OnTrac Confirms Network Breach, Notifies Customers
OnTrac confirmed hackers breached its corporate network and may have accessed customer PII. Watch for delivery-themed phishing built on your shipping data.
OnTrac, a regional parcel delivery company operating across the United States, is notifying customers that hackers accessed its corporate network and may have obtained customer personal information, per BleepingComputer.
The disclosure is in the “may have accessed” category: confirmed network intrusion, unconfirmed data exfiltration. That distinction matters legally, but it doesn’t change what customers should do. Network access is the precondition; whether data actually moved is a forensics question that can take weeks to resolve definitively.
What OnTrac holds on customers
Parcel carriers hold the data you hand over when you ship or receive packages: name, delivery address, phone number, email, and package tracking history. None of those fields are financial credentials on their own, but all of them are useful for social engineering. A convincing phishing message doesn’t require your credit card number — it needs your name, recent delivery details, and a plausible hook. That’s exactly what a delivery company breach provides.
What to do
- Review your OnTrac account for any unexpected activity or address changes.
- Do not follow links in delivery-themed emails or text messages, even those referencing accurate package details. Navigate directly to ontrac.com to check on any shipment.
- If you reused your OnTrac login password at other services, rotate those other passwords now. The exposure risk propagates through reuse.
- Be alert to phishing attempts over the coming weeks that use shipping details as authenticity scaffolding — messages become more convincing when the sender already has your name and recent order context.
As of publication, OnTrac has not disclosed how the network was accessed, how many customers are affected, or which specific data fields are in scope. Those details will emerge through the formal state notification process.
For similar context on how attackers use breached logistics and loyalty data as phishing pretext, see Chick-fil-A’s June credential stuffing incident and Origin Energy’s recent PII breach.
Found this useful? Share it.


