Trucky
Book a call β†’
All resources
β˜… FBI Alert Β· 07 Β· Cybersecurity

Cyber-Enabled Cargo Theft: How Hacked Load Board Accounts Are Being Used to Steal Real Freight

The FBI warns of a $725M surge in cyber-enabled cargo theft. Learn how hacked load board accounts and remote access tools are used to steal real freight, and how carriers can protect themselves.

Trucky Γ— We SecureΒ·July 4, 2026Β·8 min read

On April 30, 2026, the FBI issued a public service announcement warning the transportation and logistics industry about a sharp rise in what it calls "cyber-enabled strategic cargo theft." The numbers behind that warning are hard to ignore. Cyber-enabled cargo theft losses in the United States and Canada reached an estimated $725 million in 2025, a 60% jump from the year before. Confirmed incidents rose 18%, and the average value stolen per theft climbed 36% to nearly $274,000, a sign that criminals are getting more selective and going after higher-value loads.

This isn't the same old story of a trailer disappearing from a truck stop. This is a hybrid crime that starts with a phishing email and ends with a truckload of goods vanishing into a resale network.

How the Attack Actually Works

The FBI notes that the broader tactic, compromising brokers or carriers to post fraudulent load board listings, has been active since at least 2024. Proofpoint has tracked one specific cluster within this activity running since at least mid-2025, with some evidence pointing to activity as early as January of that year.

1

The initial compromise

Attackers impersonate brokers through spoofed emails, often referencing a carrier-broker agreement or a complaint about service quality. The email contains a shortened or disguised link. Clicking it leads to a fake website that instead delivers a remote monitoring and management (RMM) tool β€” the kind of software IT departments normally use for remote support. Tools observed in these campaigns include ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, N-able, and LogMeIn Resolve. Because these are legitimate, signed applications, they often slip past antivirus and endpoint detection tools without raising alarms.

2

Posting fake loads

Once inside a broker's or carrier's system, the attackers use the compromised load board account to post fraudulent listings, sometimes tens of thousands at a time. Legitimate carriers see what looks like a normal, attractive load and respond to it.

3

Compromising the responder

When a carrier reaches out about the fake load, the attackers reply with what looks like a standard carrier-broker agreement, but the document again delivers malware. This is how the compromise spreads from the original victim to new carriers who had no idea anything was wrong.

4

Taking over the identity

Posing as the compromised carrier, the criminals bid on and accept real shipments, then double-broker the load to drivers who may not know they're part of a theft. To keep the scheme running, attackers alter the carrier's FMCSA registration details and update insurance information so the account can accept loads it normally wouldn't. Many carriers don't discover they've been compromised until a broker calls asking about a shipment that never arrived.

5

The theft

Loads are cross-docked or transloaded to complicit drivers, often within 24 hours, and the cargo is diverted and resold. In some cases, the criminals contact the broker afterward to demand a ransom for information about the missing load.

Who's Behind It

Independent security researchers at Have I Been Squatted and Ctrl-Alt-Intel separately uncovered a related campaign in February 2026, tracing it to a Russian-speaking cybercrime group with Armenian-speaking operators they dubbed Diesel Vortex. Active from September 2025 until its infrastructure was dismantled in February 2026, the group used 52 phishing domains to steal more than 1,600 login credentials from users of major logistics platforms including DAT Truckstop, Penske Logistics, and Timocom. Proofpoint has separately tracked nearly two dozen related campaigns since August 2025, ranging from small, targeted attempts to mass campaigns sending over a thousand emails at once. Researchers assess with high confidence that these cybercriminal groups are working directly with organized crime networks that handle the physical side of the theft β€” the actual trucks, drivers, and resale channels.

The National Motor Freight Traffic Association has described the link between digital compromise and physical theft as now "unmistakable," noting that attackers are also using deepfake voice calls impersonating dispatchers and GPS spoofing or jamming to hide a vehicle's real location during an active theft.

What Carriers and Brokers Can Actually Do

The good news is that this attack chain has clear points where it can be interrupted. Based on FBI and industry guidance, the most effective steps are:

  • β˜…Enforce multi-factor authentication everywhere it counts. Load board accounts, dispatch platforms, and email systems should all require MFA β€” this single control blocks the credential-based access that starts most campaigns.
  • β˜…Verify shipment requests through a second channel. Never rely solely on contact info in the original message; call the broker or carrier back on a number you already have on file.
  • β˜…Monitor your FMCSA registration for unauthorized changes. Regular checks at safer.fmcsa.dot.gov can catch a compromise early.
  • β˜…Audit carrier credentials before tendering a load. Cross-reference DOT numbers and insurance status independently rather than trusting documents sent by the other party.
  • β˜…Watch for unauthorized RMM software on company machines. AnyDesk, ScreenConnect, and TeamViewer are legitimate β€” which is exactly why they're dangerous when installed without your knowledge.
  • β˜…Report incidents to IC3.gov. The FBI has specifically asked for incident reports to help build a clearer picture of active threat groups like Diesel Vortex.

Why This Matters for Mid-Sized Carriers

Smaller and mid-sized fleets are often assumed to be too small to attract this kind of attention, but that assumption doesn't hold up. Lean back offices, shared or personal email accounts, and overlapping dispatch and billing access all create the kind of gaps attackers look for. And because the entire scheme depends on identity, not size, a compromised mid-sized carrier is just as useful to criminals as a large one β€” sometimes more so, since smaller operations may take longer to notice something is wrong.

This is exactly the kind of threat Threat Intercept Console was built to help carriers get ahead of: identifying exposure in dispatch and load board access, flagging suspicious remote access activity, and giving carriers a clear picture of where they stand before an incident happens rather than after.

Sources

FBI Public Service Announcement (April 30, 2026); Proofpoint Threat Insight research on cargo theft campaigns; National Motor Freight Traffic Association (NMFTA) cybersecurity reporting.

Free exposure check

See what an attacker sees on your fleet tonight.

No pitch. 72-hour reply. We map your real exposure β€” ELD endpoints, broker logins, leaked credentials, GPS anomalies. Visit /threat-console.

β˜… Want this implemented for your fleet?

Book a 30-minute strategy call.

Walk away with a plan β€” even if we never work together.

Book a call β†’