The National Motor Freight Traffic Association (NMFTA) has been preaching for years now that cybersecurity is no longer an IT issue; it’s an industry wide problem that not only includes shipper, broker and carrier operations but everything surrounding them: their vendors, their customers, law enforcement and even the community at large.
The lines between traditional freight fraud and strategic theft have become blurred as technology continues to expand the attack surface for threat actors. Cyber-enabled tactics have caused cargo theft to surge, with losses estimated near $725 million in the U.S. and Canada in 2025 — a 60% increase over 2024, according to the Federal Bureau of Investigation.
Ole Villadsen, a staff threat researcher at cybersecurity company Proofpoint, discovered a substantial amount of malicious email traffic targeting truckers in Fall 2024. Cyber criminals were using compromised email accounts to email truckers malicious links that, if clicked on, would leave behind malware on their computers. A year later, he picked up another trail of a threat actor that was using remote monitoring and management (RMM) tools to access truckers’ computer systems.
This time he was able to link the activity directly to cargo theft, Villadsen said during a presentation of his research this week at the NMFTA Cybersecurity Conference.
“It's amazing how much targeting is going on against transportation right now,” he said.
And cybercriminals have found a new target: Motus, the FMCSA’s new online registration system that launched in May, replacing the outdated Unified Registration System.
The rollout of the system, which has been a rocky one to say the least, has created yet another opportunity for attack. Central Analysis Bureau (CAB), a CCJ sister company, has previously highlighed six issues that have emerged from Motus' clunky rollout.
Shawn Rasmor, principal product manager at Truckstop, said this is the type of disruption bad actors count on.
“They attack when there's volatility, like the Motus rollout,” Rasmor said. “They know people are anxious to lose their authority, and so suddenly there's these emails that look like they're coming from the government.”
Villadsen confirmed this with his research.
He said criminals are sending carriers and brokers emails with fake URLs that guide them to a credential harvesting site disguised as trusted brands like Truckstop.com, DAT Freight & Analytics, Highway and Central Dispatch. It prompts them to enter their username and password and then provides a fake multi-factor authentication code.
“There's someone on the other side looking at that. They're getting notifications that someone is entering all this. They'll use that information within a minute or two on the website that they're impersonating to try to log in and then quickly change everything up so they can control that,” Villadsen said. “We do see some targeting Motus.”
[RELATED: Was FMCSA's Motus site vibe coded?]
The impetus to go forward with Motus was due in part to the rise in freight fraud, though it wasn’t the primary reason, said Federal Motor Carrier Safety Administration (FMCSA) Deputy Administrator Jesse Elison during his address at the NMFTA conference Thursday.
“Motus was so important beyond its statutory requirement, beyond what we owe to the industry. It's critical to combat fraud,” he said. “It's critical to be able to have the vetting process in place that Motus offers that wasn't in place under the disparate eight major platforms, which didn't talk to each other, and which bad actors had various entry points into.”
Elison said the significance of freight fraud has garnered support from the U.S. Department of Transportation for FMCSA’s efforts to mitigate it. He highlighted some of that ongoing work, including the crackdown on CDL mills, changes to the ELD vetting process and Motus.
He admitted Motus is not where it needs to be, noting the difficulties in getting it off the ground.
“Despite having a high level of confidence when we did launch, those following weeks were really tough because what we had built wasn't working, and every time we tried to fix it, it worked less,” Elison said.
He said the biggest challenge has been ensuring all the relevant data is accurately reflected in the new system, adding that FMCSA has made great strides in the last couple of months.
The goal, he said, is for the user experience to be seamless within a matter of weeks but noted that shoring up the backend will be an ongoing process, though he expects work to be complete well within a year’s time.
“We have the right teams in place, and we've been really fortunate with how things have worked to be able to manage that kind of a crisis, given the limitations with how government works,” Elison said. “Sometime in the future, maybe that story will be told. But we were really fortunate and going in the right direction.”
























