Overview
OnTrac, one of the largest last-mile parcel delivery companies in the United States, is notifying customers that hackers gained unauthorized access to a portion of its corporate network over a three-day window in April 2025. The breach exposed a category of personally identifiable information (PII) that is particularly damaging: Social Security numbers, dates of birth, driver's license numbers, government-issued ID numbers, and in some cases health information — data that cannot be easily replaced or cancelled like a compromised credit card.
The company submitted breach notification data to the Maine Attorney General's Office, revealing more than 40,000 individuals were affected. Physical letters are being sent to impacted customers.
What Happened
Attackers gained access to a portion of OnTrac's internal network between April 13–15, 2025. The breach was discovered around April 15, triggering an internal response that included re-securing the network and engaging outside forensic investigators. The incident was later disclosed to regulators in accordance with state data breach notification laws.
As of the notification date, OnTrac reported no evidence that the stolen data had been publicly released or actively used for fraud — though this is a standard disclosure caveat and does not guarantee the data remains unexploited.
Who Is OnTrac
OnTrac (operating under parent company LaserShip, which acquired the brand in 2021) is a major US regional parcel carrier specializing in last-mile delivery. The company operates:
- 64 facilities across 31 states
- Four regional sorting centers
- Approximately $1.5 billion in annual revenue
OnTrac serves major e-commerce retailers and ships millions of parcels annually, meaning its customer database contains PII for a wide cross-section of American online shoppers.
Data Exposed
The breach exposed some of the most sensitive categories of personal information:
| Data Type | Risk |
|---|---|
| Social Security Numbers | Tax fraud, new account fraud, identity theft |
| Dates of Birth | Account verification bypass, combined with SSN: high risk |
| Driver's Licenses / Gov IDs | Document fraud, identity establishment |
| Medical / Health Information | Insurance fraud, HIPAA exposure implications |
Unlike compromised payment card numbers — which can be cancelled and reissued — SSNs and health records are effectively permanent identifiers. Victims face years of potential downstream identity fraud including fraudulent tax filings, benefit fraud, and synthetic identity attacks.
OnTrac's Response
OnTrac is offering affected individuals 12 months of complimentary credit monitoring and identity protection services. Activation codes are included in the physical breach notification letters being sent to impacted customers. The company states it has re-secured its network but has not disclosed specific details about the attack vector or whether ransomware was involved.
Legal Fallout
Law firms have already initiated investigations into the breach for potential class action litigation:
- Shub Johns & Holbrook LLP — investigating OnTrac's data security practices
- Barnow and Associates — exploring claims on behalf of affected customers
The litigation focus centers on OnTrac's alleged failure to implement adequate technical safeguards to protect the sensitive data it collects as part of its delivery operations.
What Affected Customers Should Do
If you receive an OnTrac breach notification letter:
- Activate the credit monitoring offer included in your letter — use the full 12-month period
- Place a credit freeze with all three major credit bureaus (Equifax, Experian, TransUnion) — this is free and prevents new accounts from being opened in your name
- Request your free credit reports at AnnualCreditReport.com and review for unfamiliar accounts
- File your taxes early to prevent fraudulent tax returns using your SSN
- Monitor your health insurance explanation-of-benefits statements for services you didn't receive
- Consider an IRS Identity Protection PIN at IRS.gov to prevent tax fraud
Industry Context
The OnTrac breach is part of a pattern of logistics and delivery companies being targeted by attackers seeking large PII datasets. Delivery companies are attractive targets because they collect full customer PII — including home addresses and phone numbers — at scale from e-commerce operations, while their internal security posture often lags behind financial sector peers.