OnTrac reports customer data exposure following corporate network intrusion
Parcel carrier OnTrac is notifying customers that an unauthorized party accessed its corporate network and may have viewed files containing personal information.The company said it detected the incide...
Parcel carrier OnTrac is notifying customers that an unauthorized party accessed its corporate network and may have viewed files containing personal information.
The company said it detected the incident on March 23, 2026. Its investigation found that the intruder accessed certain files between March 20 and March 22. OnTrac’s public notification identifies customer names as exposed data, but other potentially affected information was redacted from the sample filing provided to authorities. The company has not disclosed how many people were impacted.
OnTrac said it hired an outside cybersecurity specialist to investigate the incident and determine its scope. The carrier also stated that it took measures to secure the affected information and prevent it from being distributed. That wording does not establish whether the company negotiated with or paid the attackers, and OnTrac has not publicly confirmed that a ransom was involved.
In its notification, the company said it has found no evidence of fraud or public disclosure connected to the incident. It also said it currently has no reason to believe the information has been misused.
Support for affected individuals
OnTrac is offering recipients of the notification 12 months of complimentary credit monitoring and identity-protection services through CyberScout. Eligible individuals must enroll within 90 days of the notice.
The company is also advising affected customers to review credit reports and financial-account statements for suspicious activity. Depending on their circumstances, recipients may consider placing a fraud alert or security freeze with the major credit-reporting agencies.
OnTrac, established in 2021 through the combination of OnTrac Logistics and LaserShip, provides last-mile delivery services across the United States. The privately held company says it operates 102 locations in 35 states, reaches approximately 70% of the U.S. population, and works with more than 7,000 independent delivery contractors.
No ransomware or extortion group had publicly claimed responsibility for the intrusion at the time of reporting. OnTrac had not provided additional details about the attack method, the number of affected customers, or whether any data was ultimately published.
