Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

OnTrac Breach Puts Last-Mile Delivery Data Under Scrutiny

OnTrac Breach Puts Last-Mile Delivery Data Under Scrutiny
Photo by Pixabay on Pexels

Parcel delivery company OnTrac is notifying customers after an attacker accessed files within its corporate network during a March intrusion. The company has not publicly disclosed the full range of exposed information or the number of affected people, leaving customers to manage uncertainty around identity theft and targeted fraud.

OnTrac has begun notifying customers that an unauthorized party accessed files within its corporate network, bringing another data security incident into the increasingly connected logistics sector. The company detected the intrusion on March 23, 2026, and its investigation determined that the attacker had access to certain files between March 20 and March 22.

Names were among the compromised data, but the public notification reportedly redacted the other affected information categories. OnTrac has also not disclosed how many people received breach notices. That lack of detail makes it difficult for customers and business partners to assess the actual risk associated with the incident.

Why delivery data is valuable

Last-mile delivery companies process more than shipping labels. Their systems can contain names, home addresses, telephone numbers, email addresses, delivery instructions and records that reveal purchasing patterns. Even when payment details are not involved, this information can support convincing phishing messages, package delivery scams and attempts to impersonate retailers or couriers.

OnTrac operates across a large portion of the United States and works with thousands of independent delivery contractors. This creates a broad operational environment in which corporate systems, customer portals, mobile devices and third-party access must be secured consistently.

Customer and business response

The company says it brought in an external specialist, secured the affected information and has not identified fraud or public distribution of the stolen data. It is offering affected individuals 12 months of credit monitoring and identity protection.

Customers receiving a notice should consider several precautions:

  • Verify unexpected delivery messages through the retailer or courier's official application.
  • Avoid opening links in unsolicited texts claiming that a delivery fee or address confirmation is required.
  • Review financial accounts and credit reports for unfamiliar activity.
  • Consider a credit freeze if sensitive identity information was exposed.
  • Use unique passwords for retailer and delivery service accounts.

A transparency problem

In my view, the central issue is not simply that a breach occurred. It is that customers cannot make informed security decisions without knowing which data fields were accessed. A name alone carries limited risk, while a name combined with an address, birth date or government identifier creates a significantly different threat.

OnTrac should publish clearer information as its investigation progresses, including the number of affected people, the categories of compromised data and the initial access method. Logistics providers should also review contractor access, segment customer information from operational systems and shorten the time between detecting an intrusion and notifying those potentially affected.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path