
OnTrac Data Breach Exposes Customer Information After Network Intrusion
Parcel delivery firm OnTrac alerts customers that hackers accessed personal data during a three-day network breach, prompting free credit monitoring services.
OnTrac, a major parcel-delivery company specializing in last-mile e-commerce deliveries, has begun notifying customers of a data breach after attackers infiltrated its corporate network. The company detected the unauthorized access on March 23, 2026, and an internal investigation revealed that between March 20 and 22, the intruder accessed certain files containing customer information.
The exact scope of exposed data remains unclear because OnTrac redacted the specific data elements in its notification template submitted to regulators. However, the company confirmed that names were among the compromised details. The breach impacts an undisclosed number of individuals across the 35 states where OnTrac operates, covering roughly 70% of the U.S. population through its network of over 7,000 independent delivery contractors.
In response, OnTrac engaged a third-party cybersecurity specialist to investigate the incident and “ensure the data described above was re-secured and not distributed.” This phrasing strongly implies that the company may have reached a settlement with the attackers, typical of a ransomware or extortion payment, to prevent the release of stolen information. OnTrac stated that it has no evidence of fraud or public exposure of the stolen data, but it is offering affected customers 12 months of complimentary credit monitoring and identity protection services through CyberScout.
This incident underscores the persistent threat of network intrusions to businesses of all sizes. Even organizations without customer-facing websites can fall victim, but for website owners and hosting providers, the stakes are equally high: a single breach can compromise customer trust and expose sensitive data. For businesses seeking to strengthen their defences, proactive measures such as those offered by AEU-I—providing security-first IT, infrastructure and consulting—can help organizations identify vulnerabilities, implement robust security controls, and establish effective incident response plans before attackers strike.