Ransom! OnTrac (SEP-2026)
In the US, the emperador threat actor reportedly targeted OnTrac, a major last-mile e-commerce delivery company, and exfiltrated 197k employee PII records as leverage for a $1 million ransom demand, threatening public release. The attackers sent ransom/payment instructions and extortion notices to OnTrac contacts, warning that non-cooperation would result in data being made public and “partners and employees” being targeted. #UnitedStates

Incident Details

  • Victim: OnTrac
  • Sector: Transportation
  • Country: US
  • Actor: emperador
  • Source: http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/ontrac/
  • Discovered: 2026-09-23T20:51:04.749900+00:00
  • Published: 2026-09-23T20:07:00+00:00

Information

  • OnTrac is a major last-mile e-commerce delivery company formed by the 2021 merger of LaserShip and OnTrac, positioned as a direct alternative to FedEx and UPS with coast-to-coast coverage, 7-day-a-week operations, and competitive rates reaching over 75% of the U.S. population.
  • The attackers claim to have obtained the full employee database, including 197,000 records containing employee PII and related HR and contact details.
  • A ransom demand of $1 million was issued, with a threat to publicly post the data if payment is not made.
  • The threat actor stated that instructions would be emailed, with additional contact offered via session or email if messages are not received.
  • The message warned that employees and partners would be targeted if cooperation was not provided.
  • Notification emails were sent to multiple OnTrac contacts, including customer service, software support, API support, and several named employees.

Disclaimer: This post is based on public claims made by the ransomware group "emperador". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live