OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]
Source: BleepingComputer · July 24, 2026 at 10:59 PM · AI-assisted report

KUALA LUMPUR, 25 JULY 2026 —
Listen to this article
DomainFork Audio · read aloud
OnTrac, a US-based parcel delivery company, has notified its customers of a data breach after hackers gained access to its corporate network, potentially exposing personal details of its clients. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.
Market Impact
OnTrac has a history dating back to 2021, when it was formed from the merger of OnTrac Logistics and LaserShip. The company specializes in "last-mile" e-commerce deliveries and operates at 102 locations across 35 states, covering roughly 70% of the US population. It works with more than 7,000 independent delivery contractors, making it a significant player in the US parcel delivery market. The company's services are designed to provide fast and efficient delivery solutions to its customers, but the recent data breach has raised concerns about the security of its systems.
The data breach at OnTrac is believed to have occurred between March 20 and 22, with the attacker gaining access to certain files on the company's network. While the exact nature of the exposed data is unclear, OnTrac has stated that it may include personal details such as names. The company has contracted a third-party specialist to help determine the scope of the breach and has taken steps to "ensure the data described above was re-secured and not distributed." This statement suggests that OnTrac may have reached an agreement with the attackers, possibly involving a ransom payment, to prevent the leaked data from being distributed. OnTrac has stated that it is not aware of any fraud or publication of stolen information resulting from the incident.
The impact of the data breach on the Malaysian market is currently unclear, as OnTrac's operations are primarily focused on the US market. However, the incident serves as a reminder of the importance of cybersecurity in the logistics and delivery industry, which is increasingly relevant to Malaysia's growing e-commerce sector. Malaysian companies that work with international logistics providers like OnTrac may need to reassess their own cybersecurity measures to prevent similar breaches. Details not yet available on whether any Malaysian customers or businesses have been affected by the breach.
In response to the breach, OnTrac is offering free credit monitoring and identity protection services to affected customers for a period of 12 months. Customers are also advised to review their credit reports and account statements and consider placing a free fraud alert or credit freeze if necessary. The company's swift response to the breach is aimed at mitigating the risks associated with the exposed data. OnTrac's actions are in line with industry best practices for responding to data breaches, which emphasize the importance of transparency, customer notification, and support.
The outlook for OnTrac and its customers remains uncertain, as the company continues to investigate the breach and determine its full extent. The incident highlights the ongoing threat of cyberattacks to businesses and individuals alike, and the need for robust cybersecurity measures to prevent and respond to such incidents. As the investigation continues, OnTrac customers and stakeholders will be watching closely to see how the company responds to the breach and works to prevent similar incidents in the future. With the rise of e-commerce and online shopping, the importance of secure logistics and delivery systems cannot be overstated, and companies like OnTrac must prioritize cybersecurity to maintain customer trust and protect sensitive data.