All resources
★ Field Report · 14 · Cybersecurity

The wire that never arrived: ACH-redirect and BEC fraud against brokerages and factoring desks

Business Email Compromise drove 73% of reported cyber incidents in 2024. Here's how ACH-redirect fraud hits freight brokerages and factoring desks — and how to stop it.

Trucky × We Secure·June 16, 2026·7 min read

Business Email Compromise drove 73% of reported cyber incidents in 2024. Here's how ACH-redirect fraud hits freight brokerages and factoring desks — and how to stop it before the money moves.

When the attacker wants money instead of freight, the weapon is Business Email Compromise (BEC). There's no malware fireworks — just a quiet takeover of an inbox, a few weeks of reading how your payments work, and then a single, perfectly-timed email that reroutes a payment to the attacker's account. By the time anyone chases the overdue invoice, the ACH has cleared and the money is unrecoverable.

Why this is the dominant financial threat now

BEC accounted for 73% of reported cyber incidents in 2024, up sharply from 44% the year before, and the FBI estimates cumulative BEC losses at roughly $55 billion over the past decade. In broader payments-fraud research, 79% of organizations faced payment-fraud attempts in a single year, with third-party and vendor impersonation the leading tactics. For freight, that lands squarely on brokerages and factoring desks, where multi-party payment flows create exactly the seams attackers exploit.

The anatomy of an ACH-redirect hit

  • Access. The attacker phishes a broker, carrier or factoring inbox — or buys the credentials.
  • Reconnaissance. They watch silently: who pays whom, on what cycle, in what tone. They often set a hidden inbox rule so the real owner never sees the relevant threads.
  • The pivot. Posing as a known vendor, carrier or factoring company, they send "updated" banking details for an invoice that's genuinely outstanding.
  • The payout. The payment lands in a mule account and is moved out within hours.
  • The discovery. Days or weeks later, the legitimate party asks where their money is. Now it's a dispute and a loss, not a recovery.

Why factoring desks are a favorite target

Factoring already involves a third party standing between carrier and broker, plus a steady rhythm of invoices and remittances. That complexity is cover. A fraudster who establishes a little credibility — paying a few loads cleanly first — can then manipulate the process: false dispute, "changed" remit-to details, fake documentation. The more hands a payment passes through, the easier it is to slip a fraudulent instruction into the chain unnoticed.

The tell is almost always a payment-detail change delivered by email under time pressure. Treat every "our bank account has changed" message as guilty until verified by a phone call to a number you already had.

How to actually stop it

Two layers do the heavy lifting. First, email security and identity protection that keeps inboxes from being compromised in the first place and flags suspicious inbox-rule changes. Second, payment-fraud monitoring tuned to the freight payment flow — watching for new banking instructions, anomalous payment requests and the behavioral fingerprints of an account takeover — paired with a hard process rule: any change to payment details triggers a verified call-back before money moves. Technology plus a mandatory pause beats either one alone.

Want your brokerage or factoring desk stress-tested against ACH-redirect fraud? Book a free exposure check — no pitch, 72-hour reply.

★ Want this implemented for your fleet?

Book a 30-minute strategy call.

Walk away with a plan — even if we never work together.

Book a call