“They Are Not Stealing Your Trucks. They Are Stealing Your Login.”
For most of my career, cybersecurity sat with the technology group. You hired competent people, you bought the tools, and the CEO asked about it once a year. That arrangement is finished, and freight is where the consequences are showing up first.
A criminal who wants your freight no longer needs to touch your freight. They need your email account, your load board credentials, and about a week of patience. The FBI published a warning about exactly this in April, and it should be read by every owner in this industry, not forwarded to the IT department.
What the FBI Is Actually Describing
On April 30, the Bureau issued a public service announcement titled Cyber-Enabled Strategic Cargo Theft Surging. The numbers in it will look familiar if you read our piece on insurance: cargo theft losses reached nearly $725 million in 2025, a 60% increase, with confirmed incidents up 18% and the average theft rising 36% to $273,990.
What makes the PSA worth your time is the mechanics. The FBI walks through the scheme step by step, and it is more disciplined than most people expect.
It starts with a phishing email that understands your business. The attacker impersonates a broker and sends a link, usually for a carrier-broker agreement or, more cleverly, an invitation to review and resolve a poor service rating. Anyone who has run a brokerage knows how fast someone will click a link about their own service scores. The link leads to a convincing fake site, which installs legitimate remote monitoring and management software. Not exotic malware. Ordinary admin software, which is exactly why it goes unnoticed. The attacker now has quiet, complete access.
From there, they get on the load boards using compromised accounts and post fake loads, sometimes tens of thousands of them, which pulls in legitimate carriers who then receive the same malicious agreement and get compromised themselves. The scheme recruits its own next victims.
Then the real theft. Posing as a compromised carrier, they accept genuine shipments and double-broker them to partially unwitting drivers with altered bills of lading and changed destinations. To make the cover hold, they update the legitimate carrier’s contact information with FMCSA and adjust its insurance information so it appears eligible for loads it never used to accept.
Sit with that for a second. Your authority, your MC number, your reputation, and your customers, operated by somebody else. The FBI notes that a compromised carrier often finds out only when brokers start calling about missing loads booked under their name.
The freight then gets cross-docked or transloaded to complicit drivers and sold. Sometimes the thieves come back and demand a ransom in exchange for telling the broker where the load is.
Why It Works So Well Right Now
The tactics in that PSA are not clumsy, and their success is documented in the CrowdStrike 2026 Threat Hunting Report, which covers investigations from July 2025 through June 2026.
The central finding is that attackers increasingly do not break in. They log in. CrowdStrike describes intrusions that occur without malware, lateral movement, or privilege escalation because a legitimate identity does all the work. They recorded a 171% surge in criminal activity aimed at cloud environments and a 15-fold spike in monthly device code phishing attempts, which is the technique for capturing a real login rather than cracking a password.
That is the same story the FBI is telling in freight terms. Nobody is defeating your firewall. They are borrowing your credentials and then behaving like you.
Speed is the second finding. CrowdStrike observed China-nexus adversaries exploiting vulnerabilities within 24 hours of a working proof of concept becoming public, and more than 80 victims identified within four days of one vulnerability disclosure. The window between a flaw becoming known and being used against you is now measured in hours.
Third, AI is on both sides of this. The report describes AI as a tool, a target, and a force multiplier for adversaries, with attackers generating payloads and shell commands, abusing enterprise language models, and in one case firing 200,000 API requests in two minutes to hijack a victim’s own AI resources. Meanwhile the software supply chain is being poisoned upstream, with over 300 software dependencies compromised in a single day by one group and 131 AI framework packages poisoned by another.
Put those together and you get the environment we are operating in. Attacks that look like normal logins, launched within hours of an opportunity appearing, at a scale no human team is generating by hand.
Freight Has a Specific Weakness
Every industry is exposed to this. Ours has a particular problem, and it comes from how we work.
Freight communication is fast, informal, and high-trust by design. A load needs covering in 20 minutes. Somebody emails a rate confirmation, somebody replies from a phone, a driver gets dispatched, and the whole exchange takes four minutes because that is what the job requires. That speed is a competitive advantage and an attack surface at the same time.
We are also a chain business. Your security posture includes every broker, carrier, and shipper you exchange documents with, and the FBI scheme spreads precisely along those relationships. A compromised counterparty is a compromised counterparty regardless of how good your own controls are.
And the fraudulent traffic has gotten convincing. Quote requests that read like real quote requests. Carrier packets that look like carrier packets. Service complaints that reference real details. The volume of it is machine-generated now, and the quality has risen with the tooling.
What to Watch For
The FBI’s indicator list translates directly into things your team can be trained to notice this week.
Someone contacts you about a shipment booked in your company’s name that nobody at your company authorized. Emails arrive from a free provider dressed up to look official, like [email protected] rather than your actual domain. Requests come in to download a document from a shortened or unfamiliar link. An email claims a negative service review and offers a link to resolve it. Domains arrive that are almost right, with an extra character, a different ending, or a small misspelling. Phone numbers turn out to be internet numbers that go dead a week later.
One indicator deserves special attention because it is the quietest: new or unauthorized mailbox rules. Forwarding to an outside address, automatic deletion, hidden folders. That is what someone sets up when they intend to stay inside your email without being noticed. Check for it.
The Health Check Belongs to the CEO
My view is that an internal cybersecurity health check is job number one, and it is not a technology exercise. It is a business review that the business owner needs to lead.
The questions are not complicated. Who can access what, and does that still match what people actually do? Is multifactor authentication genuinely everywhere, including load boards, email, and your TMS, rather than mostly everywhere? Can data be exported in bulk, and by whom, and would you know if it happened? Do you verify a change to banking, contact, or dispatch details through a second channel, using a number you already had rather than the one in the message? Does anyone check whether loads are moving under your authority that you did not book? And when someone reports something suspicious, does anything happen?
The FBI’s own guidance is unglamorous and effective: verify shipment requests and pickups independently before releasing loads, use multichannel verification, treat a familiar name or address as no proof of anything, and document the parties thoroughly, including drivers, licenses, plates, and DOT and MC numbers.
None of that requires a large budget. It requires a decision that this is a business priority.
Where We Fit, and Where We Do Not
We are a freight technology company, not a security vendor, and you need real security tooling and real expertise for the parts of this that are genuinely a security problem.
What we do own is the operational layer, and several of these attacks show up there first. The FBI notes that attackers change a carrier’s FMCSA contact and insurance details to make the impersonation hold. Our Risk and Compliance Guardrails continuously reverify carriers against live data, with each check timestamped, so a carrier whose registered details have suddenly changed is a flag rather than a surprise. That same continuous vetting is the answer to the rebrokering rulings courts handed down this month, and the FBI PSA describes double-brokering as a step in the theft itself.
EKA Control Center AI surfaces operational exceptions to a person while they are still small like a unplanned break in GPS tracking, required carrier documents details changed at pickup or mid-shipment – and the like – are exactly the anomalies worth someone’s attention.
There is also a structural point. Every additional disconnected system is another login, another vendor, another place credentials live, and another integration nobody is watching. Consolidating the operation into one environment reduces the number of doors and makes access control something you can actually manage, rather than something spread across a dozen administrator screens.
The Bottom Line
Cybersecurity in freight is now a business risk that sits alongside insurance, liability, and credit, and it belongs on the same agenda. A successful attack does not just cost you a load. It can put your authority in someone else’s hands, put your customers on the phone with your competitors, and stop your operation cold with ransomware.
Run the health check. Ask the uncomfortable questions yourself instead of delegating them. In part two of this series, we will get specific about what small and midsize operators should prioritize, because the guidance written for enterprises with security teams does not fit a company operating 30 – 150 trucks and one IT employee or contractor.
Talk to EKA about the operational side of this, and get real security help for the rest.
This article is general information about business risk, not security, legal, or insurance advice. If you believe you have been targeted, file a complaint with the FBI’s Internet Crime Complaint Center at ic3.gov and contact your local FBI field office in addition to reporting stolen cargo to local police.
FAQs
What is cyber-enabled cargo theft?
It is freight theft that begins with a computer intrusion instead of a break-in. Attackers compromise a broker’s or carrier’s email and load board accounts through phishing, then impersonate that company to accept real loads, alter bills of lading, change delivery destinations, and route freight to complicit drivers who sell it. The FBI issued a public warning about the surge in April 2026.
How do the attackers get in?
Usually through a phishing email designed for our industry, often a carrier broker agreement or a notice about a poor service rating. The link leads to a fake site that installs legitimate remote monitoring software, giving the attacker quiet, complete access without triggering the alarms that traditional malware would. CrowdStrike’s 2026 research describes the same broader pattern of intrusions that use valid credentials rather than malware.
What warning signs can I look for today?
Contact about shipments booked in your name that you did not authorize. Emails from free providers imitating your domain. Requests to download from shortened or unfamiliar links. Notices about negative service reviews with a link to resolve them. Lookalike domains with small misspellings or different endings. Phone numbers that are internet-based and short-lived. And check your mailbox rules for unauthorized forwarding, auto-deletion, or hidden folders.
Why is freight especially vulnerable?
Because the work is fast, informal, and built on trust between counterparties. Loads get covered in minutes through quick email and phone exchanges, which leaves little room for verification. The industry is also a chain, so a compromised broker or carrier becomes a threat to everyone they transact with, which is exactly how the FBI describes the scheme spreading.
Is this an IT problem or a business problem?
A business problem. The exposure is your operating authority, your customer relationships, your cargo, and your ability to keep running, which makes it a CEO-level risk rather than a technical one to delegate. Technology teams handle the tools. Deciding that verification, access control, and a regular health check are priorities is a business decision.
