OnTrac tells customers hackers were inside its network for three days in March
The last-mile delivery firm hints at a quiet deal with its attackers, but no ransomware crew has claimed the hit.

Key points
- OnTrac, a US last-mile parcel delivery company, says hackers were inside its corporate network between 20 and 22 March 2024.
- The intrusion was spotted on 23 March, and files containing customer names and other redacted personal details were accessed.
- OnTrac says the stolen data was "re-secured and not distributed", wording that typically points to a ransom payment.
- No ransomware group has claimed the attack, and OnTrac has not said how many customers are affected.
- Affected customers are being offered 12 months of free credit monitoring through CyberScout, with 90 days to enrol.
OnTrac, the US parcel-delivery firm that handles roughly 70% of the country's last-mile e-commerce drops, is writing to customers to say hackers got into its corporate network in March and took files containing their personal information.
OnTrac was formed in 2021 from the merger of OnTrac Logistics and LaserShip. It runs 102 depots across 35 states and works with more than 7,000 independent drivers. If you have ever had a package from Amazon or a similar retailer land on your doorstep on the East or West Coast, there is a good chance OnTrac carried it the last mile.
The company says it spotted the intrusion on 23 March. An internal investigation found the attacker was rummaging through files between 20 and 22 March, a window of about 72 hours.
What was stolen?
Customer names, and other personal details that OnTrac has blanked out in the sample breach notice it filed with regulators. The company has not spelled out publicly whether addresses, phone numbers, tracking histories or anything more sensitive were in the files.
The redactions matter. Notification letters usually list the specific data categories exposed, so a redacted sample suggests OnTrac is telling different customers different things depending on what was in their record.
Did OnTrac pay a ransom?
Probably, though the company will not say so directly. In its notice, OnTrac says it took steps to "ensure the data described above was re-secured and not distributed."
You cannot "re-secure" data that has already left your network unless the people holding it agree to hand it back or delete it. In practice, that phrasing almost always describes a ransom payment, the money criminals demand in exchange for not publishing stolen files on a leak site.
OnTrac told BleepingComputer, which first reported the incident, that it is not aware of any fraud or publication of the stolen data. No ransomware or extortion crew has claimed the attack on their leak site, which is consistent with a deal being struck early.
What should OnTrac customers do?
Enrol in the free credit monitoring OnTrac is offering, keep an eye on bank and card statements, and consider a fraud alert if anything looks off.
OnTrac is paying for 12 months of credit monitoring and identity protection through a service called CyberScout. Customers have 90 days from receiving the letter to sign up, so the letter is not something to leave on the kitchen counter.
A fraud alert is free and tells lenders to double-check before opening credit in your name. A credit freeze goes further and blocks new credit applications entirely until you lift it. Both are worth considering if the letter suggests sensitive details, not just your name, were in the files.
| Detail | What OnTrac says |
|---|---|
| Intrusion window | 20 to 22 March 2024 |
| Discovered | 23 March 2024 |
| Data confirmed exposed | Customer names, other details redacted |
| Customers affected | Not disclosed |
| Ransom | Not confirmed, wording suggests a payment |
| Support offered | 12 months CyberScout credit monitoring |
Who is likely behind it?
Unknown, and that silence is itself a clue. When ransomware groups do not get paid, they name victims on public leak sites within days or weeks to pressure them. Months on from the OnTrac intrusion, no group has claimed it. Either the attackers were unusually private, or they got what they wanted and moved on.



