All resources
★ Field Report · 08 · Cybersecurity

Your ELD is a backdoor. Most carriers have no idea.

The device your driver is required by federal law to carry is also one of the least-secured pieces of technology on your fleet. Here is what researchers found — and what you need to do about it.

Trucky × We Secure·June 15, 2026·6 min read

In 2024, researchers at Colorado State University presented a paper at the Network and Distributed System Security Symposium that won runner-up for best paper. The finding: commercial ELDs — the devices every US carrier is legally required to run — can be wirelessly compromised over Bluetooth or Wi-Fi, used to spread malware from truck to truck while moving down a highway, and in some cases leveraged to force vehicles to pull over remotely.

FBI Bulletin

A bridge that runs in both directions

The FBI issued a bulletin years earlier. Their language: ELDs "create a bridge between previously unconnected systems critical to trucking operations." That bridge runs in both directions.

Why the mandate created the risk

The FMCSA ELD mandate that went into full effect in 2019 required carriers to log hours of service electronically. What it did not require was any security standard for the devices doing that logging. No encryption requirements. No third-party audits. No cybersecurity certification before self-certification.

The result: a market flooded with cheap, compliant-on-paper devices that do little to nothing to follow security best practices — a finding confirmed by FBI-referenced research on devices purchased directly off the shelf at retail stores.

In 2026, FMCSA updated compliance expectations to require encrypted data transmissions and mandatory over-the-air update capabilities. That is progress. But most fleets are still running devices purchased years before those standards existed.

What an attack through an ELD actually looks like

An attacker does not need to be inside your office. They need to be within wireless range of one of your trucks — a truck stop, a weigh station, a yard. From there:

  • They access the ELD over an unencrypted Bluetooth or Wi-Fi connection.
  • They load malware onto the device.
  • That malware spreads to other vehicles the truck comes within range of — including loading docks and distribution centers.
  • From the ELD, the attacker pivots to connected systems: your TMS data feed, driver communication logs, DOT compliance records.

The Colorado State team demonstrated this in a controlled environment. They were not speculating.

The three questions every carrier needs to answer today

1

When did your ELD vendor last push a security update?

If you cannot answer this, your device may be running firmware with known vulnerabilities. Ask your vendor directly. If they cannot answer either, that is your answer.

2

Does your ELD encrypt data in transit?

Unencrypted Bluetooth connections are no longer compliant under 2026 FMCSA standards. If your device is still transmitting data in the clear, you are exposed — legally and operationally.

3

What connects to your ELD network?

ELDs are increasingly integrated with TMS platforms, fuel card systems, and fleet management software. An attacker who enters through the ELD does not stay there.

What the We Secure partnership covers

Our cybersecurity offering, delivered through We Secure, includes endpoint detection on all devices with network access — including telematics systems — and continuous monitoring for lateral movement between systems. If an ELD on your fleet is behaving like an entry point, we see it.

Next step

Start with a free exposure check

We will run the same scan an attacker would run on your network — including your connected telematics — and tell you exactly what they see.

★ Want this implemented for your fleet?

Book a 30-minute strategy call.

Walk away with a plan — even if we never work together.

Book a call