“If Copies of Your Email Are Going to a Stranger, Somebody Is Already Inside.”
A thief who has your email password can book loads in your name, change delivery locations, sell the freight, and leave you to explain it to your customer. He does it without going near a truck or a dock. The FBI described that scheme in a warning it issued in April, and part one of this series walked through how it runs, step by step.
Most published security guidance assumes the existence of a security team. That guidance runs dozens of items deep, and nothing in it says which item to do first. A company whose entire IT function is one person, or a contractor who bills by the hour, has no way to work a list like that. That describes most carriers, most brokers, and a great many shippers of every size short of the majors.
The Center for Internet Security, a nonprofit whose security standards are used across US industry, already sorted its recommendations for companies in exactly that position. CIS publishes 3 tiers, ranked by the amount of security expertise a company has on staff. The first tier is written for companies with little or none. It holds 56 items. CIS calls it Implementation Group 1.
56 items is still too many for one person. The 7 below are the ones that stop the scheme the FBI described, ordered so the cheapest and most decisive work comes first. Most companies finish 4 of them before something urgent interrupts, which is why the order matters as much as the list.
1. Turn On Multifactor Authentication, and Own the Rollout Yourself
Turn on multifactor authentication everywhere you have to log in to get somebody something. Email first, then the load boards, then your TMS, then anything that touches money. Do the administrator accounts before everyone else’s.
Multifactor authentication is the first thing you do because the theft starts with a working login. Nobody defeats the firewall. A second factor makes a stolen password worthless, which is why CISA puts this one on the chief executive’s list rather than the IT list and tells the CEO to own the rollout personally.
You need to spend a few hours of setup and be prepared to handle a week of complaints. My view is that the rollout belongs to the owner, because it fails on exceptions. Someone will say their phone will not run the app. Someone else will say the load board is too slow with it turned on. Unless the person who signs the checks has already decided the answer, those exceptions get granted.
2. Check Whether Copies of Your Email Are Going Somewhere Else
Open the rules settings in every mailbox and read what is in there. Start with dispatch and accounts payable. Those two mailboxes carry the load and payment traffic a thief is after.
Every email system lets you set rules that handle messages automatically. One kind of rule sends a copy of everything that arrives to an outside address. An attacker sets one up so that changing your password later does not cut off the feed. He keeps reviewing your rate confirmations and payment traffic in his own inbox, and nothing looks wrong on your screen. The FBI’s indicator list names this directly: new or unauthorized rules that forward mail to an external address, automatically delete messages, or file them in a folder no one opens.
You can expect to spend an afternoon and nothing else. If you find a rule nobody at your company wrote, somebody is already inside.
3. Call Back on the Number You Already Had
Before you act on any request to change banking details, a remit-to address, a dispatch contact, or insurance information, call the company back on the number already in your file. Never use the number printed in the message asking for the change. Write that down as a standing rule and apply it, whoever the request appears to come from.
The scheme works because the request looks legitimate, and the reply address belongs to the thief. The FBI’s own guidance is short on this point: verify shipment requests and pickups independently before you release a load, use more than one channel, and confirm anything unexpected through a second channel.
You do not need to spend any time executing this, as long as the rule is written down. A rule kept in one person’s head stops being followed the day that person is out.
4. Take Control of Your FMCSA Registration Account
If you hold operating authority, find out who at your company owns your FMCSA registration account, who else can sign in, and when somebody last checked the registered contact and insurance details. Put that last check on a monthly schedule. Shippers can move to item 5.
An attacker who updates a carrier’s FMCSA contact and insurance information makes his impersonation hold up when a broker runs a check on him. That step works because many carriers cannot say who has access to their own records. FMCSA is replacing the registration system now. Motus opened to supporting companies on December 8, 2025, and to all regulated entities in the second quarter of 2026, with fraud prevention and identity verification named as reasons for the rebuild. Existing USDOT and docket numbers carry over unchanged.
An afternoon’s worth of work to sort out who has access, then a few minutes a month to check.
5. Take Away the Right to Install Software, and Turn On Encryption
Remove the ability to install software for anyone who does not need it and enable full-disk encryption on every laptop.
The FBI describes the thief installing ordinary remote access software rather than a virus, which is why antivirus software does not flag it. Somebody who cannot install software cannot be talked into installing that. Encryption answers a separate problem: an encrypted laptop left at a truck stop costs you a laptop and nothing more.
This does not cost you anything. Both come with the operating system you already bought. Expect one argument per person over the install rights.
6. Restore a File and Time It
Pick a real system and a real file, restore them from your backup, and write down how many hours it took. Once a quarter is enough.
CISA’s instruction is to test restores regularly rather than trusting that the backup job runs. A backup nobody has ever restored is a guess. The number that matters is how many hours your operation sits idle waiting for the file, because that is what a ransomware morning actually costs you.
To accomplish this, you will need to spend half a day, 4 times a year.
7. Give One Person the Job and 15 Minutes a Month
Put one person’s name on this work and give them a standing 15-minute slot in a meeting you already hold.
CISA recommends appointing a security program manager who reports progress to leadership every month. For a company without a security team, that job is a name and a calendar slot. It matters because every item above comes undone over time. Multifactor authentication is disabled for a driver app that will not cooperate. A new dispatcher gets the right to install software because it was faster that morning. A new rule appears on somebody’s mailbox, sending copies outside.
Cost is 15 minutes a month, and it builds the record you need the day somebody asks you to prove you manage risk.
What to Skip for Now
Do not buy a security product until the 7 items above are finished.
Vendors will offer you a service that monitors your systems around the clock, a platform that collects and sorts security alerts, a test in which someone is paid to break into your network, and a security executive on contract for a few hours a month. Every one of those solves a real problem. Every one of them assumes the basics are already in place.
CIS makes the same point by splitting its list into tiers. The first tier exists because the list that fits a bank does not fit a company with no security staff, and the higher tiers assume you employ people. Paying for monitoring before you turn on multifactor authentication is like paying someone to watch a thief walk in through an unlocked door.
Practice drills are worth running, and CISA recommends them. They come after the list.
Where We Fit, and Where We Do Not
We build freight technology. We are not a security company, and the 7 items above are yours to do. No vendor, this one included, turns on your multifactor authentication or reads through your email settings for you.
What we own is the operational layer, where 2 of the FBI’s steps show up first. EKA Risk and Compliance Guardrails runs automated FMCSA safety checks and ongoing carrier risk monitoring against safety and insurance requirements, so you hear about a carrier whose registered details changed before you tender the load, rather than after the freight is gone. That is the same continuous vetting the courts put pressure on when a carrier re-brokers your load. EKA Control Center AI flags operational exceptions while they are still small, including an unplanned break in GPS tracking or changes to carrier document details at pickup or mid-shipment.
There is also a counting problem. Every disconnected system is another login and another place credentials sit. A company running 9 systems has 9 sets of credentials to revoke when a dispatcher quits, and 9 administrator screens where somebody could already hold access you never granted. Running the operation on a single platform reduces the number of doors, which makes it possible to finish item 1.
The Bottom Line
You cannot buy your way past cyber-enabled cargo theft, and you do not need to. The 7 items are a month of attention, most of it free, and they stop the theft at the point where it actually starts.
Run item 2 today. It costs an afternoon, and a rule you did not write — quietly copying your email to an address you do not recognize — means somebody is already inside.
Talk to EKA about the operational side of this and get real security help for the rest.
This article is general information about business risk, not security, legal, or insurance advice. If you believe you have been targeted, file a complaint with the FBI’s Internet Crime Complaint Center at ic3.gov and contact your local FBI field office in addition to reporting stolen cargo to local police.




