In this article:
- Which fake Motus portal domains FMCSA identified
- Why compliance-update emails can fool a busy transportation company
- What motor carriers should do if someone clicked or entered credentials
Check the link before anyone signs in
An email asks your company to update a registration profile. It looks official, sounds urgent and points to a government-style portal.
FMCSA is warning that scammers are impersonating its Motus application. Motor carriers have received emails with the subject “Notice of Required Off-Cycle Update- Motus email” directing them to a fake “New MOTUS Portal.”
The fake websites to watch for
FMCSA identifies these fraudulent addresses. They are shown here with brackets to prevent accidental clicks:
- dot[.]motusdatasboard[.]com
- dot[.]motusdatadesk[.]com
- dot[.]motuswebdeck[.]com
- dot[.]motusfunction[.]com
Use the real Motus site
The legitimate application is motus.dot.gov. Open it from a trusted bookmark or type the address into your browser.
The FMCSA alert documents impersonation attempts. It does not report confirmed account compromises, cargo losses or malware from this campaign.
Why this can fool a transportation company
The request fits real work. Someone handling registration, compliance or company updates may see a task that appears routine.
The key lesson: “dot” at the beginning of a website address does not make it a government website. In dot[.]motusdatadesk[.]com, the domain is motusdatadesk.com.
What your company should do now
Treat unexpected compliance-update emails as requests to verify, not instructions to obey.
- Open Motus independently using a trusted bookmark or by typing motus.dot.gov into the browser.
- Verify unexpected requests with your compliance provider or FMCSA using contact details you already trust.
- Alert your IT provider and ask them to search email logs for the listed domains and subject line.
- Block the malicious domains in email, DNS or web-filtering tools where available.
- Tell staff who to contact before acting on a suspicious notice.
If someone entered credentials
Involve your IT provider immediately. Reset affected passwords through the legitimate service, revoke active sessions where supported, review recovery settings and check the carrier profile for unauthorized changes.
Preserve the original email, including headers if possible. Report the attempt through the FMCSA Contact Center and FBI IC3.
Would your team recognize a fake compliance notice?
Securing Your Business helps small and midsize transportation companies strengthen their response to phishing. Managed Phishing Testing & Staff Training can use trucking-specific scenarios so employees practice pausing before they click.
The Business Security Baseline reviews safeguards that matter after a suspicious login attempt, including mailbox access, authentication and account recovery.
Contact Securing Your Business to discuss protecting the people and accounts that keep your operation moving.
Related resources
Sources
Need an evidence-backed starting point?
The free Exposure Review shows what is publicly observable. The Business Security Baseline verifies the essential controls protecting the business.