OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea

A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division calling out state-backed hackers. A busy week of stories that almost slipped past.

ThreatVectr Newsdesk· 3 min read
A modern office building with a digital padlock symbol overlayed, representing cybersecurity
Share

Key points

  • OnTrac, a parcel delivery company serving the western United States, confirmed it was hacked in a breach that may affect customers expecting deliveries.
  • The UK Department for Education exposed records belonging to roughly 607,000 people, most of them children, in a data loss incident.
  • Amazon Web Services (AWS), the world's largest cloud computing platform, publicly linked a series of infrastructure attacks to hackers working on behalf of North Korea.
  • Adobe, the software company behind products like Photoshop and Acrobat, released security patches closing flaws that could let criminals take control of a victim's computer.

What happened to OnTrac customers?

OnTrac, which delivers parcels for retailers across states including California, Nevada, and Arizona, confirmed criminals broke into its systems. If you have been waiting on a delivery handled by OnTrac, your contact details or order information may have been caught up in the breach. Watch your inbox for phishing emails, which are fake messages designed to trick you into handing over passwords or payment details, that mention a missed delivery or a problem with your parcel. That is a classic follow-up move after this kind of breach.

How did 607,000 records leave a UK government department?

The UK Department for Education lost data on approximately 607,000 people. Most of those records belong to children. The department has not fully detailed how the loss occurred, but the failure mode here is almost always the same: data shared too broadly, stored without proper controls, or handed to a third party without adequate checks. Parents of school-age children in the UK should keep an eye out for any unusual contact that references their child's school or personal details.

Why is AWS naming North Korea?

Amazon Web Services publicly attributed a wave of attacks on cloud infrastructure to hackers acting on behalf of the North Korean government. In practice, major cloud providers rarely name nation states directly; when they do, it means the evidence is solid enough that they are willing to defend it. North Korean state hackers have a well-documented history of targeting cryptocurrency platforms and technology companies to steal funds that help fund the regime.

SecurityWeek flagged this attribution alongside separate research from a firm called Mythos focused on North Korean activity in the crypto sector, painting a consistent picture of a state that treats hacking as a revenue stream.

What did Adobe patch, and should you update now?

Yes, update now. Adobe pushed fixes for security flaws in several of its products. Some of those flaws were rated critical, meaning a criminal could exploit them to take full control of a computer simply by getting the target to open a malicious file. If you use any Adobe software on a Windows or Mac machine, open the application, go to Help, and check for updates today.

Story Who is affected Action needed
OnTrac breach Parcel recipients, western US Watch for phishing emails about deliveries
UK DfE data loss 607,000 people, mostly children Monitor for suspicious contact referencing school data
AWS / North Korea Cloud platform users, crypto firms Review cloud access logs, check IAM permissions
Adobe patches Anyone running Adobe software Update all Adobe products immediately

Operational takeaway: a breach disclosure with no detail about root cause is not a disclosure, it is a holding statement.

© 2026 Threat Vectr