5 phishing emails hitting dispatch desks right now in 2026 — and how to spot them.
Attackers are sending highly targeted phishing emails to US trucking dispatch teams in 2026. Here are the 5 most common patterns, annotated examples, and a printable red-flag checklist to share with your team Monday morning.
These aren't hypothetical. In 2025 and 2026, attackers sent highly targeted phishing emails to US trucking dispatch teams — compromising broker accounts, installing remote access tools, and enabling $725M in cargo theft. Here are the 5 patterns, with annotated examples and a checklist to share with your team.
Why your dispatch desk is the primary target
Dispatchers are the keys to the kingdom. They have credentials for load boards, TMS platforms, and broker communication channels. They handle high-volume email under time pressure — dozens of load requests, check calls, and rate confirmations every hour. And most receive zero security training specific to trucking threats.
Proofpoint researchers in late 2025 documented organized crime groups running coordinated remote access campaigns specifically targeting trucking and logistics dispatch teams — not because they wanted to steal data, but because controlling a dispatcher's account meant controlling physical freight worth hundreds of thousands of dollars per load.
The 'fake broker rate confirmation'
The attacker spoofs a real broker's email domain — often with a single character changed (e.g. coyote.com → coyotelogistics-rates.com). The email looks exactly like a normal rate confirmation but contains a link to 'view the rate sheet' that installs an RMM tool.
Hi team,
Please find the updated rate confirmation for Load #8841 attached. The shipper has requested an amended delivery window — please review and confirm by 3PM.
📎 View Rate Sheet → coyotelogistics-rates.com/rc/8841.pdf
Questions? Call your rep at (312) 555-0192.
Thanks, Mike Reyes | Carrier Relations | Coyote Logistics
The 'carrier packet request' from a new shipper
Targets owner-operators and small carriers hungry for new business. The attacker poses as a shipper or broker onboarding the carrier and sends a 'carrier packet' PDF or link that installs malware — then uses the harvested MC number and insurance certificates to impersonate the carrier on load boards.
Hi,
We found your carrier profile on DAT and we'd love to add you to our preferred carrier network. We have consistent dry van lanes out of Atlanta — 3–5 loads/week.
To get started, please complete our carrier packet:
📋 Complete Carrier Packet → carrier-setup.freightpartnersinc.net/onboard
Takes about 10 minutes. Once approved you'll receive loads directly from our team.
Best, Sarah Walsh | Carrier Development
The 'ELD compliance update' from 'FMCSA'
Attackers know carriers are terrified of FMCSA violations. This email spoofs official government communications — warning of a compliance issue with your ELD or DOT number and demanding immediate action through a link that installs malware.
FEDERAL MOTOR CARRIER SAFETY ADMINISTRATION — NOTICE OF COMPLIANCE REVIEW
Your USDOT record indicates a potential ELD reporting discrepancy. To avoid a compliance hold on your operating authority, you must complete a verification form within 72 hours.
🔒 Complete Verification → fmcsa-updates.gov.us.com/compliance/verify
Failure to respond may result in suspension of operating authority.
FMCSA Compliance Division
The 'lumper / detention invoice' malware attachment
A simple but effective attack targeting accounting. The attacker sends a realistic-looking detention or lumper invoice as a Word document or Excel file. Opening it executes a macro that installs malware. This attack specifically targets firms that use older Microsoft Office versions without Protected View enabled.
Hello Accounts Payable,
Please find attached the detention invoice for delivery on 06/03 at the Chicago facility. Total owed: $380.00.
📎 Detention_Invoice_2847.xlsm ← (malicious macro-enabled Excel file)
Please remit payment within 30 days. Thank you for your business.
Premier Lumper Services
The 'fuel card update' account takeover
Targets fleet managers and operations leads. The attacker spoofs a fuel card provider (EFS, Comdata, Relay) and claims the account requires re-verification due to a 'security review.' The goal: steal credentials and drain the fleet's fuel card balance, or use account access to harvest driver data for identity theft.
Dear Fleet Manager,
As part of our ongoing security upgrades, we require all account holders to verify their credentials by June 20. Failure to verify will result in a temporary account hold.
🔐 Verify My EFS Account → efs-fleetsupport.com/verify/secure
This takes less than 2 minutes. Your drivers will not be affected during business hours.
EFS Security Team
The printable red-flag checklist for your team
Print this. Post it at every dispatch station. Go through it with new hires during onboarding. Check every unexpected email against this list before clicking any link or opening any attachment.
- ★Does the sender domain exactly match the company's real website? (e.g. coyote.com, not coyotelogistics-rates.com)
- ★Is there a link asking you to 'view a document' on an external website rather than a direct attachment?
- ★Is there artificial urgency — a deadline, account-suspension threat, or 'immediate action required'?
- ★Is the attachment a .xlsm, .docm, .exe, or .zip file you weren't expecting?
- ★Is this from a government agency (FMCSA, DOT, USDOT) via email with a link? Real compliance notices come by postal mail or registered portal.
- ★Is someone you've never worked with offering new loads, rates, or partnerships via a cold email with a link?
- ★Does the email ask you to update login credentials, re-enter payment info, or confirm insurance details through a link?
- ★When in doubt — call the sender directly using a number from their real website, not the number in the email.
What to do if you clicked
- Disconnect the machine from the network (unplug ethernet, disable Wi-Fi).
- Leave it running — do NOT turn it off, forensics need the memory state.
- Call your IT contact or SOC immediately.
- Change all passwords for load boards, TMS, and email from a different device.
- Notify your broker contacts that your account may be compromised.
- Check FMCSA records for any unauthorized changes.
- Try to 'fix it yourself' by running antivirus — attackers monitor for this.
- Pay any ransom before consulting a professional.
- Wait to see 'if anything happens' — dwell time averages 16 days.
- Tell only one person — escalate to ownership immediately.
- Continue dispatching on the compromised machine.
The technical layer that stops these attacks before they arrive
Human training matters — but humans make mistakes under pressure. The second line of defense is technical. Trucky's cybersecurity partnership with We Secure deploys three layers that stop these 5 attack patterns before the email ever reaches a dispatcher:
- ★Email security with link sandboxing — every inbound link is detonated in a sandbox before delivery. Malicious links are stripped automatically.
- ★Anti-spoofing (DMARC / DKIM / SPF enforcement) — emails spoofing your domain or your brokers' domains are blocked at the gateway, not just flagged.
- ★EDR with behavioral detection — if a dispatcher does click, EDR detects the RMM tool installation within seconds and kills it before it can call home.
Combined, these three controls stop 94%+ of the phishing attack chain before any human decision point.
Book a 30-minute strategy call.
Walk away with a plan — even if we never work together.
Book a call →
