OnTrac customer data breach exposes personal info
Parcel delivery company OnTrac says attackers broke into its corporate network and accessed customer files. The company has not said exactly what data was taken but believes customer names may be included.
- Report priority
- Medium
- Involves
- OnTrac
What is known
OnTrac found unauthorized access to certain files after attackers got into its corporate network between March 20 and 22, and it brought in an outside cybersecurity firm to investigate the intrusion.
What to do
OnTrac has not published a public list of exact data types exposed, so customers should watch for a direct notification letter from the company rather than checking a version number or file.
OnTrac is offering 12 months of free credit monitoring and identity protection to affected customers, who should enroll through the notice they receive, review their credit reports, and consider placing a fraud alert.
Reported details
OnTrac detected the breach on March 23, 2026, and its investigation traced unauthorized file access back to March 20 through 22. The company has not disclosed the specific data elements involved, describing them only in redacted form in its notification letters, and says it has re-secured the affected systems. No threat group has publicly claimed the attack, and OnTrac has not said whether a ransom was demanded or paid.