Supply chain collaboration, human judgment and digital security combat cargo theft

Load boards are the hunting grounds of threat actors, said GenLogs director of partnerships Danielle Spinelli.

Spinelli, who launched her career in the freight industry as a broker and now works on the technology vendor side, said criminals will impersonate a carrier and claim technical issues are preventing them from accessing the carrier packet brokers use for vetting and onboarding. Alternatively, they will send an email with a PDF of their documents, and because the carrier is expecting that email, they’re more likely to click on the attachment, which then installs malware on the broker’s computer that lurks in the background, waiting to pounce on a high-value load.

“They’re hunting,” Spinelli said Wednesday during a panel that discussed cybersecurity’s role in preventing cargo theft at the annual National Motor Freight Traffic Association Cybersecurity Conference held in Long Beach, California.

Ole Villadsen is a hunter but for the good guys. The staff threat researcher at cybersecurity company Proofpoint has discovered about 15 different groups that are actively targeting the transportation industry with malware, remote monitoring and management (RMM) tools and/or credential phishing with the intent to steal cargo.

Cargo theft is expected to increase in the second half of 2026, according to Overhaul’s Q2 2026 U.S. Cargo Theft Report, which tracked 605 incidents, up 5% from Q1. As the regulatory and economic environments shift, experts at the NMFTA conference expressed how essential it will be for each segment of the freight industry to collaborate and accept a shared responsibility for security.

Shawn Rasmor, principal product manager at Truckstop, said he wants to see improvement in communication and transparency across the supply chain to mitigate theft and its impact on the industry and the economy as a whole.

“We need to improve that and have everyone playing a role in understanding who is supposed to be getting this (cargo). I'm going to make sure I know who's going to get it next, and I own it until I give it to the next party,” Rasmor said. “It's blockchain but from a human standpoint … It’s that accountability across the ecosystem.”

Partner Insights
Information to advance your business from industry suppliers

Taking it slow

During his session, Villadsen displayed several real emails that illustrated cyberattacks, along with one carrier’s account of an attack that was posted to Reddit a year ago.

On the flip side of Spinelli’s earlier example, that carrier explained how its dispatcher — in a rush — clicked a malicious “setup” link delivered via email from a cybercriminal impersonating a broker. The resulting webpage requested he install remote access and an EXE file.

Though the carrier didn’t move forward with the load, it was too late. The hacker had accessed the dispatcher’s accounts and set out to book loads using the carrier’s credentials.

Beyond the fundamentals of cybersecurity like multi-factor authentication and password variation, Villadsen said, “Slow down,” noting the importance of verifying all the sender's domains. “Every email that's coming in the door is potentially malicious, especially in this industry.”

He said carriers are an easy target because the majority are small businesses with limited security in place, and the urgency that is often pushed in phishing emails is already built into the competition for loads. Transported Asset Protection Association Chairman Scott Cornell emphasized that point, saying, “I always hear, ‘We're trying to move the freight in a timely manner,’ and I say … ‘Fast is good, but slow is accurate.’”

Spinelli added that she is concerned cargo theft numbers will spike because of shrinking truck and driver capacity in the market, leading brokers to forego vetting as it gets harder to cover a truck.

Fighting fire with fire

Spinelli shared the story of a driver who showed up in a truck that didn’t have the correct red hue that the shipper was accustomed to seeing. That small difference triggered a red flag, and it was found that the truck had a fake VIN plate.

It took human judgment to prevent that attempt from succeeding.

“The two need to be together: digital front and physical front. That's how we combat this,” she said. “You need somebody there looking at things and having that Spidey sense; then have the tech there to throw up the signals for you.”

That’s because freight fraud, though still physical, is also now digital.

Cornell said the top location for theft is the warehouse, but it isn’t a burglary like the old days. It’s a bad guy — or a good guy being manipulated by a bad guy — tricking shippers into handing over real freight by impersonating a carrier (typically through digital means).

He noted that the shipper is the biggest gap in the industry right now.

“I always say ‘bad guys are like rainwater running down your roof. They're just looking for the first crack that they can pour into, and they found that crack,” Cornell said. “That's the crack,” and that’s why collaboration is key.

“There is nothing we can do to solve cargo theft. Cargo theft is never going away. That needs to be clear,” he added. “But we can certainly make it more difficult. We can certainly minimize it. We can certainly have an impact on it.”

Angel Coker Jones is a senior editor of Commercial Carrier Journal, covering the technology, safety and business segments. In her free time, she enjoys hiking and kayaking, horseback riding, foraging for medicinal plants and napping. She also enjoys traveling to new places to try local food, beer and wine. Reach her at [email protected].