OnTrac Suffers Data Breach After Network Hack, Customer Data Potentially Exposed
Parcel delivery company OnTrac has disclosed a data breach resulting from a network hack, with threat actors gaining access to its corporate network and potentially exposing personal customer information.

OnTrac, a prominent parcel delivery company, has alerted its customers to a data breach that occurred after threat actors successfully infiltrated its corporate network. The incident, detected on March 23, allowed unauthorized access to certain files between March 20 and March 22, potentially exposing sensitive personal details of its customer base.
While the company has confirmed that names may have been accessed, the full scope of the compromised data remains unclear. OnTrac has redacted specific data elements in the notification samples shared with authorities, leaving the exact nature of the exposed information under investigation. This lack of clarity raises concerns for customers regarding the potential impact on their personal and financial security.
OnTrac, which specializes in last-mile e-commerce deliveries and operates across 35 states, has engaged a third-party cybersecurity specialist to thoroughly investigate the incident. The company stated it has taken steps to re-secure the affected data and prevent its distribution, hinting at a possible negotiation or ransom payment to the attackers to ensure the data is not leaked publicly.
Despite these measures, OnTrac has stated that it is not aware of any fraudulent activity or publication of the stolen information resulting from the breach. The company also expressed no reason to believe that such misuse of data will occur. However, this assurance does little to alleviate the inherent risks associated with a confirmed network intrusion and data exfiltration.
To assist affected customers in mitigating potential risks, OnTrac is offering a complimentary 12-month subscription to a credit monitoring and identity protection service through CyberScout. Customers are urged to enroll within 90 days of receiving the notification. Additionally, OnTrac recommends that customers review their credit reports and account statements regularly and consider placing fraud alerts or credit freezes if they deem the risk significant.
As of the publication time, no ransomware or data extortion groups have publicly claimed responsibility for the attack on OnTrac. The investigation is ongoing, and further details regarding the attackers' methods, the full extent of the data compromised, and whether a ransom was paid are still pending. The incident underscores the persistent threat landscape faced by logistics and delivery companies, which often handle vast amounts of personal customer data.
This breach highlights the critical need for robust cybersecurity measures in the logistics sector. Companies like OnTrac are prime targets due to the valuable personal information they store, making them attractive to cybercriminals seeking to exploit data for financial gain or other malicious purposes. The ongoing investigation will be crucial in understanding the full impact and preventing future incidents.