Skip to content

OnTrac Parcel Delivery Company Suffers Data Breach After Network Hack

OnTrac, a private American parcel-delivery company specializing in last-mile e-commerce deliveries, has informed its customers that hackers breached its corporate network and accessed their personal details. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.

The type of information exposed is unclear as OnTrac redacted the data elements in the notification sample shared with authorities. However, the company has assured customers that they are not aware of any fraud or publication of stolen information resulting from this incident.

In response to the security incident, OnTrac contracted a third-party specialist to help determine the scope of the breach and took steps to ensure the data described above was re-secured and not distributed. This statement suggests a possible agreement between the firm and the attackers, typically a ransom payment, to make sure that the customer information is not leaked.

To help exposed customers mitigate the risks that may arise from the exposure of their sensitive data, OnTrac is offering free-of-charge access to a 12-month credit monitoring and identity protection service via CyberScout. Recipients of the letter are also recommended to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if the risk is deemed significant.

BleepingComputer has contacted OnTrac to learn more about the attack, the number of impacted clients, and whether a ransom was paid, but we have not heard back by publication time. At the time of writing, no ransomware or data extortion threat groups have taken responsibility for the attack.

OnTrac's Response to the Data Breach

OnTrac has taken steps to address the security incident and protect its customers’ sensitive information. The company has contracted a third-party specialist to help determine the scope of the breach and ensure that the data is re-secured and not distributed. This response suggests that OnTrac may have paid a ransom to the attackers to prevent further exposure of customer information.

Impact on Customers

The type of information exposed in the data breach is unclear, as OnTrac redacted the data elements in the notification sample shared with authorities. However, customers are advised to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if the risk is deemed significant.

Mitigation Measures

OnTrac is offering free-of-charge access to a 12-month credit monitoring and identity protection service via CyberScout. This service will help customers mitigate the risks that may arise from the exposure of their sensitive data. Recipients of the letter are also recommended to review their credit reports and account statements, and consider placing a free fraud alert or credit freeze if the risk is deemed significant.

Conclusion

The data breach at OnTrac highlights the importance of robust cybersecurity measures in protecting sensitive customer information. While the company has taken steps to address the security incident, customers are advised to remain vigilant and take proactive measures to protect their personal details.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *