All resources
★ Field Report · 16 · Cybersecurity

Your MC number is for sale: dark-web monitoring for stolen DOT, MC and driver PII

Clean, aged MC numbers sell for tens of thousands on criminal markets. Here's how carrier-identity theft works — and how dark-web monitoring flags it before a load disappears.

Trucky × We Secure·June 16, 2026·7 min read

Clean, aged MC numbers sell for tens of thousands on criminal markets. Here's how carrier-identity theft works — and how dark-web monitoring flags it before a load disappears under your name.

Freight identity theft doesn't look like consumer identity theft. Criminals aren't after your credit card — they're after your operating authority. Your FMCSA profile, MC number, DOT number, insurance certificate and contact details are what brokers and load boards use to verify you're real. Take that over, and an attacker can book loads, intercept payments and reroute freight while your reputation absorbs the damage.

A working market, not a hypothetical

This is an established economy. Aged, clean MC numbers with good safety records are bought and sold for tens of thousands of dollars, because a "seasoned" authority sails past the scrutiny a brand-new applicant attracts. When buying isn't an option, attackers steal: phishing a carrier's DOT PIN or FMCSA portal credentials, then quietly changing the registered contact details so load confirmations and payments route to them. Highway's 2025 data ranked sold MCs, compromised inboxes and phone spoofing as the three fastest-rising fraud vectors in freight.

The FMCSA has responded — overhauling registration, moving toward a single USDOT identifier, adding identity verification and standing up a dedicated registration-fraud team. But enforcement trails the criminals, and the burden of noticing a takeover still falls largely on the carrier.

Why a hijacked profile is so dangerous

When an impersonator controls your FMCSA contact info, the fallout compounds:

  • Cargo theft under your name. Loads booked as you, then rerouted and stolen.
  • Denied insurance claims. If an impersonator signed the bill of lading, your cargo policy may not respond — coverage often hinges on who is legally liable on a valid BOL.
  • Compliance trouble. Unauthorized changes to your records can trigger audits or suspensions.
  • Reputation damage with brokers and shippers who think you disappeared with a load.

What dark-web monitoring does about it

Monitoring watches the places this surfaces before it costs you. It scans criminal marketplaces, paste sites and breach dumps for your DOT and MC numbers, broker authority and driver PII, and it watches for unauthorized changes to your registered contact details. The goal is early warning: catching the takeover at the listing or credential-leak stage — not after a load has vanished and the claim's been denied.

Check your FMCSA record like you check your fuel card statement. The carriers who get burned are almost always the ones who found out their contact info had changed only after the claims started coming in.

A simple baseline every carrier should run

Even before formal monitoring, three habits cut your risk:

  • Review your FMCSA profile weekly for any contact, email or address change you didn't make.
  • Protect your DOT PIN and portal credentials like banking logins — unique password, MFA, never entered from an emailed link.
  • Be suspicious of anyone offering to buy your authority — that's the demand side of this market talking.

Want to know if your DOT, MC or driver data is already exposed? Book a free exposure check — no pitch, 72-hour reply.

★ Want this implemented for your fleet?

Book a 30-minute strategy call.

Walk away with a plan — even if we never work together.

Book a call