Cargo theft used to mean a cut lock and a missing trailer. Now it’s possible without any physical break-in. Fraudsters use stolen carrier credentials, spoofed email addresses, and fake broker identities to book loading, redirect freight, and disappear with shipments that were given to them willingly. The industry calls it strategic cargo theft, and it has turned the load board and the inbox into the most vulnerable points of entry.
The Numbers Behind the Problem
Verisk CargoNet, which tracks theft incidents across the U.S. and Canada, recorded 3,625 cargo theft incidents in 2024, a 27% increase over the prior year, with the average loss per incident climbing to over $202,000. Its 2025 reporting showed the average loss rising again to nearly $274,000 per incident, with estimated annual losses around $725 million. The American Trucking Associations reported that strategic theft that relies more on fraud and deception has risen roughly 1,500% since early 2021. This now accounts for nearly one in five cargo theft incidents in the United States.
The Transportation Intermediaries Association's 2025 State of Fraud report found that 83% of surveyed members experienced at least three types of fraud in a six-month window, that 22% suffered losses exceeding $200,000 in that same period, and that unlawful brokerage was the most cited fraud tactic. TIA recorded 1,611 fraud incidents among its members between September 2024 and February 2025, a 65% increase over the prior period.
In double-brokering fraud, the schemes take on a few recognizable forms. A criminal may pose as a legitimate carrier, accepts a load, then re-brokers it to an unsuspecting trucking company while collecting payment and vanishing. In fictitious pickups, a fraudster arrives with the right paperwork and the right load number, obtained from a compromised email account or load board profile, and drives away with freight the shipper believed was going to its carrier. In identity theft, a criminal operates under a legitimate company's MC number and insurance certificates, sometimes for months, taking loads the real company never sees.
Every one of these depends on stolen or fabricated digital identity. The crowbar has been replaced by a password.
How the Credentials Get Stolen
The point of entry is usually a phishing scam. A dispatcher or owner-operator receives an email that looks like it came from a load board, a factoring company, or a familiar broker, asking them to log in or confirm account details. The credentials go straight to the fraudster, who now controls the company's load board profile, sees its booked freight, and can communicate as the company itself.
With a compromised email the rest is easy. A fraudster monitoring a broker's or carrier's mailbox learns which loads are moving, who the counterparties are, and what the paperwork looks like. From there, inserting altered pickup instructions or impersonating a party to the transaction is straightforward. The fraud succeeds because everything about it looks routine to the people processing it.
Small carriers and 3PLs are the preferred targets. They hold the same credentials and move the same freight as large operations, but they rarely have email security, multi-factor authentication, or anyone watching for a suspicious login from an unfamiliar location. A criminal who compromises one small carrier's identity can use it against dozens of brokers and shippers before the pattern surfaces.
What Actually Prevents It
Multi-factor authentication on email, load board accounts, and TMS logins means a stolen password alone no longer hands over the company's identity. Email security filters out the phishing attempts that start most of these schemes, and monitoring flags the unusual login, the new forwarding rule, or the access from an unexpected country that signals an account takeover in progress.
Verifying new counterparties against FMCSA records and known contact information before tendering a load, confirming any change to pickup or payment instructions through a phone call to a known number, and training dispatchers to recognize the patterns of double-brokering and fictitious pickup schemes all stop fraud that gets past the technology. A driver who confirms the pickup number through the broker's verified line rather than the paperwork in front of him has defeated most fictitious pickups on his own.
Where a Managed IT Partner Helps
A managed service provider can run the technical half of this defense as an ongoing, proactive service. The provider can enforce multi-factor authentication across email, load boards, and operational systems, run the filtering and monitoring that catch phishing and account takeovers early, and lock down and log the remote access points fraudsters probe for. When something suspicious does occur, an unusual login, a forwarding rule nobody created, the provider can catch it while it's still an attempted fraud rather than a missing load.
For a small carrier or 3PL, the arithmetic is direct. With the average theft now costing more than a quarter million dollars, one stolen load can exceed years of the security spending that would have prevented it, and the reputational damage with shippers and brokers costs more than the freight.
If you're not confident your company's email and load board credentials are protected, or that your team would catch a fraudulent pickup before the freight left the yard, a Network Discovery might be in order. We'll assess how your systems are secured, where your credentials are exposed, and what an attacker impersonating your company could reach.
Ready to take the next step? Contact the Connecting Point team today to discuss your organization's needs.
Fill out our Network Discovery Form to get started!
970.356.7224 | www.CPcolorado.com | sales@CPcolorado.com
Connecting Point is a trusted IT solutions provider based in Greeley, Colorado, helping businesses across Northern Colorado and beyond navigate technology decisions with confidence.


