A legitimate company name doesn't prove a freight request is legitimate. Use these 10 checks before you accept a load, open an account link, or send money.
Why trucking scam prevention now includes account security
The company is real. The MC number checks out. The email mentions the right load. You can still be talking to a scammer.
Freight fraud usually works by borrowing something real – a carrier's identity, a broker's reputation, an ongoing email thread, or a stolen load-board login. A busy dispatcher or owner-operator can finish the usual paperwork and still miss the person actually behind the request.
An FBI alert from April 2026 described cargo-theft schemes that start with a fake freight message, move to remote access on the victim's computer, and end with fraudulent load postings and diverted cargo. That changes what an ordinary carrier agreement or account-verification email might mean – it could be the first step toward someone operating under your company's name. The checks below are about fraud and account security, and they work alongside your driving, vehicle, and cargo-safety procedures, not instead of them.
1. Verify the person, not just the company name
Look up the business independently before you accept a new relationship. Match its legal name and identifiers to official records, then confirm that whoever is emailing you actually represents it.
FMCSA recommends checking contact numbers in SAFER and calling the listed number when it differs from the one you were given, and it warns that search results can include fake business profiles. Save verified contacts in your own records, and require a second check before dispatch approves a load from a new contact or an unexplained number change. A matching company record proves the business exists – it doesn't prove who's writing to you.
2. Slow down on rates that look too good
A rate that looks unusually attractive deserves more questions, especially when it's paired with pressure to commit immediately.
Review who's contracting with you, who pays, the pickup and delivery locations, payment terms, and any deductions, and check available broker payment history and credit information. Make dispatch explain any mismatch between the load posting, rate confirmation, and agreement before approving it. A good credit score addresses payment risk – it doesn't prove the person sending the agreement controls the named company.
3. Log into freight platforms through a route you already trust
Treat an unexpected request to verify billing, restore an account, complete onboarding, or fix a registration problem as a reason to check independently, not a reason to click through.
FMCSA's fraud-alert page documents fake audit requests, carrier-profile notices, and lookalike government portals – a familiar logo or an official-sounding deadline doesn't make a link trustworthy. Give staff a shared list of approved login bookmarks and support contacts, and have them open the platform directly to confirm any request there. If a broker uses an onboarding system you don't recognize, verify it with the broker through an established contact before uploading documents.
4. Stop when a document asks you to install anything
A carrier packet or rate confirmation shouldn't turn into a software install. In the FBI's April 2026 warning, malicious downloads installed remote-management tools that gave attackers access to victims' systems.
Require sign-off from your IT contact before anyone installs a document viewer, browser extension, remote-support tool, or “security update” requested during a freight transaction, and never follow emailed instructions to disable endpoint protection or paste commands into a computer. If a genuine partner needs specialized software, confirm the product and its source separately – urgency isn't a substitute for that check.
5. Keep email and load-board passwords separate
Email connects the rest of your business – password resets, invoices, customer conversations, account recovery. Reusing its password on a freight platform means one stolen login can reach much further.
Use unique passwords stored in a password manager, and turn on multifactor authentication everywhere it's supported – CISA recommends phishing-resistant options like security keys or passkeys where you can get them. Review email, load-board, dispatch, and administrator accounts together: who owns each one, which MFA method it uses, and who controls recovery. Individual logins mean removing a departing dispatcher doesn't depend on guessing who else knows a shared password.
6. Verify payment changes outside the email thread
An invoice number and an ongoing conversation can make fraudulent bank details sound convincing. A compromised mailbox can let an attacker step into a transaction that's otherwise completely real.
Require a callback to a previously verified number before changing bank details, factoring instructions, or the payment recipient, and record who confirmed the change and who approved it. Use a second approver where staffing allows; if you're a one-person operation, the independent callback and the written record are what protect you. Replying “are these details correct?” in the same thread doesn't count as an independent check.
7. Match the truck at the dock to the carrier you actually hired
Verification has to reach the loading dock. A valid carrier packet doesn't prove the truck that shows up is the one you contracted.
FMCSA advises matching the truck's name and numbers to the contracted carrier and recording vehicle information. Agree with the shipper on the expected driver and equipment before arrival, define who can approve a substitution, and hold the load if the details don't match until it's resolved. Record the handoff at a cross-dock too. Give drivers the same instruction: call dispatch if anyone asks them to hide who they work for or use a different carrier name.
8. Require separate approval for delivery changes
A believable explanation can still send a legitimate driver to the wrong place. A last-minute warehouse change, cross-dock instruction, or request to hand freight to another truck should trigger an approval process you already have in place – not one you invent on the spot.
Name an after-hours contact who can verify changes with the original authorized party, and record the approved destination, who authorized it, and when. The driver should get confirmation through your established dispatch channel before acting, especially while someone is pressuring them to turn off the planned route.
9. Verify fuel advances and keep the shipment record together
Truckstop describes fuel-advance fraud built around impersonated carriers and fabricated pickup paperwork. A photo of a bill of lading is evidence to check, not automatic authorization to release funds.
Before issuing an advance, reconcile the request against the approved carrier, agreed terms, and an independently confirmed pickup, and escalate any mismatched name or new payment destination. Keep the rate confirmation, pickup and delivery records, approved changes, and payment instructions together under the load number, and restrict who can access them. A consistent record helps your team catch contradictions and gives investigators something usable if a transaction goes wrong.
10. Practice the stop-and-report decision before you need it
An employee who suspects a scam needs to know who to call and whether they're allowed to pause the transaction. Working that out during a live incident costs time you don't have.
Run a short exercise with dispatch and billing: a familiar broker emails new payment instructions while a driver gets a new delivery address – who pauses each action, who verifies it, and who covers after hours? If you suspect fraud, preserve the original messages, account details, load number, and handoff timeline. Contact your bank immediately if money moved, report online fraud to IC3, and call local law enforcement for suspected cargo theft. Tell the load board and report broker or carrier identity fraud to FMCSA where applicable. Don't confront anyone you suspect of being involved.
Check the accounts behind your freight operation
Every precaution above depends on the accounts your staff use to carry it out. If you don't know whether email access, MFA, forwarding rules, and administrator protections are actually working, that's worth finding out before a scam tests it for you.
The free Zero-Access Exposure Review looks at public signals – your domains, email authentication, and internet-facing services – without logging into anything internal. The $1,995 Business Security Baseline goes further and verifies internal safeguards like MFA, mailbox rules, and admin access against real evidence, for businesses with up to 25 employees. Ask about scoping either one around the accounts your dispatch and billing teams depend on every day.
Which of these should a small carrier tackle first?
Start with whichever decision would expose the most of your business if you got it wrong today. Name an owner for each action and keep evidence it was done – “we normally do that” is hard to rely on during a rushed pickup or a billing problem at six in the evening.
| Check | Evidence to request | Suggested owner |
|---|---|---|
| Independent callback for payment changes | A written rule requiring a callback to a previously verified number before any bank, factoring, or payment change | Billing lead |
| Identity verification for new partners | A named person responsible for confirming carrier or broker identity before the first load | Office manager or dispatch lead |
| Approval for pickup and delivery changes | A documented process defining who can approve a destination or equipment change | Dispatch lead |
| MFA and account recovery | Confirmation that dispatch and billing accounts use MFA and have a named recovery contact | IT provider or administrator |
Related resources
Give your team a way to stop a scam before it costs you
Most of these checks come down to one habit: verify before you act. Managed phishing testing and short follow-up training can be scoped around the account-verification and payment-change decisions your dispatch and billing staff face every week.
