraud alert or credit freeze on their credit files.

Has Any Group Claimed Responsibility?

As of the disclosure, no ransomware or data extortion threat groups have publicly claimed responsibility for the attack on OnTrac’s network. The number of impacted customers and whether the company paid a ransom remain undisclosed, as OnTrac has not responded to requests for additional information.

Source: BleepingComputer