Skip to content
Ransomware News

Ransomware Group emperador Hits: OnTrac

Admin
HookPhish team

Summary

In the latest cybersecurity news, OnTrac — an organization based in US — has fallen victim to a ransomware attack conducted by the group emperador. This data breach, discovered on 2026-09-23T20:51:04.749900+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization OnTrac
Threat Group emperador
Summary OnTrac is a major last-mile e-commerce delivery company formed by the 2021 merger of LaserShip and OnTrac. It positions itself as a direct alternative to FedEx and UPS, offering coast-to-coast coverage, 7-day-a-week operations, and competitive rates to reach over 75% of the U.S. population.

We hold your full employee database, 197k records of employee PII:

employeeNumber,xrefCode,firstName,middleName,lastName,loginId,employeeId,hireDate,originalHireDate,startDate,terminated,roles,legalEntity,legalEntityAddress,homePhone,mobilePhone,businessPhone,businessMobile,pager,personalFax,personalEmail,businessEmail,facebook,linkedin,addressPrimary1,addressPrimary2,addressMailing1,addressMailing2,userApproved,nativeAuth,culture

We demand an amount of 1 million, otherwise your data WILL be publicly posted.

Instructions will be emailed to you shortly.

If you do not receive them, contact me on session, or email me.

Session: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358
Email: [email protected], [email protected]

(I prefer session.)

If you do not cooperate, your partners and employees will be targeted.

Emails were sent to: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected] [Sector: Retail, Transportation]

Date of Breach 2026-09-23T20:07:00+00:00
Discovery Date 2026-09-23T20:51:04.749900+00:00
Region US
Business Sector Transportation

 

How to reduce your ransomware risk

Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:

Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions