Trucking & Logistics

That FMCSA Update Email May Be Fake: Spotting Bogus Motus Portals

FMCSA warns of fake Motus portals targeting motor carriers. Learn how to spot the phishing emails, protect compliance accounts, and respond.

In this article:

  • Which fake Motus portal domains FMCSA identified
  • Why compliance-update emails can fool a busy transportation company
  • What motor carriers should do if someone clicked or entered credentials

Check the link before anyone signs in

An email asks your company to update a registration profile. It looks official, sounds urgent and points to a government-style portal.

FMCSA is warning that scammers are impersonating its Motus application. Motor carriers have received emails with the subject “Notice of Required Off-Cycle Update- Motus email” directing them to a fake “New MOTUS Portal.”

The fake websites to watch for

FMCSA identifies these fraudulent addresses. They are shown here with brackets to prevent accidental clicks:

  • dot[.]motusdatasboard[.]com
  • dot[.]motusdatadesk[.]com
  • dot[.]motuswebdeck[.]com
  • dot[.]motusfunction[.]com

Use the real Motus site

The legitimate application is motus.dot.gov. Open it from a trusted bookmark or type the address into your browser.

The FMCSA alert documents impersonation attempts. It does not report confirmed account compromises, cargo losses or malware from this campaign.

Why this can fool a transportation company

The request fits real work. Someone handling registration, compliance or company updates may see a task that appears routine.

The key lesson: “dot” at the beginning of a website address does not make it a government website. In dot[.]motusdatadesk[.]com, the domain is motusdatadesk.com.

What your company should do now

Treat unexpected compliance-update emails as requests to verify, not instructions to obey.

  • Open Motus independently using a trusted bookmark or by typing motus.dot.gov into the browser.
  • Verify unexpected requests with your compliance provider or FMCSA using contact details you already trust.
  • Alert your IT provider and ask them to search email logs for the listed domains and subject line.
  • Block the malicious domains in email, DNS or web-filtering tools where available.
  • Tell staff who to contact before acting on a suspicious notice.

If someone entered credentials

Involve your IT provider immediately. Reset affected passwords through the legitimate service, revoke active sessions where supported, review recovery settings and check the carrier profile for unauthorized changes.

Preserve the original email, including headers if possible. Report the attempt through the FMCSA Contact Center and FBI IC3.

Would your team recognize a fake compliance notice?

Securing Your Business helps small and midsize transportation companies strengthen their response to phishing. Managed Phishing Testing & Staff Training can use trucking-specific scenarios so employees practice pausing before they click.

The Business Security Baseline reviews safeguards that matter after a suspicious login attempt, including mailbox access, authentication and account recovery.

Contact Securing Your Business to discuss protecting the people and accounts that keep your operation moving.

Related resources

Sources

Need an evidence-backed starting point?

The free Exposure Review shows what is publicly observable. The Business Security Baseline verifies the essential controls protecting the business.