What Happened in the OnTrac Data Breach?
OnTrac, the parcel delivery company that operates under the legal name LaserShip, Inc., has notified customers about a data security incident. The company learned of suspicious activity on a limited part of its corporate computer network in March 2026. As a result, OnTrac moved quickly to bring in outside cybersecurity specialists to figure out what happened.
According to the notification, unauthorized access to certain files occurred between March 20 and March 22, 2026. This means the intrusion itself took place over a short window in late March 2026, shortly before OnTrac detected the suspicious activity. The company has not disclosed exactly how the attacker gained access to its systems.
Because the situation involved sensitive customer files, OnTrac worked with third-party forensic experts to conduct a full review of the affected data. This investigation took several months to complete. OnTrac has stated that it is not currently aware of any fraud or public posting of the stolen information. However, the company also acknowledged it cannot rule out future misuse, which is why it chose to notify affected individuals directly.
Who was affected?
The notification letter was sent to OnTrac customers whose personal information was stored on the affected systems. OnTrac has not publicly disclosed the total number of individuals affected by this breach. Because OnTrac operates as a delivery and logistics provider across much of the United States, the exposure could reach customers in many different states.
It remains unclear whether the exposed data belongs primarily to consumers who received packages, business clients, or a mix of both. In addition, the notification does not specify whether employees or contractors were included among those affected. Anyone who received a breach notification letter from OnTrac, or from its claims administrator Cyberscout, should assume their information was part of the exposed files.
What Information Was Potentially Exposed?
OnTrac’s notification letter confirms that the exposed files included each individual’s name paired with other sensitive data elements. The specific categories of information varied by recipient, since the letter was designed to list personalized data elements for each affected person. Based on the protective measures OnTrac is offering, the exposed data likely included sensitive identifiers.
- Full name
- Additional personal data elements specific to each individual, as referenced in the notification letter
- Information sufficient to warrant credit monitoring and identity protection services
When a company offers credit monitoring and identity protection after a breach, this usually signals that the exposed data included sensitive identifiers like Social Security numbers or financial account details. As a result, affected individuals should treat this breach seriously, even without a complete public list of every data type involved.
If sensitive identifiers were part of the exposed files, affected individuals could face a heightened risk of identity theft. Criminals often use stolen names combined with other personal details to open new credit accounts, file fraudulent tax returns, or apply for loans. In addition, exposed contact information can fuel targeted phishing attempts designed to trick victims into revealing even more sensitive data.
What is the company doing?
Once OnTrac discovered the suspicious activity, it immediately launched an investigation with the help of third-party cybersecurity specialists. The company also took steps to re-secure the affected data and confirmed that it had not been further distributed. This rapid response helped limit the scope of the exposure once the intrusion was identified.
Following the completion of the forensic review, OnTrac began notifying affected individuals in July 2026. The company is offering complimentary credit monitoring and identity protection services through Cyberscout, a TransUnion company that specializes in fraud assistance. OnTrac has also set up a dedicated assistance phone line for people with questions about the incident and their eligibility for these protective services.
What Should Affected Individuals Do?
Enroll in Credit Monitoring and Identity Protection
OnTrac is offering free credit monitoring and identity protection services through Cyberscout. Affected individuals should enroll as soon as possible, since the offer requires signing up within 90 days of the notification letter’s date. Enrollment requires an internet connection and an email address, and the service is not available to minors under 18.
This service can alert you quickly if someone tries to open new credit in your name. Because notifications are sent the same day a change appears on your credit file, enrolling gives you a real head start on catching fraud early. Taking advantage of this free offer costs nothing and provides meaningful protection.
Monitor Your Accounts and Credit Reports
Beyond the offered monitoring service, you should regularly check your own bank and credit card statements for unfamiliar charges. You are also entitled to one free credit report every year from each of the three major bureaus: Equifax, Experian, and TransUnion. You can request these at annualcreditreport.com or by calling 1-877-322-8228.
When reviewing your credit report, look closely for accounts you did not open or credit inquiries you do not recognize. If you spot anything suspicious, report it to the relevant credit bureau immediately. Because fraud can sometimes take months to surface, continued vigilance over the coming year is important.
Consider a Fraud Alert or Credit Freeze
Given that this breach may have involved sensitive personal identifiers, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires businesses to verify your identity before extending new credit in your name. You can request an initial one-year alert for free by contacting any one of the three credit bureaus.
Alternatively, a credit freeze blocks lenders from accessing your credit report altogether without your explicit permission. This offers stronger protection than a fraud alert, though it may slow down legitimate credit applications. Federal law guarantees that placing or lifting a freeze is always free of charge.
Stay Alert for Phishing Attempts
After a data breach, scammers often send emails or texts pretending to be the breached company or a related service provider. Therefore, be cautious of any unexpected messages referencing OnTrac, Cyberscout, or credit monitoring enrollment. Never click links or share personal details in response to unsolicited communications.
Instead, go directly to the official enrollment website or call the dedicated assistance line listed in your notification letter. If you are ever unsure whether a message is legitimate, contact the company directly using verified contact information. This simple habit can prevent you from becoming a victim of a secondary scam tied to this breach.
Consult a Data Breach Attorney
If your personal information was exposed in this incident, you may want to speak with an attorney who focuses on data breach cases. An attorney can help you understand whether you qualify for compensation and what steps to take next. Many offer free consultations, so reaching out costs you nothing upfront.
Because breach-related litigation often involves strict filing deadlines, it helps to act sooner rather than later. A qualified attorney can also help you document any losses tied to the breach, which strengthens any potential claim. This step is especially worthwhile if you notice signs of identity theft or fraud.
