Skip to content
Rush Commerce
Commerce & Retail Tech3 min read

OnTrac breach: your carrier holds your customer data

OnTrac found intruders in its network on March 23 and started notifying customers in late July. Your shipping carrier is a data processor you don't audit.

You picked your parcel carrier on rate cards and delivery windows. Nobody on your team asked how long it takes them to tell you when someone walks off with your customers' names and addresses. OnTrac just answered that question, and the answer is four months. The OnTrac data breach is a reminder that every carrier you hand an address file to is a data processor operating on your behalf — and you almost certainly have no visibility into their incident response.

What actually happened

Per BleepingComputer, OnTrac — the regional parcel carrier serving the western US, now part of LaserShip/OnTrac — began sending breach notification letters in late July 2026. The timeline in those letters: an attacker accessed files on OnTrac's corporate network between March 20 and March 22, 2026, and the company discovered it on March 23, 2026.

That's a fast detection and a very slow disclosure. OnTrac says it brought in a third-party specialist, investigated, and "took steps to ensure the data described above was re-secured and not distributed" — phrasing that in practice usually means someone negotiated with the people holding the files. The company states it is not aware of any fraud or publication of the stolen information. Affected people get 12 months of credit monitoring and identity protection through CyberScout, with a 90-day enrollment window.

What was actually taken is harder to pin down. OnTrac redacted the specific data elements in the notification sample BleepingComputer reviewed, so beyond customer names the exposure isn't publicly established. We've seen larger figures circulating for the affected headcount; we're not repeating them, because the reporting we can verify doesn't support a number.

Why this matters for your business

Here's the part that lands on you. A carrier breach is your breach in your customers' eyes. The person who gets the letter didn't sign up with OnTrac. They bought a lamp from you. When their name and address leak, the brand they associate with the failure is yours, and the support tickets come to your inbox — four months after the fact, with you learning about it at the same time they do.

The fix isn't leverage you don't have. It's a contract term and a data diet.

The contract term: a breach notification SLA in your carrier and 3PL agreements. Notify us within 72 hours of discovery, not four months. Small merchants assume they can't ask for this. You can — it's boilerplate in any DPA, and carriers sign DPAs all day.

The data diet: audit what you actually push to each logistics vendor. Most shipping integrations are lazy about payload scope because the API accepts whatever you send. A label needs name, address, and a weight. It does not need order history, customer notes, email marketing consent flags, or the phone number you use for account recovery. Every field you don't send is a field that can't show up in somebody else's notification letter.

Then close the loop: know which vendors hold which fields, and who at that vendor you call. If you can't name the person, you don't have an escalation path — you have a support form.

Key takeaways

  • OnTrac detected an intrusion on March 23, 2026, and began notifying affected people in late July — roughly a four-month gap
  • The specific data elements were redacted in the notification sample; beyond names, exposure isn't publicly established
  • Put a 72-hour breach notification SLA in your carrier and 3PL contracts — it's standard DPA language, and you can ask for it
  • Audit your shipping payloads: a label needs name, address, and weight, not your full customer record

Can you list every vendor that holds your customer data, and exactly which fields each one gets? Most operators can't, because the integrations were built to work, not to be minimal. We map the data flowing out of your stack, trim the payloads to what each vendor actually needs, and document the escalation path for when one of them gets hit. See how we work.

Sources: BleepingComputer.

  • #data-breach
  • #logistics
  • #vendor-risk
  • #ecommerce
  • #shipping
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.