OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea

A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division naming state-backed hackers. Stories that almost slipped past.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A modern office building with a digital padlock symbol overlayed, representing cybersecurity
Share

Key points

  • OnTrac, a parcel delivery company serving the western United States, confirmed it was hacked in a breach that may affect customers expecting deliveries.
  • The UK Department for Education exposed records belonging to roughly 607,000 people, most of them children, in a data loss incident.
  • Amazon Web Services (AWS) publicly linked a series of infrastructure attacks to hackers working on behalf of North Korea.
  • Adobe released security patches closing flaws that could let criminals take full control of a victim's computer.

What happened to OnTrac customers?

OnTrac, which delivers parcels for retailers across California and the broader western US, confirmed criminals broke into its systems. We first reported on 24 July that hackers were inside OnTrac's network for three days in March, and no ransomware crew had yet claimed the hit. If you're waiting on a delivery handled by the company, your contact details or order information may have been caught up in the breach. Watch your inbox for phishing emails, fake messages designed to trick you into handing over passwords or payment details, that reference a missed delivery or a parcel problem. That's a classic follow-up move.

How did 607,000 records leave a UK government department?

The UK Department for Education lost data on approximately 607,000 people, most of them children. The department hasn't detailed how the loss occurred, but the failure mode is almost always identical: data shared too broadly, stored without proper controls, or handed to a third party without adequate checks. Parents of school-age children in the UK should watch for unusual contact that references their child's school or personal details.

Why is AWS naming North Korea?

AWS publicly attributed a wave of attacks on cloud infrastructure to hackers acting on behalf of the North Korean government. Major cloud providers rarely name nation states directly; when they do, it means the evidence is solid enough that they'll defend it in public. Our story from 30 July on how Amazon traced the September npm hijack of popular packages to North Korean hackers fits the same pattern: Pyongyang treats hacking as a revenue stream, and AWS has now decided it's worth saying so openly.

SecurityWeek flagged this attribution alongside separate research from a firm called Mythos focused on North Korean activity in the crypto sector, painting a consistent picture.

What did Adobe patch, and should you update now?

Update now. Adobe pushed fixes for security flaws in several of its products, some rated critical. A criminal could exploit them by getting a target to open a malicious file, no further interaction required. If you're running any Adobe software on Windows or Mac, open the app and check for updates today.

Story Who is affected Action needed
OnTrac breach Parcel recipients, western US Watch for phishing emails about deliveries
UK DfE data loss 607,000 people, mostly children Monitor for suspicious contact referencing school data
AWS / North Korea Cloud platform users, crypto firms Review cloud access logs, check IAM permissions
Adobe patches Anyone running Adobe software Update all Adobe products immediately

Operational takeaway: a breach disclosure with no detail about root cause isn't a disclosure, it's a holding statement.

© 2026 Threat Vectr