OnTrac notifies customers of data breach after network hack

OnTrac notifies customers of data breach after network hack

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.

The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.

Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities.

image

OnTrac is a private American parcel-delivery company specializing in “last-mile” e-commerce deliveries, formed in 2021 from the merger of OnTrac Logistics and LaserShip.

The firm operates at 102 locations across 35 states, covering roughly 70% of the U.S. population, and working with more than 7,000 independent delivery contractors.

In response to the security incident, OnTrac contracted a third-party specialist to help determine the scope of the breach and took steps to “ensure the data described above was re-secured and not distributed.”

This statement suggests a possible agreement between the firm and the attackers, typically a ransom payment, to make sure that the customer information is not leaked.

"We are not aware of any fraud or publication of stolen information resulting from this incident, nor do we have any reason to believe any such misuse of information will occur," OnTrac says in the notification.

To help exposed customers mitigate the risks that may arise from the exposure of their sensitive data, OnTrac is offering free-of-charge access to a 12-month credit monitoring and identity protection service via CyberScout, with a 90-day enrollment deadline.

Recipients of the letter are also recommended to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if the risk is deemed significant.

BleepingComputer has contacted OnTrac to learn more about the attack, the number of impacted clients, and whether a ransom was paid, but we have not heard back by publication time.

At the time of writing, no ransomware or data extortion threat groups have taken responsibility for the attack.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper
source: BleepingComputer