All resources
★ Security Playbook · 07 · Cybersecurity

5 phishing emails hitting dispatch desks right now in 2026 — and how to spot them.

Attackers are sending highly targeted phishing emails to US trucking dispatch teams in 2026. Here are the 5 most common patterns, annotated examples, and a printable red-flag checklist to share with your team Monday morning.

Trucky × We Secure·May 28, 2026·8 min read

These aren't hypothetical. In 2025 and 2026, attackers sent highly targeted phishing emails to US trucking dispatch teams — compromising broker accounts, installing remote access tools, and enabling $725M in cargo theft. Here are the 5 patterns, with annotated examples and a checklist to share with your team.

Why your dispatch desk is the primary target

Dispatchers are the keys to the kingdom. They have credentials for load boards, TMS platforms, and broker communication channels. They handle high-volume email under time pressure — dozens of load requests, check calls, and rate confirmations every hour. And most receive zero security training specific to trucking threats.

Proofpoint researchers in late 2025 documented organized crime groups running coordinated remote access campaigns specifically targeting trucking and logistics dispatch teams — not because they wanted to steal data, but because controlling a dispatcher's account meant controlling physical freight worth hundreds of thousands of dollars per load.

1

The 'fake broker rate confirmation'

The attacker spoofs a real broker's email domain — often with a single character changed (e.g. coyote.com → coyotelogistics-rates.com). The email looks exactly like a normal rate confirmation but contains a link to 'view the rate sheet' that installs an RMM tool.

From: dispatch@coyotelogistics-rates.com
To: dispatch@yourcarrier.com
Subject: Rate Confirmation — Load #8841-CHI — Action Required

Hi team,

Please find the updated rate confirmation for Load #8841 attached. The shipper has requested an amended delivery window — please review and confirm by 3PM.

📎 View Rate Sheet → coyotelogistics-rates.com/rc/8841.pdf

Questions? Call your rep at (312) 555-0192.

Thanks, Mike Reyes | Carrier Relations | Coyote Logistics

Domain mismatch
Real Coyote is coyote.com — not coyotelogistics-rates.com. Always check the full domain, not just the display name.
Urgency + PDF link
'Action required by 3PM' combined with a link (not an attachment) to an external domain is a classic phishing trigger combo.
Phone number doesn't match
Google the broker's real number. Attackers use VOIP numbers they control to answer verification calls.
2

The 'carrier packet request' from a new shipper

Targets owner-operators and small carriers hungry for new business. The attacker poses as a shipper or broker onboarding the carrier and sends a 'carrier packet' PDF or link that installs malware — then uses the harvested MC number and insurance certificates to impersonate the carrier on load boards.

From: carrier-setup@freightpartnersinc.net
To: owner@yourfleet.com
Subject: Carrier Setup — We'd Love to Work with Your Fleet

Hi,

We found your carrier profile on DAT and we'd love to add you to our preferred carrier network. We have consistent dry van lanes out of Atlanta — 3–5 loads/week.

To get started, please complete our carrier packet:

📋 Complete Carrier Packet → carrier-setup.freightpartnersinc.net/onboard

Takes about 10 minutes. Once approved you'll receive loads directly from our team.

Best, Sarah Walsh | Carrier Development

Unsolicited outreach asking for credentials
Legitimate brokers don't cold-email carrier packet links. They use DAT, Truckstop, or direct phone calls.
External subdomain for the form
The main domain may look real, but a brand-new subdomain like carrier-setup.freightpartnersinc.net is hosted malware infrastructure.
3

The 'ELD compliance update' from 'FMCSA'

Attackers know carriers are terrified of FMCSA violations. This email spoofs official government communications — warning of a compliance issue with your ELD or DOT number and demanding immediate action through a link that installs malware.

From: compliance@fmcsa-updates.gov.us.com
To: safety@yourcarrier.com
Subject: ⚠ URGENT: ELD Compliance Review Required — MC# [YOUR MC]

FEDERAL MOTOR CARRIER SAFETY ADMINISTRATION — NOTICE OF COMPLIANCE REVIEW

Your USDOT record indicates a potential ELD reporting discrepancy. To avoid a compliance hold on your operating authority, you must complete a verification form within 72 hours.

🔒 Complete Verification → fmcsa-updates.gov.us.com/compliance/verify

Failure to respond may result in suspension of operating authority.

FMCSA Compliance Division

Government domains end in .gov only
fmcsa.dot.gov is the real domain. Any .gov.us.com, .gov.net, or variation is fake. The FMCSA does not send compliance notices via unsolicited email links.
Manufactured urgency with a deadline
'72 hours to avoid suspension' is designed to prevent the recipient from thinking clearly or verifying independently.
4

The 'lumper / detention invoice' malware attachment

A simple but effective attack targeting accounting. The attacker sends a realistic-looking detention or lumper invoice as a Word document or Excel file. Opening it executes a macro that installs malware. This attack specifically targets firms that use older Microsoft Office versions without Protected View enabled.

From: billing@premierlumperservices.com
To: ap@yourcarrier.com
Subject: Invoice #2847 — Detention Charges — Please Process

Hello Accounts Payable,

Please find attached the detention invoice for delivery on 06/03 at the Chicago facility. Total owed: $380.00.

📎 Detention_Invoice_2847.xlsm ← (malicious macro-enabled Excel file)

Please remit payment within 30 days. Thank you for your business.

Premier Lumper Services

.xlsm or .docm file extensions
These are macro-enabled files. Legitimate invoices arrive as PDF. Never enable macros on an attachment you weren't expecting.
Lumper service you don't recognize
Verify against actual deliveries in your TMS before opening any attachment from an unknown billing company.
5

The 'fuel card update' account takeover

Targets fleet managers and operations leads. The attacker spoofs a fuel card provider (EFS, Comdata, Relay) and claims the account requires re-verification due to a 'security review.' The goal: steal credentials and drain the fleet's fuel card balance, or use account access to harvest driver data for identity theft.

From: security@efs-fleetsupport.com
To: fleetmanager@yourcarrier.com
Subject: Action Required: EFS Account Security Verification

Dear Fleet Manager,

As part of our ongoing security upgrades, we require all account holders to verify their credentials by June 20. Failure to verify will result in a temporary account hold.

🔐 Verify My EFS Account → efs-fleetsupport.com/verify/secure

This takes less than 2 minutes. Your drivers will not be affected during business hours.

EFS Security Team

Real EFS domain is wexinc.com or efsllc.com
Not efs-fleetsupport.com. Log in directly through your saved bookmark — never through an email link.
'Deadline to verify or face account hold'
Fuel card companies do not suspend accounts via email. Call your account rep directly to verify any security notices.

The printable red-flag checklist for your team

Dispatch desk · Email red-flag checklist

Print this. Post it at every dispatch station. Go through it with new hires during onboarding. Check every unexpected email against this list before clicking any link or opening any attachment.

  • Does the sender domain exactly match the company's real website? (e.g. coyote.com, not coyotelogistics-rates.com)
  • Is there a link asking you to 'view a document' on an external website rather than a direct attachment?
  • Is there artificial urgency — a deadline, account-suspension threat, or 'immediate action required'?
  • Is the attachment a .xlsm, .docm, .exe, or .zip file you weren't expecting?
  • Is this from a government agency (FMCSA, DOT, USDOT) via email with a link? Real compliance notices come by postal mail or registered portal.
  • Is someone you've never worked with offering new loads, rates, or partnerships via a cold email with a link?
  • Does the email ask you to update login credentials, re-enter payment info, or confirm insurance details through a link?
  • When in doubt — call the sender directly using a number from their real website, not the number in the email.

What to do if you clicked

Do this
  • Disconnect the machine from the network (unplug ethernet, disable Wi-Fi).
  • Leave it running — do NOT turn it off, forensics need the memory state.
  • Call your IT contact or SOC immediately.
  • Change all passwords for load boards, TMS, and email from a different device.
  • Notify your broker contacts that your account may be compromised.
  • Check FMCSA records for any unauthorized changes.
Do NOT
  • Try to 'fix it yourself' by running antivirus — attackers monitor for this.
  • Pay any ransom before consulting a professional.
  • Wait to see 'if anything happens' — dwell time averages 16 days.
  • Tell only one person — escalate to ownership immediately.
  • Continue dispatching on the compromised machine.

The technical layer that stops these attacks before they arrive

Human training matters — but humans make mistakes under pressure. The second line of defense is technical. Trucky's cybersecurity partnership with We Secure deploys three layers that stop these 5 attack patterns before the email ever reaches a dispatcher:

  • Email security with link sandboxing — every inbound link is detonated in a sandbox before delivery. Malicious links are stripped automatically.
  • Anti-spoofing (DMARC / DKIM / SPF enforcement) — emails spoofing your domain or your brokers' domains are blocked at the gateway, not just flagged.
  • EDR with behavioral detection — if a dispatcher does click, EDR detects the RMM tool installation within seconds and kills it before it can call home.

Combined, these three controls stop 94%+ of the phishing attack chain before any human decision point.

★ Want this implemented for your fleet?

Book a 30-minute strategy call.

Walk away with a plan — even if we never work together.

Book a call