Ransomware.Live Emperador Ransomware Targets OnTrac with Employee Data Theft Claims
Article Content
- •Emperador ransomware claims to have stolen 197,000 employee records from OnTrac.
- •OnTrac's previous breach in March 2026 involved unauthorized access to customer files.
- •No independent verification of the current claims has been established.
The Emperador ransomware group has claimed a new attack against OnTrac, a major U.S. parcel carrier, alleging the theft of approximately 197,000 employee records and demanding a ransom of $1 million. This claim follows a previously confirmed network breach at OnTrac that occurred between March 20-22, 2026, where unauthorized access to customer files was reported. OnTrac has not publicly confirmed the latest ransomware claim, and there is currently no independent evidence to verify the extent of the alleged data compromise. The Emperador group has also threatened to release salary information for OnTrac employees. As of now, the claims remain unverified, and the situation is being monitored closely for any further developments or evidence from Emperador. The attack highlights ongoing vulnerabilities in the logistics sector and the potential for significant data breaches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Emperador and Electrolux in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Attacks Target Multiple Companies in September 2026 In September 2026, multiple ransomware groups, including Booba Project and Panzer, launched attacks on various organizations. Atlas Ocean Voyages suffered a breach where 37 GB of sensitive data was stolen, while Cerámicas Kantu S.A.C. was threatened with data release unless negotiations occurred. The attacks highlight…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…