Ransomware group emperador hits OnTrac
OnTrac — a transportation target operating in US has been listed by the emperador ransomware group on 2026-09-23. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | OnTrac |
|---|---|
| Threat Group | emperador |
| Summary | OnTrac is a major last-mile e-commerce delivery company formed by the 2021 merger of LaserShip and OnTrac. It positions itself as a direct alternative to FedEx and UPS, offering coast-to-coast coverage, 7-day-a-week operations, and competitive rates to reach over 75% of the U.S. population. We hold your full employee database, 197k records of employee PII: employeeNumber,xrefCode,firstName,middleName,lastName,loginId,employeeId,hireDate,originalHireDate,startDate,terminated,roles,legalEntity,legalEntityAddress,homePhone,mobilePhone,businessPhone,businessMobile,pager,personalFax,personalEmail,businessEmail,facebook,linkedin,addressPrimary1,addressPrimary2,addressMailing1,addressMailing2,userApproved,nativeAuth,culture We demand an amount of 1 million, otherwise your data WILL be publicly posted. Instructions will be emailed to you shortly. If you do not receive them, contact me on session, or email me. Session: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358 Email: xdlmfao@morke.ru, kajsdsalkufsaoiuairw7@outlook.com (I prefer session.) If you do not cooperate, your partners and employees will be targeted. Emails were sent to: webcustomerservice@ontrac.com, customerservice@ontrac.com, softwaresupport@ontrac.com, softwaresupport@ontrac.com, apisupport@ontrac.com, RSaiz@OnTrac.com, scorral@ontrac.com, SMcCandless@OnTrac.com [Sector: Retail, Transportation] |
| Date of Breach | 2026-09-23 |
| Discovery Date | 2026-09-23 |
| Region | US |
| Target Domain | — |
| Business Sector | Transportation |
| Severity | MEDIUM |
Claim by emperador
OnTrac is a major last-mile e-commerce delivery company formed by the 2021 merger of LaserShip and OnTrac. It positions itself as a direct alternative to FedEx and UPS, offering coast-to-coast coverage, 7-day-a-week operations, and competitive rates to reach over 75% of the U.S. population. We hold your full employee database, 197k records of employee PII: employeeNumber,xrefCode,firstName,middleName,lastName,loginId,employeeId,hireDate,originalHireDate,startDate,terminated,roles,legalEntity,legalEntityAddress,homePhone,mobilePhone,businessPhone,businessMobile,pager,personalFax,personalEmail,businessEmail,facebook,linkedin,addressPrimary1,addressPrimary2,addressMailing1,addressMailing2,userApproved,nativeAuth,culture We demand an amount of 1 million, otherwise your data WILL be publicly posted. Instructions will be emailed to you shortly. If you do not receive them, contact me on session, or email me. Session: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358 Email: xdlmfao@morke.ru, kajsdsalkufsaoiuairw7@outlook.com (I prefer session.) If you do not cooperate, your partners and employees will be targeted. Emails were sent to: webcustomerservice@ontrac.com, customerservice@ontrac.com, softwaresupport@ontrac.com, softwaresupport@ontrac.com, apisupport@ontrac.com, RSaiz@OnTrac.com, scorral@ontrac.com, SMcCandless@OnTrac.com [Sector: Retail, Transportation]
Posted by the emperador threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Leak post (onion / Tor)
http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/ontrac/
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

