2026 OnTrac — network intrusion Mar 20–22; customer notices (Jul)
Data compromised
Per sample notice summarized by BleepingComputer: customer names in combination with other data elements that OnTrac redacted in the public AG sample. Nationwide count not published. Company states it is unaware of fraud or publication of stolen information.
Technical writeup
Verified company notice — incident March 20–22, 2026; detected March 23; customer notifications dated around July 22, 2026 (BleepingComputer July 24). OnTrac (last-mile parcel carrier; OnTrac/LaserShip) said an unauthorized party accessed certain files on a limited portion of its network. The public sample notice lists names plus redacted additional elements. OnTrac engaged third-party specialists, says it re-secured the data and is unaware of fraud or publication, and offered 12 months of CyberScout credit monitoring (90-day enrollment). BreachHistory retains recordsAffected 0 pending an attested headcount. California AG listing (sb24-626905) and July multi-state notice summaries reaffirm March 20–22 access window, March 23 discovery, and CyberScout monitoring offers; nationwide headcount still not published in sources reviewed.
Root cause
Potentially suspicious activity on a limited portion of OnTrac’s network discovered March 23, 2026; unauthorized party accessed certain files March 20–22 (company notice)
References
- https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/
- http://www.documentcloud.org/documents/28513559-lasership-ontrac-breachnote/
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626905
- https://www.claimdepot.com/data-breach/ontrac-final-mile-2026