OnTrac has begun notifying customers that an unauthorized party accessed files within its corporate network, bringing another data security incident into the increasingly connected logistics sector. The company detected the intrusion on March 23, 2026, and its investigation determined that the attacker had access to certain files between March 20 and March 22.
Names were among the compromised data, but the public notification reportedly redacted the other affected information categories. OnTrac has also not disclosed how many people received breach notices. That lack of detail makes it difficult for customers and business partners to assess the actual risk associated with the incident.
Why delivery data is valuable
Last-mile delivery companies process more than shipping labels. Their systems can contain names, home addresses, telephone numbers, email addresses, delivery instructions and records that reveal purchasing patterns. Even when payment details are not involved, this information can support convincing phishing messages, package delivery scams and attempts to impersonate retailers or couriers.
OnTrac operates across a large portion of the United States and works with thousands of independent delivery contractors. This creates a broad operational environment in which corporate systems, customer portals, mobile devices and third-party access must be secured consistently.
Customer and business response
The company says it brought in an external specialist, secured the affected information and has not identified fraud or public distribution of the stolen data. It is offering affected individuals 12 months of credit monitoring and identity protection.
Customers receiving a notice should consider several precautions:
- Verify unexpected delivery messages through the retailer or courier's official application.
- Avoid opening links in unsolicited texts claiming that a delivery fee or address confirmation is required.
- Review financial accounts and credit reports for unfamiliar activity.
- Consider a credit freeze if sensitive identity information was exposed.
- Use unique passwords for retailer and delivery service accounts.
A transparency problem
In my view, the central issue is not simply that a breach occurred. It is that customers cannot make informed security decisions without knowing which data fields were accessed. A name alone carries limited risk, while a name combined with an address, birth date or government identifier creates a significantly different threat.
OnTrac should publish clearer information as its investigation progresses, including the number of affected people, the categories of compromised data and the initial access method. Logistics providers should also review contractor access, segment customer information from operational systems and shorten the time between detecting an intrusion and notifying those potentially affected.
