Trucking & Logistics

You Just Found Out a Load Was Double Brokered. Here's What to Do in the First 24 Hours.

Found out a load was double brokered? A plain-English checklist for freight brokers: locate the freight, hold payment, preserve evidence, and report it.

A driver you do not recognize asks who is paying. The truck at the dock does not match the carrier on your rate confirmation. Or the booked carrier stops answering. Here is what to do, in order, during the first day.

First, what double brokering is

Double brokering happens when the carrier booked for a load, or someone pretending to be that carrier, transfers the load to another carrier without the broker’s authorization. The fraudster may try to collect payment while the carrier that hauled the freight is left unpaid.

That is different from co-brokering: a disclosed arrangement between licensed brokers. A suspected double-brokered load may also involve identity theft. For example, someone may use a legitimate carrier’s USDOT or MC details with a lookalike email address to book freight. Do not assume the real carrier or broker was involved; verify the facts independently.

This is not legal advice. Responsibility for payment and other legal obligations depends on the facts and applicable agreements. Contact your transportation attorney and insurer early.

Hour 0–1: Find the freight

Your first priority is the cargo and its location—not sorting out the paperwork. Keep communications factual and use contact information already held in trusted records.

  • Call the driver who has the load. Record the driver’s name, company, USDOT number, truck and trailer numbers, and current location.
  • Call the shipper and receiver. Confirm what was picked up, by whom, and whether the delivery appointment still stands.
  • Call the carrier you booked using the phone number in its FMCSA record, such as the number listed through SAFER. Do not rely on a number supplied only in the disputed email or rate confirmation. If the real carrier says it never booked the load, identity theft may be involved.
  • If the freight may be at risk of theft, contact local law enforcement where it was last known to be.

Hour 1–2: Stop the money

Once you suspect double brokering, assume a payment could reach the wrong party until the destination is independently verified.

  1. If a wire has already gone out, call your bank’s fraud line immediately and request a wire recall.
  2. File a report with the FBI’s Internet Crime Complaint Center at ic3.gov.
  3. Ask your bank whether the FBI’s Financial Fraud Kill Chain applies. The program is limited to qualifying international wires of at least $50,000, with a SWIFT recall started, reported within 72 hours.
  • Place a hold on payment for the load in your transportation management system (TMS) and with accounting.
  • Check for recent remit-to or factoring changes, including a new notice of assignment (NOA).
  • Tell quick-pay or factoring contacts not to release funds for the disputed load.

Hour 2–4: Save the evidence

Preserve records in their original form. Do not delete messages or let anyone clean up a mailbox before relevant evidence is saved. Keep a dated timeline of what happened and who took each action.

  • The rate confirmation, signed carrier agreement, and bill of lading.
  • The full email thread, including original email headers—not only screenshots.
  • Call logs, phone numbers used, load-board postings, and messages exchanged on the platform.
  • Tracking and ELD data, check-call notes, pickup and delivery records, and the carrier-onboarding packet.
  • A dated copy or screenshot of the carrier’s FMCSA record as it appears now; records can change later.

Hour 4–8: Check whether your own systems were used

A double-brokering incident does not by itself prove that your systems were compromised. Still, check for signs that someone impersonated your brokerage or accessed an employee’s account.

  • Look for reports that carriers or shippers received messages from a domain resembling yours, such as one with an extra letter or a different ending. If you find a likely lookalike, warn affected partners and give them a known phone number for verification.
  • Ask your IT provider to review the relevant mailbox for unfamiliar forwarding or inbox rules, unexpected sign-ins, and sent messages the employee does not recognize.
  • If access may be compromised, reset the account password, revoke active sessions, and confirm multifactor authentication (MFA) is enabled. Review load-board, TMS, factoring, and payment-portal accounts used by the employee as well.

Hour 8–24: Notify and report

Notify the shipper and insurer promptly and follow your incident procedures. Be clear about what is confirmed and what is still being investigated. If a real carrier’s identity was used, consider notifying that carrier; it may be hearing from other affected parties.

  • Report suspected transportation fraud to FMCSA through the National Consumer Complaint Database and contact center.
  • Report suspected wire fraud or other internet-enabled crime to the FBI’s IC3.
  • Consider reporting to local law enforcement and your state attorney general, as appropriate.
  • Notify the load board and relevant carrier-vetting service or industry network so they can review the account or activity.

After the first day

The carrier that actually hauled the freight may ask to be paid. Before paying anyone—especially if it could mean paying twice—discuss the facts and your contractual obligations with your transportation attorney and insurer.

Write down the incident timeline, the warning signs, and where existing checks did or did not work. Use the review to improve procedures and training, not to assume that a single technical change would have prevented the incident.

How to make the next one less likely

No single safeguard prevents every fraud attempt. Consider these practical checks across carrier verification, payment approval, email, and account access:

  1. Call back using official, independently obtained numbers. Do not treat the number in an incoming message as proof of identity.
  2. Re-check carrier details when a name, phone number, email, address, ownership, or other important record changes.
  3. Require a callback to a number already on file before approving a remit-to, factoring, or payment change. Document who verified and approved the update.
  4. Protect your company’s domain with properly configured SPF, DKIM, and DMARC, and monitor for confusingly similar domains. Email authentication helps but does not rule out a compromised legitimate mailbox.
  5. Use MFA on the mailboxes and business platforms involved in booking freight and processing payments. Review access and inbox rules, use individual accounts where available, and remove access promptly when roles change.

Frequently asked questions

Is double brokering illegal?

Unauthorized re-brokering can violate federal requirements, and conduct involving fraud may raise additional legal issues. The facts matter; disclosed co-brokering between licensed brokers is different. Consult a transportation attorney about a specific load.

How fast should I act if I already paid by wire?

Call your bank’s fraud line immediately to request a wire recall, then report the incident to the FBI at ic3.gov. The Financial Fraud Kill Chain applies only to qualifying international wires of at least $50,000, with a SWIFT recall initiated and a report made within 72 hours; ask your bank about eligibility.

Where can I report suspected double brokering?

FMCSA accepts complaints through its National Consumer Complaint Database and Contact Center. You can also report internet-enabled fraud to the FBI’s IC3, and contact local law enforcement, your state attorney general, and the relevant load board as appropriate.

Will insurance cover a double-brokered load?

Coverage depends on the policy, facts, and applicable exclusions or conditions. Notify your insurer promptly and ask about its reporting requirements; this article cannot determine whether a particular loss is covered.

Could our email have been part of the problem?

Possibly, but the incident alone does not establish mailbox access or compromise. Review suspicious sign-ins, forwarding rules, and sent messages with your IT provider, and investigate lookalike domains. Preserve evidence before making changes where practical.

Sources

Use these official resources for reporting and general guidance. They do not replace legal advice, your insurer’s instructions, or your organization’s incident-response procedures.

Review cybersecurity and fraud prevention for your brokerage

The freight broker services page explains how the free Zero-Access Exposure Review checks public signals, and how the authorized Business Security Baseline verifies agreed internal safeguards. Neither is emergency incident response, legal advice, carrier vetting, or an FMCSA compliance audit.

Explore freight broker servicesStart the free Zero-Access Exposure Review