OnTrac Notifies Customers of Data Breach Following Network Intrusion
Parcel delivery giant **OnTrac** has begun notifying customers about a data breach stemming from an unauthorized intrusion into its corporate network. The incident, detected in late March, may have exposed personal details, prompting the company to offer credit monitoring services.
The incident, which **OnTrac** detected on March 23, involved an attacker accessing certain files within their corporate network between March 20 and 22. While **OnTrac** has confirmed that customer names were potentially exposed, the full scope of compromised data remains unclear, as specific data elements were redacted in the notification sample shared with authorities.
**OnTrac**, formed in 2021 from the merger of **OnTrac Logistics** and **LaserShip**, specializes in βlast-mileβ e-commerce deliveries. The company operates across 102 locations in 35 states, serving approximately 70% of the U.S. population and working with over 7,000 independent delivery contractors.
In response to the breach, **OnTrac** engaged a third-party cybersecurity specialist to assist with the investigation and implement measures to βensure the data described above was re-secured and not distributed.β This phrasing often suggests that a negotiation, potentially including a ransom payment, may have occurred to prevent the further dissemination of stolen customer information.
βWe are not aware of any fraud or publication of stolen information resulting from this incident, nor do we have any reason to believe any such misuse of information will occur,β **OnTrac** stated in its official notification.
To mitigate potential risks for affected individuals, **OnTrac** is providing complimentary access to 12 months of credit monitoring and identity protection services through **CyberScout**. Customers have a 90-day window to enroll in this service. Additionally, recipients of the breach notification are advised to regularly review their credit reports and account statements and consider implementing a fraud alert or credit freeze if they deem the risk significant.
As of the time of writing, no ransomware or data extortion groups have publicly claimed responsibility for the attack. **OnTrac** has not yet disclosed the total number of affected customers or confirmed whether a ransom was paid.