When you think of cargo theft, what picture comes to mind?
If you’re like most folks that have spent years in trucking, you picture a midnight breach at an unsecured drop lot, a padlock cut on a trailer door, or someone hotwiring a day cab parked off the interstate. For decades, cargo theft was a crime of physical opportunity. It took bolt cutters, physical daring, and a getaway driver.
But if you have been paying attention to the freight market lately, you know the game has totally changed.
Now, picture this: you’re in the office or doing a 10-hour reset in your sleeper berth. Then your phone rings. On the line is an irate freight broker or shipper wanting to know why a $600,000 load of enterprise AI servers or commercial copper rolls never arrived at a warehouse in Ohio. You check your dispatch system, dumbfounded. Your trucks were not within hailing distance of that lane. Your drivers were hauling dry goods across. But the broker has a signed rate confirmation, a W-9, and one of your very own active Certificates of Insurance with your exact USDOT and Motor Carrier (MC) numbers stamped right on the top.
Welcome to the modern era of identity hijacking – a cyber-enabled crime wave that is currently shaking the American transportation sector to its core.
Identity fraud attempts in the logistics industry increased by over 200% from 2023 to 2025, along with an almost 1,500% surge in strategic theft, where criminals use stolen data to book loads. Rather than breaking door latches, bad actors steal data from the dark web and use legitimate carrier credentials to fraudulently book loads and redirect freight for their own gain. The worst part? Under federal law, your trucking company could be held strictly liable for hundreds of thousands of dollars in stolen goods – even if your physical trucks never turned a tire on that run.
At HMD Trucking, operating out of our headquarters right here in the Chicago freight hub, we see firsthand how vital it is to protect not just our iron and rubber but also our digital footprint. In this comprehensive guide, we are taking a deep dive into how identity hijacking works, the massive legal liabilities involved, how federal regulators are fighting back in 2026, and the exact steps you can take to safeguard your authority.
Contents:
- The Escalation of Cyber-Enabled Cargo Theft: The 2026 Landscape
- Inside the Playbook: How Cybercriminals Hijack Carrier Authorities
- The Federal Response: FMCSA’s Motus Platform and Biometric Vetting
- Action Plan: How to Safeguard Your Trucking Identity
- Key Takeaways for Truckers and Fleet Owners
- The Road Ahead: Safeguard Your Authority and Drive with Confidence
The Escalation of Cyber-Enabled Cargo Theft: The 2026 Landscape
To understand why identity hijacking has become such a dominant threat, we have to look at the numbers. Supply chain crime data compiled by Verisk CargoNet reveals a fascinating – and frightening – shift in how organized crime targets American freight.
There was little change in the volume of supply chain crime from 2024 to 2025, with reported events holding at a steady 3,600 or so a year. Yet behind that flat line is a historic escalation in the cost of such thefts. In 2025, confirmed cases of cargo theft rose 18% to 2,646, and industry losses followed suit with a 60% increase in one year, going from $454.9 million to $725 million.
The reason for the disparity between incident numbers and financial impact is clear: organized cyber syndicates have left the low-margin consumer goods they could once be tracked on. They are now hijacking carrier authorities to make off with the most valuable freight on U.S. highways.
That trend shows no sign of letting up in 2026. CargoNet has already put 596 confirmed thefts on the books in the first quarter, representing more than $131.58 million in losses. As we reach the midpoint of the year, total national losses have passed the $359 million mark, and the average stolen load is worth a record $341,518.
| Metric / Indicator | 2024 Full Year | 2025 Full Year | Q1 2026 | H1 2026 |
| Total Reported Supply Chain Events | 3,607 | 3,594 | 767 | N/A |
| Confirmed Theft Incidents | 2,243 | 2,646 (+18%) | 596 | N/A |
| Total Estimated Financial Loss | ~$454.9 Million | ~$725 Million (+60%) | $131.58 Million | >$359 Million |
| Average Loss Value Per Stolen Load | $202,364 | $273,990 (+36%) | ~$220,771 | $341,518 |
| Top Commodities Targeted | Consumer Electronics, Food | Food & Bev (+47%), Metals (+77%) | Enterprise Hardware, Metals | Commercial Copper, AI Servers |
The Shifts in What and Where Thieves Are Stealing
Criminal networks have fundamentally changed their shopping list. Consumer-grade televisions and laptops have fallen out of favor. Instead, fraudsters use stolen carrier identities to tender loads of the following:
Commercial Copper and Raw Metals: Metal theft jumped by 77% in 2025, with almost 7 out of 10 metal thefts targeting commercial copper shipments. Copper is virtually undetectable, has a high market value, and can be readily purchased at scrap yards for quick cash.
High-End Food and Agriculture: Food and beverage thefts increased 47% in 2025 to a total of 708 incidents. Meats, frozen seafood, and tree nuts are targets since they can be consumed or resold in secondary markets long before authorities track the supply chain.
AI Infrastructure & High-Performance Computing: In the tech industry criminals have shifted to commercial hardware. Enterprise graphics processing units, or GPUs, high-density RAM modules, solid-state drives, and server racks bound for AI data centers or crypto mining nodes are ideal picks. One truckload of server hardware can easily exceed the total value of $1 million to $2 million.
Geographically, while California remains the single most targeted state – accounting for 38% of all national cargo thefts in 2025 – the danger zone has expanded. Theft activity has migrated away from the immediate coastal port basins like Los Angeles and pushed inland toward distribution hubs in Kern County (+82%) and San Joaquin County (+44%). Furthermore, major transit states across the country are seeing massive upticks, including New Jersey (+50% in 2025 and +119% in Q1 2026), Indiana (+30%), and Pennsylvania (+24%).
Inside the Playbook: How Cybercriminals Hijack Carrier Authorities
How does a fraudster in an office thousands of miles away steal a carrier’s identity and make off with a half-million-dollar load? It’s not an accident. Instead, it is the end result of an intentional, very organized technical process.
The Dark Web Data Leak and SAFER Modifications
The foundation for the current epidemic of stolen authority was laid in mid-2023 when a massive cybersecurity incident exposed the database for the Federal Motor Carrier Safety Administration (FMCSA). While initial public reporting indicated that only minimal government employee information was leaked, by late 2023, the entire FMCSA Personal Identification Number (PIN) database was in the hands of criminal syndicates who were selling it on dark web forums.
With these stolen DOT PINs, bad actors access the government’s legacy SAFER (Safety and Fitness Electronic Records) portal. They perform an illegal MCS-150 update on a legitimate carrier that is targeted. The fraudsters silently alter the main phone number, physical address, and email address for the carrier, rerouting those communications to their own devices.
When a freight broker runs an automated compliance check using standard screening tools, all is green. The broker looks for an active USDOT number, a clean safety rating, years in business, and contact information that matches up with government records.
Email Infiltration and Communications Interception
As brokers and screening services got more sophisticated in flagging sudden contact changes on SAFER profiles, cybercriminals adapted. Today they are attacking carriers directly.
Scammers glean public data for small- to mid-sized motor carriers who use basic public email services (like @gmail.com or @yahoo.com) or weak password protection. Attackers gain access to the primary email account of the carrier, often through credential stuffing or phishing emails. Inside they don’t immediately lock out the carrier. Instead, they create silent inbox rules that would invisibly forward incoming broker messages to a covert folder and delete any replies sent out.
The hacker then digs through the carrier’s historical sent mail to collect authentic documentation:
- Current Certificates of Insurance (COI) with active policy numbers.
- FMCSA operating authority certificates.
- Completed W-9 forms.
- Bank Notices of assignment (NOA’s) from factoring companies.
Using these valid documents, the thief pitches brokers, bids on high-value loads, and executes rate confirmations directly from the carrier’s actual email address. As if this were not bad enough, in 2026 more and more criminals are hacking into cloud VoIP business phone systems. Should a skeptical broker phone the number on the rate confirmation to verify the details, the call is seamlessly transferred to an operative working in a call center operated by the criminal syndicate.
The Double Broker Diversion Scheme Workflow
Once the fraudster books the high-value load under your hijacked authority, the actual theft is set into motion through a five-stage diversion process:
- Load Acquisition: Under the hijacked name, the scammer contacts a freight broker to book a high-value shipment and completes a digital rate confirmation using W-9 and COI documents.
- Re-Brokering the Load: The scammer places the load on a public load board using a secondary company, often offering a higher price than the market to ensure a quick pickup.
- The Innocent Trucker Arrives: An unsuspecting, legitimate motor carrier accepts the second-rate confirmation and sends a driver and rig to the shipping facility. A real truck arrives at the loading dock with a valid pickup number, so the dock workers immediately load the trailer.
- The Mid-Transit Reroute: While the truck is on the highway, the swindler calls the driver, claiming to be the broker, and states that the receiving warehouse has an emergency overflow or that the delivery address has been changed. He is told to park his truck in an offsite cross-dock or a rental storage yard.
- The Disappearing Act: The freight is offloaded, instantly transferred into unmarked trailers, and driven away. When the shipper realizes the freight never made it to its destination after several days, the digital trail is stone-cold, and the scammer has deleted their temporary accounts.
The Legal Trap: Why Compromised Carriers Face Massive Liability
That leads us to the most dangerous element of identity hijacking for American trucking companies: the legal exposure.
When a half-million-dollar load goes poof, the cargo owner and lead broker aren't going to sit back and take the loss. They are going to trace the paperwork back to the authority that booked the shipment, and that means you, your company, and your insurance provider.
Strict Liability Under the Carmack Amendment
In the United States, liability for interstate surface transport is governed by the Carmack Amendment, a federal statute (49 U.S.C. § 14706). Carmack was intended to create a uniform standard across state lines, though it sets an extremely high bar for motor carriers.
Under Carmack, a shipper or broker must only prove three things to establish a prima facie strict liability case against a carrier:
- The load was delivered to the carrier at origin in good condition;
- The cargo arrived damaged or short, or did not arrive at all;
- The actual monetary value of the economic loss.
Once you establish those three points, strict liability attaches. Full burden shifts to the carrier. In order to avoid liability for the entire lost shipment, the carrier must affirmatively prove that they were entirely free from negligence and that the loss was caused by one of five very narrow common law exceptions:
- An Act of God (e.g., a natural disaster);
- An act of the public enemy (military forces in an active war, for example);
- An act or default of the shipper;
- Public authority (e.g., government impoundment); or
- The inherent vice or nature of the goods.
The Identity Theft Reality Check
This is where the trap snaps shut. If a broker sues your carrier authority because an identity thief used your MC number to steal a load, can you say you were an innocent victim of identity theft?
The answer from federal courts has consistently been: No.
Federal case law has made it clear that third-party criminal activity, strategic fraud, and cyber deception do not fall under any of the five common law defenses. Courts reason that organized crime syndicates are not a public enemy (which legally refers to hostile foreign armed forces, not domestic thieves).
In cases such as Northern Refrigerated Transportation, federal courts determined that a motor carrier could not avoid Carmack liability merely by asserting that its digital identity had been hijacked, particularly if the carrier did not safeguard its passwords, was using insecure public email accounts, and did not routinely audit its publicly available SAFER records. If an impersonator presents authentic credentials that you failed to secure, your entity can be held strictly liable in the courts for the full actual replacement value of the lost freight.
Why Contractual Limitations of Liability Fail
Many fleet owners assume that even if they are found liable, their standard tariff or Bill of Lading terms will cap their liability (for instance, limiting payout to $0.50 per pound or $50,000 per trailer).
However, under federal case law – including key appellate rulings like Exel, Inc. v. Southern Refrigerated Transport, Inc. and Donna Karan Co. LLC v. Airgroup – a carrier must satisfy a strict four-prong test before any limitation of liability is legally enforceable:
- Maintain a tariff or schedule of rates available to the shipper upon request;
- Obtain the shipper’s explicit, written agreement to the chosen liability limit;
- Give the shipper a reasonable opportunity to choose between two or more levels of liability (e.g., a lower rate for limited coverage versus a higher rate for full value protection); and
- Issue a valid bill of lading prior to shipment reflecting this choice.
In an identity hijacking case, this test breaks down instantly. Because your actual company never spoke to the shipper, you never provided them with a "reasonable opportunity to choose" rates. As a result, courts routinely throw out liability caps, leaving compromised carriers exposed to judgments for the uncapped, full market value of the cargo.
The Insurance Exclusion Nightmare: "Voluntary Parting"
If strict liability is not painful enough, here is the final kicker: your cargo insurance will probably not cover the loss.
Standard Motor Truck Cargo (MTC) policies were written decades ago to protect against physical accidents – collisions, rollovers, fires, or physical break-ins at truck stops. When a carrier makes a claim for a load that was stolen via identity theft and double brokering, insurance adjusters quickly pull out the fine print of the policy and cite the Voluntary Parting Exclusion (sometimes called False Pretense or Deception Exclusions).
This clause provides that there is no coverage for loss or damage if the freights were voluntarily turned over or delivered to someone else because of fraudulent schemes, tricks, or false pretenses. Since the warehouse employees were sufficiently cooperative to load the truck driven by the secondary driver, the event is classified by the insurer as a voluntary transfer by fraud.
The result? You are left with strict statutory liability to the shipper for $500,000+, and your insurance company hands you a formal claim denial.
The Federal Response: FMCSA’s Motus Platform and Biometric Vetting
Realizing that the legacy URS registration system and static DOT PIN numbers were fundamentally compromised, the FMCSA undertook a massive technological overhaul.
On May 14th, 2026, the FMCSA officially retired its old registration databases and debuted its new digital registration system, Motus, on May 19, 2026.
Motus, from the Latin meaning “movement,” brings all management of motor carriers, brokers, and freight forwarders into one secure dashboard. More importantly, it permanently does away with the vulnerable paper filing processes and static DOT PINs that enabled dark-web hackers to change carrier contact information.
IDEMIA and CLEAR Biometric Authentication
At the heart of Motus’s architecture is government-grade identity verification through technology partners IDEMIA and CLEAR. Under Motus, no new USDOT or MC authority can be granted, and no existing authority registration profiles (such as MCS-150 updates) can be changed without completing an obligatory identity verification check first.
When an authorized fleet representative logs into Motus, they must navigate a multi-layered security protocol:
- Login.gov Authentication: Users sign in using Login.gov backed by mandatory multi-factor authentication (MFA).
- ID Document Capture: Users scan an unexpired government-issued photo ID (a state CDL, driver's license, US passport, or permanent resident card) using a smartphone camera.
- Biometric Facial Scan: IDEMIA’s identity engine prompts the user to take a live "selfie." The software executes real-time facial comparison matching against the physical ID document to ensure the person is physically present and not using a stolen photo or digital deepfake.
- Corporate Cross-Verification: Powered by CLEAR, Motus cross-references the validated individual against IRS Employer Identification Number (EIN) records, state business registry filings, and physical office addresses.
Furthermore, Motus strictly mandates that this verification must be completed by a verified company official (an owner, partner, or corporate officer explicitly named on official corporate organization filings). Third-party dispatchers, external consultants, and process agents (BOC-3 filers) are strictly prohibited from making profile changes without verified entity-level authorization.
| Feature / Security Layer | Legacy FMCSA System (Pre-2026) | Modernized Motus Platform (2026) |
| Authentication Credential | Static 5-digit DOT PIN numbers | Login.gov + Multi-Factor Authentication (MFA) |
| Identity Proofing | Unverified form self-reporting | IDEMIA Biometric Facial Scan & Live ID Verification |
| Business Verification | Manual, unchecked address entries | CLEAR IRS EIN & State Corporate Cross-Matching |
| Authorized System Users | Unrestricted third-party consultants & brokers | Verified "Company Officials" only |
| Processing Medium | Paper forms accepted (until late 2025) | 100% Fully Digital Operations |
While Motus has drastically closed the front door on FMCSA database takeovers, it has created operational friction. Fleet owners who failed to set up Login.gov accounts prior to the May 2026 cutoff or those facing name discrepancies between their CDL and tax filings have experienced paper-recovery backlogs averaging eight business days, briefly freezing their ability to update insurance or make operational changes.
Action Plan: How to Safeguard Your Trucking Identity
As cybercriminals turn their attention away from federal databases and focus their energy on hacking carrier email accounts, phone systems, and load board profiles, you cannot rely on the government to protect your business. Here is the operational action plan every fleet owner and owner operator should implement right away:
Upgrade Your Communication Security
- Ditch Public Email Addresses: If your trucking company is still using @gmail.com, @yahoo.com, or @aol.com, you are inviting an attack. Get a custom business domain (like @yourfleetname.com) and host your email through a professional service with strict security practices.
- Enforce Hardware Multi-Factor Authentication (MFA): Implement MFA on all company emails, transportation management systems (TMS), and load board portals. Try to avoid SMS text verification codes when possible, since phone numbers are subject to spoofing and SIM swapping. Use authenticator apps or hardware security keys.
- Check Email Forwarding Rules: Make it a practice to examine security settings in your email account to look for undetected auto-forward rules or unauthorized login locations. Scammers depend on silent inbox rules to keep you from spotting their activity.
- Secure Business Phone Systems: Secure administrative access on your software-based VoIP phone systems. Make sure call-forwarding rules cannot be altered without multi-factor authorization.
Implement Strict Dispatch Protocols
- Require Outbound Call-Back Verification: Do not accept as valid or reliable a phone number or email address that is provided only on an incoming rate confirmation sheet. When dealing with freight brokers, always verify their contact information through verified industry databases such as Carrier411, Highway, or DAT Directory and make a verification phone call to the number listed there before sending a driver.
- Monitor SAFER and Monitoring Services: Keep active alerts on carrier vetting platforms (such as Highway or RMIS). If someone changes your company contact information without your permission, you will be alerted in hours rather than days.
Review Insurance Policies and Legal Contracts
- Audit Your Cargo Policy for Fraud Exclusions: Sit down with your insurance agent and review your motor truck cargo policy line by line. Inquire about exclusions for voluntary parting, deception, and false pretense. Invest in a policy endorsement that specifies coverage for strategic theft, double broker fraud, and identity hijacking, if available.
- Enforce Carmack Limitation Compliance: Make sure your rate contracts and your Bills of Lading give a clear and explicit choice between levels of liability. A well-drafted, legitimate limitation clause will be your best friend in a lawsuit.
Key Takeaways for Truckers and Fleet Owners
- The identity hijacking is now an industry epidemic: The 2025 cargo theft loss increased 60%, up to $725 million, as the average value of loads stolen in 2026 surpassed $341,000.
- Target Commodities Have Changed: Criminals are stealing identities to target commercial copper (+77%), high-value meats/seafood/nuts (+47%), and high-performance AI server hardware.
- You Face Strict Legal Liability: Under the Carmack Amendment (49 U.S.C. § 14706), carriers have strict statutory liability for lost freight. Identity theft by a third party is not considered a viable legal defense by the courts.
- Insurance coverage gaps exist: The typical MTC insurance policy excludes coverage for fraudulent thefts due to “voluntary parting" provisions, which would leave affected carriers fully exposed.
- FMCSA’s Motus System is Live: Motus was launched in May 2026 and requires IDEMIA biometric facial scanning as well as checks against the corporate database at CLEAR when making any registration changes, effectively killing static DOT PIN vulnerabilities.
- Taking Preventative Steps is now a Must: Move to custom domain emails, require non-SMS multi-factor authentication, secure VoIP phone systems, and confirm brokers through independent broker directories before taking loads.
The Road Ahead: Safeguard Your Authority and Drive with Confidence
At the end of the day, trucking has always been an industry based on trust, hard work, and clear communication. But as our trucks and dispatch systems become more digitally connected, the risks we face evolve beyond the pavement. Identity hijacking not only threatens a freight broker’s bottom line; it attacks the hard-earned reputation and livelihood of professional American carriers.
But by staying informed, locking down your credentials, and verifying every link in your logistics chain, you can keep your authority secure and your fleet moving on ahead safely.