emperadorRansomware Victim๐Ÿ‡บ๐Ÿ‡ธ US OrganizationTransportation

OnTrac

OnTrac is a major last-mile e-commerce delivery company formed by the 2021 merger of LaserShip and OnTrac. It positions itself as a direct alternative to FedEx and UPS, offering coast-to-coast coverage, 7-day-a-week operations, and competitive rates to reach over 75% of the U.S. population. We hold your full employee database, 197k records of employee PII: employeeNumber,xrefCode,firstName,middleName,lastName,loginId,employeeId,hireDate,originalHireDate,startDate,terminated,roles,legalEntity,legalEntityAddress,homePhone,mobilePhone,businessPhone,businessMobile,pager,personalFax,personalEmail,businessEmail,facebook,linkedin,addressPrimary1,addressPrimary2,addressMailing1,addressMailing2,userApproved,nativeAuth,culture We demand an amount of 1 million, otherwise your data WILL be publicly posted. Instructions will be emailed to you shortly. If you do not receive them, contact me on session, or email me. Session: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358 Email: xdlmfao@morke.ru, kajsdsalkufsaoiuairw7@outlook.com (I prefer session.) If you do not cooperate, your partners and employees will be targeted. Emails were sent to: webcustomerservice@ontrac.com, customerservice@ontrac.com, softwaresupport@ontrac.com, softwaresupport@ontrac.com, apisupport@ontrac.com, RSaiz@OnTrac.com, scorral@ontrac.com, SMcCandless@OnTrac.com [Sector: Retail, Transportation]

Incident Details

Threat Group
emperador
Victim / Organization
OnTrac
Website / Domain
โ€”
Industry Sector
Transportation
Country / Region
๐Ÿ‡บ๐Ÿ‡ธ US
Date Discovered
Wednesday, September 23, 2026

What This Listing Means

Posting on emperador's ransomware leak site typically signals that the threat actor claims to have:

  • โ–ธGained unauthorized access to the organization's network via phishing, exposed credentials, or an unpatched vulnerability
  • โ–ธExfiltrated sensitive data โ€” potentially including financial records, PII, customer data, or trade secrets
  • โ–ธDeployed ransomware to encrypt systems and disrupt operations
  • โ–ธIssued a ransom demand with a deadline to publish all stolen data publicly if unpaid

๐Ÿ‡บ๐Ÿ‡ธ US-based organizations hit by ransomware may have mandatory breach notification obligations under state laws, HIPAA (healthcare), SEC regulations (public companies), or CISA guidelines. The notification window is typically 72 hours from discovery.

Open Source Investigation

Is This Your Organization?

Security Arsenal provides 24/7 ransomware incident response. We contain active attacks, support ransom negotiation decisions, perform forensic analysis, and recover your data.

Get Emergency ResponseIR Services Overview

Protect Your Organization

โ† Back to Ransomware Tracker
OnTrac โ€” emperador Ransomware Leak Site Listing | Security Arsenal | Security Arsenal