A freight broker’s email about a complaint can look like an everyday operational problem. A carrier clicks to protect its rating, opens a broker agreement, and gets back to work.
But the document can be the first move in something much larger than ordinary phishing. Once criminals control a freight account, they can post fake loads, impersonate real companies, and redirect valuable cargo that already has a legitimate shipper and driver.
The stolen item is not just a password. It can be an entire truckload, and the people moving it may not realize they are following instructions from an attacker.

Overview
What the first message looks like
The entry point may be a spoofed broker email about a carrier agreement, a service complaint, an insurance document, or a poor rating that needs attention. The message contains a shortened or lookalike link and pushes the recipient to open a form or download a file.
Because brokers and carriers routinely exchange documents, the request fits the work. The danger is hidden in the destination. The FBI says phishing sites used in these attacks can host malicious executable files that install legitimate remote monitoring and management software, giving criminals quiet access to company systems.
What the criminals do with access
After compromising a broker or carrier, the attackers use its identity on freight load boards. They post fake loads, answer bids, send more malicious broker agreements, and compromise additional companies. The FBI says some attackers have posted fake loads in the tens of thousands.
The criminals also bid on real loads while posing as a trusted carrier. They can alter contact details, insurance information, bills of lading, dispatch instructions, and delivery destinations. An unwitting driver may pick up genuine cargo and carry it to a place controlled by the thieves.
Why this is a confirmed scam
In April 2026, the FBI’s Internet Crime Complaint Center issued a public warning about a surge in cyber-enabled strategic cargo theft. The FBI reported that estimated cargo theft losses in the United States and Canada reached nearly $725 million in 2025, up 60% from 2024, while confirmed incidents rose 18%.
The key warning signs include:
- A broker email uses a free account or a slightly altered company domain.
- A complaint, rating, or agreement link downloads a program.
- A new broker account posts an unusually valuable or high-rate load.
- Contact or insurance details change immediately before booking.
- A delivery address changes after pickup without independent confirmation.
- Other companies report shipments booked under your authority without permission.
Why Freight Workflows Are Vulnerable
The logistics industry runs on speed. Loads move through brokers, carriers, dispatchers, drivers, warehouses, and customers, often across several systems. A request can be urgent and still be real, which makes “urgent” a useful word for attackers.
Identity is also distributed. A recognizable company name, motor-carrier number, insurance certificate, and familiar email signature may appear together, yet the account behind them can be compromised. The documents can be genuine files stolen from the victim company.
Load boards create a marketplace where new relationships form quickly. A carrier may have only hours to review and accept a shipment. Criminals exploit that pace by making the rate attractive and the paperwork look complete.

Remote access changes the attacker’s view. Instead of guessing how a company communicates, criminals can watch real inboxes, read current lanes, copy templates, and reply from legitimate accounts. That makes a fake load look like it came from the same workflow used yesterday.
The same access can reveal which employee is away, which customer accepts last-minute changes, and which loads carry valuable or easily resold goods. A tailored reroute sent at the right moment is harder to challenge than a random request from an unknown address.
Insurance documents are useful camouflage too. An attacker can present a real certificate stolen from the compromised account, then change only the email or phone number used for confirmation. A document can be authentic while the person sending it is not.
Double-brokering adds another layer. A criminal can accept a real load under a stolen carrier identity, then pass the movement to a driver who thinks the job is legitimate. The driver may follow a reroute sent by the attacker and deliver the cargo away from its intended destination.
By the time the real carrier learns its authority was used, the shipment may have been cross-docked or transferred again. Each handoff makes recovery harder and gives the attackers more distance from the initial phishing email.
How the Load Board Cargo Theft Scam Works
Step 1: A broker or carrier receives a phishing lure
The email may mention a negative service review, an updated broker packet, a rate confirmation, or a compliance issue. The visible sender resembles a known company, but the domain contains an extra word, punctuation mark, or different ending.
Step 2: A malicious file creates remote access
The linked page imitates a familiar portal and offers a document. Instead of a harmless PDF, the download can install remote monitoring software. Because some remote tools are legitimate products, basic defenses may not immediately treat them as malware.
Step 3: The attacker studies and takes over accounts
With mailbox, load-board, or workstation access, the criminal gathers credentials, templates, contacts, and shipment details. New forwarding rules or hidden folders can conceal alerts from the real account owner.
Step 4: Fake loads spread the compromise
The attacker posts attractive loads under the victim’s name. Carriers who respond receive the same malicious paperwork, creating more compromised accounts. A single stolen identity can become a distribution point.
Step 5: A real shipment is booked under a stolen identity
The criminal bids on a legitimate load while impersonating a carrier. Documents and public records make the booking appear valid. Contact or insurance details may be changed so verification requests reach the attacker.
Step 6: The driver receives altered instructions
After pickup, the attacker changes the delivery location, provides a modified bill of lading, or claims the customer requested a new warehouse. The driver may be only partially aware that anything is wrong.
Step 7: The cargo is transferred and stolen
The load can be cross-docked, transloaded, or handed to another driver. Criminals resell the goods, and some contact the broker again to demand money for information about the shipment.

The Warning Signs Across the Shipment
Email clues matter, but this scam cannot be stopped by inbox training alone. The organization must watch the entire load lifecycle. A message that is harmless at booking can be followed by a suspicious reroute after pickup.
Inspect domain names letter by letter. The FBI lists free email providers, added prefixes or suffixes, different top-level domains, and slight misspellings as indicators. A familiar display name is not enough.
Treat any unexpected software download as a stop signal. Broker packets and rate confirmations normally arrive as documents or through known portals. A request to run an EXE, remote support client, or browser “update” should go to IT before it is opened.
Operational changes deserve two-channel verification. A new dispatcher, phone number, delivery address, bank account, insurance document, or routing instruction should be confirmed using contact information already on file, not the details inside the change request.
Company and Checkout Checks
Check the business identity
Verify the legal name, operating authority, motor-carrier and Department of Transportation numbers, insurance, and known contact details. Compare them with records already held by the company and authoritative databases rather than attachments supplied in the email.
Check the account and domain
Review recent sign-ins, mailbox rules, load-board sessions, password changes, and contact-profile edits. A valid company profile can still be under criminal control. Call a previously known number to verify unusual activity.
Check the load before release
Confirm the driver, vehicle, trailer, pickup number, destination, and carrier relationship through separate channels. Record driver identification, license plate, truck and trailer numbers, and photographs where policy and law allow.
Check every post-pickup change
A reroute is the logistics equivalent of a changed bank account. Require a documented callback to a trusted shipper or broker contact. Do not rely on the person who sent the new address to validate their own request.
What to Do if You Have Fallen Victim to This Scam
- Start the incident plan immediately. Notify security, dispatch, management, the broker, carrier, shipper, insurer, and affected customer. Do not wait to determine whether the problem is “only email.”
- Try to stop the load. Contact the verified driver and legitimate parties through numbers already on file. Give law enforcement the last confirmed location, equipment identifiers, cargo description, and altered destination.
- Call local police and the FBI. Report the cargo theft to the police agency with jurisdiction and file a complaint with IC3. Preserve bills of lading, rate confirmations, messages, call records, GPS data, and surveillance footage.
- Contain compromised accounts. Disable affected mail, load-board, remote-access, and identity sessions. Reset credentials from clean systems, revoke tokens, and review multifactor and recovery settings.
- Hunt for persistence. Check remote monitoring tools, startup items, new administrators, scheduled tasks, mailbox forwarding, deleted messages, and altered profiles. A scanner such as Malwarebytes can help find common malware, but a business incident should receive professional forensic review.
- Warn trading partners. Tell them which domains, phone numbers, documents, and load references were abused. Attackers may continue using the stolen identity after the first shipment is discovered.
- Notify financial and insurance contacts. If bank or payment data was exposed, contact the institution through a known number. Follow cargo, cyber, and crime-policy notification requirements promptly.
- Block known malicious infrastructure. Add domains, senders, hashes, and remote tools to security controls. AdGuard or another reputable blocker can reduce exposure to known malicious sites on individual systems, but it cannot replace controlled software installation and account monitoring.
How Logistics Companies Can Break the Chain
Use callback verification for high-risk changes and make it routine enough that staff do not feel they are slowing the business. A two-minute call before releasing a six-figure load is cheaper than tracing it after diversion.
Build the callback list before an incident. Store verified contacts for brokers, carriers, shippers, warehouses, and insurers outside ordinary email threads. When a change arrives, staff should not search the same message for the number used to verify it.
Reconcile booked loads with actual dispatch activity every day. A compromised account may be used to post or accept shipments that do not appear in the company’s transportation system. Early mismatches can reveal abuse before pickup.
Limit who can edit load-board profiles, contact details, insurance, and bank information. Require strong multifactor authentication, preferably resistant to phishing, and alert on new devices, unusual locations, new forwarding rules, and bulk load postings.
Run tabletop exercises that include both an account breach and a shipment already in motion. The response team should know who can contact the driver, who can freeze a load-board account, which police agency to call, and where current cargo and insurance records are stored.
Application allowlisting can prevent an emailed executable from launching even when a user clicks it. Remote management tools should be approved, inventoried, and monitored. Unknown instances deserve the same urgency as custom malware.
MalwareTips has described how an ordinary business email can install remote-access malware. In freight theft, that same foothold can escape the screen and change where physical goods travel.
Frequently Asked Questions
What is a freight load board?
It is an online marketplace where shippers, brokers, carriers, and owner-operators post or find available loads. Criminals abuse compromised accounts because the platform connects people who may not have worked together before.
Is double-brokering always cargo theft?
Unauthorized double-brokering is illegal and dangerous, but not every case follows this exact cyber-theft pattern. The FBI warning describes criminals using stolen identities and partially unwitting drivers to redirect loads for theft.
Why use legitimate remote-access software?
Legitimate tools can blend into normal business activity and may be trusted by security products. The criminal abuses the tool’s remote-control features after tricking a user into installing it.
Can a valid motor-carrier number still be part of the scam?
Yes. The number may belong to a real company whose account or identity was stolen. Verify the current contact through independent records and watch for last-minute profile changes.
What should a driver do after receiving a reroute?
Pause and verify the change with the dispatcher and broker through previously known contact details. Do not rely only on the number or email that sent the new address.
Where should cyber-enabled cargo theft be reported?
Report the physical theft to local police and the cyber component to the FBI’s Internet Crime Complaint Center. Also notify the insurer and all legitimate companies involved.
The Bottom Line
The load board cargo theft scam begins with a familiar email and ends with real goods at the wrong warehouse. Its power comes from combining account takeover, business impersonation, marketplace trust, and physical logistics.
No single document or company name can prove a load is legitimate once an account is compromised. Verify identities, software, pickup details, and every reroute through a second trusted channel.
The FBI’s official cargo theft warning documents the scale and the multi-step method. For brokers and carriers, cybersecurity is now part of cargo custody from the first email to final delivery.