Cybersecurity threats trucking fleets need to know about

Ashley Barber Headshot

Following more than $111 million in cargo theft losses in late 2025, an NMFTA report warns that trucking carriers face mounting risks from AI-assisted phishing, vulnerable APIs and looming federal reporting rules.

  • Digital compromise drives physical freight theft: Attackers frequently exploit stolen credentials, compromised load boards and fraudulent carrier identities to facilitate cargo theft before fleets realize a crime is occurring.
  • AI and automation amplify scam sophistication: Threat actors are using artificial intelligence to craft convincing phishing lures and bypass traditional visual "red flags," making out-of-band verification essential.
  • Expanding technology widens the attack surface: Connected trucks, telematics, APIs and third-party SaaS vendors integrate vehicle operations with corporate networks, leaving fleets vulnerable to upstream supply chain breaches.
  • Preparation and compliance are nonnegotiable: With upcoming CIRCIA federal incident-reporting mandates, carriers must deploy multifactor authentication, audit vendor access and build business-continuity plans for critical system outages.

For a long time, cybersecurity was something many trucking companies left to the IT department. Keep the servers secure, make employees take an annual training course and move on to the next priority. That approach doesn't work as well anymore. 

Cyberattacks against carriers aren't limited to stealing information. Criminals are using compromised accounts and systems to target freight, commit fraud, access financial information and disrupt operations. In some cases, gaining access to a company's systems is simply the first step toward a larger crime.

The National Motor Freight Traffic Association’s 2026 Transportation Industry Cybersecurity Trends Report describes a transportation threat environment that is becoming faster, more automated and more targeted. The report points to AI-assisted attacks, automated attack activity, misuse of legitimate access tools and APIs, third-party vulnerabilities and the growing connection between cybersecurity and physical operations.

"Throughout 2025, transportation organizations saw more concrete examples of how cyber risks can intersect with operational systems," said Joe Ohr, NMFTA chief operating officer, when the report was released. He said increased visibility creates an opportunity for the industry to take a more proactive approach to cybersecurity.

NMFTA Director of Cybersecurity Artie Crawford also highlighted the connection between digital compromise and physical losses, noting that digital compromise can be the prelude to physical loss. For carriers, brokers and fleet managers, cybersecurity is now tied directly to freight, finances, employees, customers and keeping the business running.

Cybercrime, cargo theft are converging

Cybercrime and cargo theft are increasingly connected.

A stolen password, compromised load-board account or fraudulent carrier identity can provide criminals with information they can use to target freight. The digital side of the crime may happen before anyone realizes a physical theft is being planned. CargoNet recorded 772 cargo theft events across the United States and Canada during the third quarter of 2025. The value of stolen goods reached $111.88 million, driven in part by organized groups targeting high-value shipments. CargoNet also reported that criminals were adapting their methods and placing greater emphasis on targeted information gathering.

Partner Insights
Information to advance your business from industry suppliers
Run Your Fleet. Not Your Tire Program
Presented by Michelin North America

For carriers, the consequences can extend well beyond the value of the stolen freight. A company may also have to deal with fraudulent transactions, identity issues, disputes with brokers and customers, and delays in getting paid. Cybersecurity therefore has a direct connection to cargo security.

Smaller fleets shouldn't assume they're too small to target

A lot of cybersecurity attention goes toward large companies with large amounts of data and sophisticated IT environments. Smaller fleets may have fewer security resources and fewer people dedicated to monitoring systems. Employees may also have broad responsibilities and rely heavily on established relationships with brokers, customers, drivers and vendors.

That creates opportunities for social engineering. An attacker doesn't necessarily need to break through a sophisticated technical defense; a compromised account can expose customer information, shipment details, financial records or access to other systems.

AI making scams harder to spot

Phishing emails used to have some obvious warning signs. Poor grammar, generic messages, strange email addresses and unusual wording often gave them away. That advantage is disappearing.

NMFTA identifies AI-augmented attack techniques as one of the major cybersecurity trends affecting transportation. AI can make it easier for attackers to create convincing messages and automate parts of an attack.

The same problem applies to impersonation. Information that is publicly available or obtained through previous compromises can be used to make a request appear legitimate. That makes traditional security awareness training less effective on its own. Employees can't always be expected to recognize a scam simply because something "doesn't look right."

Verification needs to become part of the process. A request to change banking information should be independently confirmed. The same should apply to unusual load instructions. Don't simply reply to the email or call the number included in the message. Use a known phone number or another established method of communication.

Connected trucks widen the attack surface

Trucks today are connected to considerably more technology than they were in the past. Telematics, routing applications, maintenance systems, mobile applications, APIs and cloud platforms exchange information across multiple systems. That connectivity provides significant operational benefits, but it also creates additional security considerations.

NMFTA specifically identifies the increased use of legitimate access tools and APIs as an expanding area of concern. The more systems that communicate with one another, the more important it becomes to understand what access those connections provide and how they are protected.

The distinction between a company's traditional IT environment and the technology supporting its vehicles is becoming less clear. That means cybersecurity teams need visibility into systems that may previously have been considered outside the traditional IT environment.

Ransomware isn't going away

Ransomware remains a serious concern for transportation companies. NMFTA's 2026 report points to the growth and fragmentation of ransomware activity, along with the use of automation and other techniques that can make attacks more difficult to detect and stop.

For a carrier, the operational consequences can be significant. If dispatch, billing, maintenance, communications or other critical systems become unavailable, the company may have difficulty moving freight or handling basic business functions. That is why ransomware preparation can't be limited to restoring files. Companies also need to understand how they would continue operating if critical systems were unavailable.

Vendors are part of your attack surface

Most trucking companies depend on a collection of technology providers. A fleet might use separate systems for dispatch, telematics, load boards, accounting, billing, maintenance, customer communication and other connected functions, creating a risk that doesn't necessarily originate inside the carrier.

NMFTA specifically identifies supply chain trust exploitation and dependencies on third-party SaaS platforms and integrations as important cybersecurity concerns. A company can have strong security practices and still be affected by a problem at one of its technology providers.

Companies should understand what information a vendor can access, how systems are connected, how security incidents are handled and what happens if the vendor becomes unavailable.

Cybersecurity requirements are changing

Cybersecurity is also becoming more closely tied to regulatory requirements. The Cyber Incident Reporting for Critical Infrastructure Act establishes a framework for certain covered entities to report significant cyber incidents and ransomware payments to the Cybersecurity and Infrastructure Security Agency.

However, it is important to distinguish between the law and the final reporting regulations. As of 2026, CISA was still working toward finalizing the implementing rule. CISA has stated that once the final rule is implemented, covered organizations will be required to report certain cyber incidents within 72 hours and qualifying ransom payments within 24 hours.

Not every trucking company will necessarily fall within CIRCIA's definition of a covered entity. The broader lesson still applies: Companies need to be able to recognize an incident, determine what happened, document it and respond quickly. Waiting days to determine who is responsible or which systems are affected is not a good position to be in during a serious cyberattack.

What fleets should actually do

There isn't one piece of software that will solve the problem. The strongest approach combines security technology with good processes and employees who know how to respond when something doesn't look right.

A few areas deserve attention:

  • Verify before acting. Payment changes, banking updates, load reassignments, password resets and other unusual requests should be confirmed through an independent communication channel.
  • Lock down accounts. Multifactor authentication should be enabled wherever possible, particularly for email, Federal Motor Carrier Safety Administration accounts, load boards, dispatch systems and applications containing financial information.
  • Vet your vendors. Find out what security controls vendors have in place, what information they can access, how systems connect and what happens if the vendor experiences a security incident.
  • Have an incident-response plan. Employees should know whom to contact when something goes wrong. Management should know how systems will be isolated, who communicates with customers and vendors, and how critical operations will be restored.
  • Keep training current. Employees need to understand that scams don't just arrive through email. Phone calls, text messages and other communication channels can also be used to impersonate people they know.
  • Know what's connected to your environment. Maintain an inventory of applications, devices, APIs and vendor connections. It is difficult to protect systems that aren't being tracked.
  • Plan for operating without critical systems. Cybersecurity planning should include business continuity. Know how dispatch, billing, communications and other essential functions would be handled if a system became unavailable.

Cybersecurity has become another operational risk that trucking companies must manage. A compromised login can contribute to freight fraud. A problem with a technology provider can affect critical operations. A ransomware attack can bring normal business activity to a halt.

The question for trucking companies isn't whether cybersecurity belongs in operations anymore — it does. The more important question is whether the company knows what it will do when the next incident happens.