In this article:
- How cyber-enabled cargo theft works
- The verification controls small carriers should use
- What to do when a load, account, or carrier identity may be compromised
Cargo theft can start with an email
Cargo theft does not always begin with a cut seal, an unsecured trailer, or a driver followed from a warehouse. It can start with a convincing email, a fake carrier packet, a stolen load-board password, or a request to install software to view shipment documents.
A criminal may never need to touch a truck. If they take over an email, dispatch, load-board, or FMCSA account, they can make a fraudulent instruction look routine. That is the risk small carriers need to plan for.
What is cyber-enabled cargo theft?
Cyber-enabled cargo theft uses digital deception or unauthorized system access to facilitate the theft or diversion of physical freight. It connects cyber risk, such as phishing, stolen passwords, fake websites, and remote access, with freight risk, such as fictitious pickup, double brokering, payment diversion, and shipment misdirection.
Locks and GPS remain necessary, but they do not stop an employee from responding to a fake load or a driver from following a fraudulent destination change.
How a scam turns into a stolen load
A criminal starts with a believable reason to act, such as a carrier packet, rate confirmation, billing notice, or account-verification request. A link captures a password or an attachment installs remote-access software. The criminal can then use a real company identity to post loads, change contact details, or continue an existing email thread.
A legitimate carrier or driver may move the freight without knowing the transaction was fraudulent. The business may not find out until a broker asks about an unauthorized load, a factoring company flags a payment dispute, or a customer reports that the freight never arrived.
- Load-board phishing and account takeover
- Carrier and broker identity theft
- Fake FMCSA and USDOT notices
- Double brokering and fictitious pickups
- Payment, factoring, fuel-card, and operating-account diversion
Start with these controls
These controls are a good place to start. They address the common ways a digital compromise becomes a physical or financial loss.
- Turn on multi-factor authentication for email, load boards, TMS, factoring, banking, cloud storage, and government accounts.
- Require a callback to a known, independently sourced number before accepting an unexpected pickup, delivery, contact, or payment change.
- Never open an executable file or install remote-access software from a carrier packet, rate confirmation, or shipment link.
- Give each employee an individual account and remove former employees and unused vendor access promptly.
- Check public FMCSA and SAFER information for unauthorized changes and keep listed contact details accurate.
- Document who can approve loads, destination changes, payment changes, and new software.
- Write down whom to call if an account, payment, carrier identity, or load appears compromised.
Verify anything that changes the load or payment
An email is a request, not proof, when it changes where freight or money will go. Use a separate source to verify the instruction. Call a number already stored in your system, published on an established website, or listed in an official FMCSA record. Do not call a number supplied only in the suspicious message.
Use this callback process for new brokers or carriers, last-minute pickup or delivery changes, driver or equipment substitutions, new bank or factoring instructions, credential requests, and unfamiliar software or login links.
- Compare the legal name, USDOT or MC number, status, and business details in official FMCSA sources.
- Confirm the broker, carrier, insurance, domain, rate, cargo, lane, pickup, delivery, and payment details through independent channels.
- Escalate any conflict between the rate confirmation, bill of lading, messages, or public records before the truck moves.
- Treat an unexpected installer, shortened link, lookalike domain, or pressure to skip a callback as a serious warning sign.
Protect your carrier identity and dispatch devices
Carrier vetting is only half of the problem. A small fleet also needs to know whether someone is pretending to be it. Review FMCSA and SAFER information regularly, restrict access to FMCSA, Login.gov, load-board, and insurance accounts, and protect the company domain with SPF, DKIM, and an appropriately configured DMARC policy.
Apply updates promptly, use managed endpoint protection, encrypt laptops and phones, enable automatic screen locking, separate administrator accounts, back up critical documents, and test recovery. Remove former employees and vendors from every system, not only email.
Do not separate cyber and cargo security
Cybersecurity does not replace physical cargo protection. Use route planning, approved parking, seals, locks, lighting, telematics, geofencing, and driver check-in procedures appropriate to the load.
These controls need to work together when digital instructions change physical activity. Decide who responds to a geofence alert, require callbacks to independently verified numbers, and document seal numbers. For high-value or easily resold cargo, define extra controls before pickup.
If you think something went wrong
Speed matters, but preserving evidence matters too. Keep a written response card available even if email or the TMS is unavailable.
- Call the driver, shipper, pickup facility, receiver, and legitimate broker through known numbers. Stop release, pickup, transfer, or delivery when it can be done safely and lawfully.
- Disconnect a suspected computer from the network without wiping it. From a known-clean device, reset affected passwords, revoke active sessions, and remove unauthorized forwarding rules, users, and integrations.
- Preserve emails, headers, text messages, call logs, screenshots, files, login history, and system alerts.
- Notify the load board, legitimate business partners, insurer, cargo insurer, factoring company, bank, and FMCSA when applicable.
- Report active theft to local law enforcement and cyber-enabled fraud to the FBI Internet Crime Complaint Center. Do not confront suspected criminals.
A 30-day plan for a small fleet
Close the easiest gaps first, then test the process with your team. Keep the result to a short list of changes with an owner and a deadline.
- Days 1–3: enable MFA, reset reused passwords, remove unused accounts, save official contacts, and ban software installers from freight documents.
- Week 1: review administrators, mailbox forwarding, remote-access tools, sign-in logs, public FMCSA information, endpoint protection, patching, backups, and vendor access.
- Week 2: publish the pre-load verification check, define approval roles, and establish an out-of-band process for urgent changes.
- Weeks 3–4: walk through a fake broker email, test an unavailable dispatcher account, test a destination-change callback, and confirm that backups restore critical operating information.
What an independent review can add
Many small trucking companies already have an IT provider. An independent review can answer a straightforward question: are the safeguards the operation depends on configured and working? It can verify evidence for email authentication, MFA, administrators, sign-in protections, mailbox rules, endpoint protection, patching, backups, logging, and incident readiness.
The free Business Exposure Review examines public signals around your business email, domains, website, and internet-facing services without logging into your TMS, load boards, or internal systems. The $1,995 Business Security Baseline verifies internal safeguards for businesses with up to 25 employees. It does not connect to trucks, certify DOT compliance, or replace cargo-security and transportation-safety procedures.
Need an evidence-backed starting point?
The free Exposure Review shows what is publicly observable. The Business Security Baseline verifies the essential controls protecting the business.