Cyber & AI intelligence
Wasteland.
Briefs indexed2861
Issues29
Published Mondays07:30 CT
█ Ransomware ONTRAC-EMPERADOR-R 2026-09-24

OnTrac: Emperador Ransomware Group Claims Theft of 197k Employee Records

"The Emperador ransomware group added US parcel carrier OnTrac to its leak site on 23 September 2026. The group says it stole a database of about 197,000 employee records and wants $1 million to keep the data private…"

The Emperador ransomware group added US parcel carrier OnTrac to its leak site on 23 September 2026. The group says it stole a database of about 197,000 employee records and wants $1 million to keep the data private. Several threat-intelligence trackers picked up the listing, including Ransomware.live, ThreatMon, HookPhish and QPulse. This is an unverified claim. OnTrac has not confirmed a breach, and no PRIMARY or established-press source has corroborated it. Every source used here is an aggregator or automated tracker that repeats the attacker's own post.

What Happened

The trackers broadly agree on the timing, with small differences:

OnTrac is the last-mile e-commerce carrier formed when LaserShip and OnTrac merged in 2021. It markets itself as an alternative to FedEx and UPS that reaches more than 75% of the US population.

The listing says Emperador contacted OnTrac directly. It names eight OnTrac email recipients (redacted in the source copies) and gives a Session messenger ID and email addresses for negotiation. It also threatens that "your partners and employees will be targeted" if OnTrac does not pay. The group has published no data sample. Nothing public shows that systems were encrypted or that deliveries were disrupted.

Undercode News adds one piece of context: it reports that OnTrac disclosed a separate intrusion earlier in 2026, with unauthorized access between 20 and 22 March during which customer files were accessed. No other source in this set mentions that incident, and Undercode says there is no evidence linking it to the Emperador claim. Treat any connection as unproven.

What Was Taken

Every source that gives a number uses the same one: about 197,000 employee records (QPulse, HookPhish and Undercode, all quoting the leak-site post). Undercode notes that ThreatMon's own feed entry does not include a record count. So all of these figures trace back to the attacker's claim, not to independent counting.

The listing names these fields:

Analyst assessment: The field names look like a standard export from an HR or workforce-management platform. The terminated and originalHireDate fields suggest the dataset covers former staff as well as current ones, which could explain a count far larger than OnTrac's current headcount. No Social Security numbers, bank details or passwords are listed. Even so, home addresses, personal emails, phone numbers and login IDs together give an attacker plenty to work with for targeted phishing, SIM-swap attempts and credential attacks.

Why It Matters

The group has a short and shaky track record. Yazoul reports that public intelligence on Emperador is "extremely limited", with no documented tools, tactics or reliable victim count. Emperador does not appear among the most active groups in ZeroHour's 30-day leak-site activity table. Its recent claims show it posts several victims a week in different countries and sectors:

The Electrolux listing contradicts itself. The post claims about 41 GB was taken from an Azure database, but the listing metadata shows 12.7 GB. That kind of mismatch is a reason to be cautious about Emperador's figures generally.

The threat to employees is the practical risk. Whether or not the breach is real, the group has publicly named OnTrac's partners and workforce as targets. Logistics employees, especially drivers and warehouse staff at contractor firms, are frequent targets of payroll-diversion and credential-phishing scams. A leaked employee list containing login IDs would make those scams more effective.

The Attack Technique

How the attackers got in is unknown. None of the sources describe the initial access method, and the listing does not mention encryption. The claim fits the data-theft-and-extortion model that is now common, in which a group steals data and threatens to publish it without deploying ransomware.

In the Electrolux case, Emperador said it got in through an Azure database. That suggests, but does not prove, that the group goes after exposed or poorly secured cloud data stores and SaaS systems rather than breaking into internal networks. If the OnTrac data came from an HR SaaS platform, the most likely routes would be stolen credentials, an over-permissioned API integration, or a compromised account at a third-party provider. This is inference, not reported fact.

What Organizations Should Do

  1. Audit HR and workforce-management systems. Review API keys, service accounts and third-party integrations with bulk-export rights. Rotate any credentials that are old or shared, and alert on large record exports.
  2. Warn employees now. If you hold workforce data similar to this, tell staff (including former staff where you can) to expect phishing, fake payroll-update requests and SIM-swap attempts that use their real details.
  3. Lock down login IDs. Because loginId and nativeAuth fields appear in the claimed data, enforce phishing-resistant MFA on employee portals. Watch for credential stuffing against those usernames.
  4. Check your cloud data stores. Look for publicly reachable databases, storage accounts with anonymous or SAS-token access, and conditional-access gaps. Azure is the vector Emperador named in the Electrolux case.
  5. Prepare partners for impersonation. Tell logistics partners and merchant customers that fraud may follow, including emails claiming to come from OnTrac or from the extortion group.
  6. Treat leak-site claims as unconfirmed until verified. Track Emperador's listings. Do not act on or share any leaked files. Confirm any exposure through your own logs before notifying people.

Sources: Emperador Ransomware Group Claims Theft of 197k Employee Records fr... | Ransomware Group emperador Hits: OnTrac | Emperador Claims OnTrac Breach: 197,000 Employee Records Allegedly... | Two New Ransomware Victims Reported: OnTrac and Trump Mobile Added... | Emperador Targets Westbridge Institute of Technology - DeXpose | Navitrans Ransomware Claim by emperador (Sep 2026) | Ransomware victims & data breaches - ZeroHour | Ransomware group emperador hits Electrolux HackerFeeds