The broker-impersonation email playbook draining US carriers in 2026
Lookalike domains, spoofed rate cons and re-brokered loads. Here's the broker-impersonation email playbook hitting US carriers in 2026 — with a red-flag checklist.
Lookalike domains, spoofed rate cons and re-brokered loads. Here's the broker-impersonation email playbook hitting US carriers in 2026 — with a red-flag checklist you can hand your dispatch desk.
Double brokering — a load illegally re-brokered to a carrier who then never gets paid — is the fraud that keeps brokers awake. In Truckstop's 2025 survey, 86% of brokers who had experienced fraud named it their single biggest threat, and complaints have risen as much as 400% since 2022. The Transportation Intermediaries Association recorded a 65% surge in freight-fraud reports between September 2024 and February 2025. Almost all of it is delivered the same way: email.
How the play works
The mechanics are consistent. An attacker either spoofs a legitimate broker's domain or takes over a real broker inbox through phishing. From that trusted-looking address, they send a rate confirmation for a real load — then re-broker it to an unsuspecting carrier, collect the broker's payment, and vanish before the carrier that hauled it ever sees a dime. The FBI's April 2026 advisory describes the cyber-enabled version step by step: compromise the account, flood load boards with fraudulent listings, bid on real freight under a hijacked identity, then alter the bill of lading and delivery address.
The volume is staggering. In a single quarter of 2025, fraud-prevention platform Highway blocked over 352,000 fraudulent inbound emails, 30,900 spoofed calls and 400,000 fraud attempts — overwhelmingly impersonation or stolen-credential attacks.
The five red flags your dispatch desk should know
- ★The domain is one character off. `@logistixbroker.com` vs `@logisticbroker.com`. Train your team to read the full sender address, not the display name.
- ★A "new" rate con arrives from a free email (Gmail, Yahoo) for a broker you normally deal with on a corporate domain.
- ★The contact info doesn't match FMCSA records. A phone number or email that differs from the broker's registered details is a takeover tell.
- ★Urgency plus a banking or routing change. "Send the BOL to this new address" or "our remit-to has changed" — especially late Friday.
- ★Pressure to skip verification. Real partners tolerate a verification call. Fraudsters resist it.
Why "just train people" isn't enough
Awareness helps, but a tired dispatcher at 5 p.m. will miss a one-letter domain swap — that's the entire business model. Layered email security does what humans can't do reliably: it authenticates sender domains (SPF/DKIM/DMARC), detects lookalike and newly registered domains, and quarantines the spoofed broker message before it reaches the inbox. The goal is that the dangerous email never gets the chance to fool a person.
The fraud isn't sophisticated code. It's a believable email at a busy moment. Your defense has to inspect the message before your team has to judge it.
What it costs to get this wrong
Between 2022 and 2025, bad-broker and double-brokering schemes drained an estimated $4 billion from the freight industry, part of more than $10 billion in total losses, and the FMCSA revoked over 15,000 broker authorities in the period. For a single carrier, one re-brokered load can mean an unpaid invoice in the tens of thousands — and a load that may be uninsured, because the party that actually hauled it isn't on any policy.
Want your broker and dispatch email pressure-tested against this playbook? Book a free exposure check — no pitch, 72-hour reply.
Book a 30-minute strategy call.
Walk away with a plan — even if we never work together.
Book a call →
