U.S. last-mile carrier OnTrac (the OnTrac/LaserShip combine) is mailing customers after a March intrusion into part of its corporate network.
BleepingComputer reported July 24 that OnTrac detected suspicious activity on March 23 and found an unauthorized party accessed certain files between March 20 and 22, 2026.
What was exposed
The public AG sample notice confirms names were in the files, with other data elements redacted in the published copy. OnTrac has not published a nationwide victim total.
What OnTrac says
The company hired outside specialists, says it re-secured the data, is unaware of fraud or publication of stolen information, and is offering 12 months of CyberScout monitoring with a 90-day enrollment window.
Action items
- If you received an OnTrac/LaserShip letter, enroll in the monitoring using only the code in that letter.
- Treat unexpected “failed delivery / customs fee” texts as phishing.
- Monitor cards and credit for identity misuse even if full card numbers were not listed in your notice.
Canonical record
OnTrac March 2026 network breach. Sources: BleepingComputer, sample notice.