Trucking & Logistics

Someone Else's Trucks Can Wreck Your FMCSA Record. Here's How to Catch It Early.

Unfamiliar inspections on your FMCSA record? Learn the warning signs of carrier identity theft, what to document, and how to request a DataQs review.

An unfamiliar inspection report may be a data error—or a warning that someone is using your carrier's identity. Compare new records with your own trucks, drivers, and dispatch activity before a discrepancy becomes harder to explain.

An unverified story with a useful warning

In a freight-industry forum post supplied for this article, a carrier described four failed roadside inspections and more than 50 driver and vehicle violations appearing on its record within about three weeks. The author said none of the inspected trucks belonged to the company.

According to that account, another operation recruited owner-operators whose trucks carried the legitimate carrier's name, supported by allegedly false lease agreements and insurance certificates. The author said an inspection office emailed a report, allowing the carrier to contact the inspector while the driver was still on scene.

This account has not been independently verified. It is not a confirmed enforcement case, and it does not establish that any email or FMCSA account was compromised. Its practical lesson is narrower: a carrier should investigate inspection records and verification requests it cannot reconcile with its own operation.

Why fraudsters want your name

Carrier identity theft is not limited to stealing a load or redirecting an invoice. A legitimate company name and USDOT number can also make an unauthorized operation appear established. That can create questions about trucks, drivers, insurance, and safety records the real carrier never expected.

FMCSA uses safety data in its Compliance, Safety, Accountability program, including the Safety Measurement System (SMS). Incorrectly attributed inspections can affect how your operation is represented in those records and create questions from business partners. An inspection you do not recognize is a reason to check—not proof of identity theft.

Brokers, shippers, and insurers may use carrier records in their own decisions. Do not assume a particular commercial or insurance consequence; document the discrepancy and discuss its actual impact with the relevant partner or your transportation attorney.

The warning signs

Investigate these signals rather than assuming each one means fraud:

  • Inspections or crashes you cannot match to your equipment, drivers, leased operations, or dispatch logs.
  • Calls or emails from inspectors, brokers, shippers, or insurers about trucks, drivers, or loads you do not recognize.
  • Questions about an owner-operator or lease-on program your company does not run.
  • Insurance verification requests for units you do not recognize or insure.
  • Changes to your FMCSA phone number, email address, or other contact details that nobody authorized.

Five habits that catch it early

Assign responsibility to a named person and keep a backup contact. A routine review is more useful than assuming someone else is watching the record.

  1. Check your safety record on a schedule. A weekly review is a practical starting point: compare new SAFER and SMS information with your equipment list, driver roster, leases, and dispatch records. If you use a carrier-record monitoring provider, confirm exactly which events it covers.
  2. Keep official contacts current. Use a company-controlled address monitored by the right staff, with a clear handoff when someone leaves. Confirm that the phone number and email recorded with FMCSA still reach your business.
  3. Protect FMCSA and related account access. Know who controls the registration login and recovery methods, use MFA where supported, and remove former-user access. Reach Motus and other portals from verified bookmarks or official FMCSA pages—not unexpected message links.
  4. Agree on insurance verification with your agent. Ask how unfamiliar certificate requests or units will be flagged. Verify a certificate through an independently obtained insurer or agent contact, rather than relying only on the document or its printed phone number.
  5. Publish a reliable verification path. Keep your official phone number and email domain visible on your website. Verify changes to those details through an established channel. Configure SPF, DKIM, and DMARC appropriately, while recognizing that email authentication does not validate a truck, lease, or carrier identity.

If it happens to you

Act promptly, but distinguish an unfamiliar record from confirmed identity misuse. A truck you do not own may still have been operating under your authority through a legitimate lease; reconcile the facts before disputing the carrier assignment.

This is operational guidance, not legal advice. A DataQs request is a request for review, not a guarantee that a record will be removed.

  1. Preserve the inspection or crash report, dates, locations, messages, and any relevant documents. Gather your equipment list, driver roster, lease records, ELD and dispatch records, and insurance schedule to explain the discrepancy.
  2. Contact the inspecting agency through independently verified details. If the inspection is recent or still underway, explain what you know and ask how to provide supporting records. Do not confront the driver or attempt to seize equipment yourself.
  3. Submit a Request for Data Review through DataQs for each incorrect record. Use the applicable wrong-carrier or wrong-driver category and attach specific supporting evidence. Requests are routed to the appropriate reviewing office; retain the case number and follow its requests for information.
  4. Report suspected identity fraud through FMCSA's complaint channels. Where appropriate, contact local law enforcement and report internet-enabled fraud to the FBI's IC3. Keep the fraud reports separate from the DataQs request to correct safety data.
  5. Notify your insurer and affected brokers or shippers with a factual summary. Share relevant case references through an appropriate channel without claiming the dispute is resolved before a decision is made.
  6. Consult a transportation attorney if the records affect your authority, contracts, insurance, or other legal obligations.

What cybersecurity can—and cannot—check

Paint, decals, and false paperwork do not require access to your IT systems. But your company email, account recovery methods, and official contact details influence whether the right person receives a warning and can respond.

A free Zero-Access Exposure Review examines public domain and email-authentication signals, including potential lookalike domains. It cannot inspect private accounts, monitor your FMCSA inspection record, validate a lease or insurance certificate, or prove fraud, exploitability, or compromise.

The $1,995 Business Security Baseline verifies agreed internal safeguards for businesses with up to 25 employees; larger teams receive a confirmed quote. Checks for Microsoft 365 protections, account access, and recovery evidence require authorization and an agreed scope. This is business IT work—not carrier vetting, a DataQs dispute service, or a DOT compliance audit.

If you run a brokerage, keep your own email and account safeguards separate from the carrier-selection decisions made by your team or vetting platform.

Frequently asked questions

Can an inspection from a truck I do not own appear on my record?

A truck may legitimately operate under your authority even if you do not own it, so check lease and operating records first. If an inspection is assigned to the wrong carrier or driver, DataQs provides a review category for that discrepancy. An unfamiliar truck alone does not prove identity theft.

Should I wait for a disputed inspection to age out?

No. Review the record promptly, preserve evidence, and request a correction if the carrier assignment or other information is wrong. Do not assume that waiting resolves the data issue or questions raised by business partners.

How do I challenge an inspection that is not ours?

Submit a Request for Data Review in DataQs, choose the applicable wrong-carrier or wrong-driver category, and attach evidence explaining the discrepancy. The request is routed to the appropriate reviewing office. Keep the case number, follow up through the system, and do not assume approval is automatic.

Is carrier identity misuse necessarily a cybersecurity incident?

No. Someone can copy a carrier's public details or use false documents without accessing its systems. Email and registration-account safeguards still matter, but unauthorized access requires evidence; a public record or lookalike domain does not prove compromise.

Does the free exposure review monitor my FMCSA safety record?

No. It reviews public business exposure signals around domains, email, websites, and internet-facing services. FMCSA safety-record monitoring, carrier vetting, DataQs requests, and legal advice are outside that service's scope.

Sources

The opening account is unverified. The official resources below explain safety-data review, reporting, and account access; they do not corroborate the forum story or establish what happened to a particular carrier.

Review your company's public email and domain signals

Start with the free Zero-Access Exposure Review for publicly observable email-authentication and potential lookalike-domain signals. No passwords or internal access. It does not establish identity theft, inspect private accounts, or monitor FMCSA safety data; agreed internal safeguard verification belongs to the Business Security Baseline.

Start the free Zero-Access Exposure ReviewCybersecurity for trucking and logistics