A hot topic at the moment in the world of freight is the concerning rise in fraudulent freight activity, including carrier identity theft that often doesn’t look fraudulent at all. Criminals or “bad actors” as we often call them in freight, are becoming much more sophisticated at impersonating legitimate carriers, compromising genuine accounts and using authentic information to access shipments. The FBI have warned that cyber-enabled strategic cargo theft is being used to impersonate legitimate businesses, access real freight and redirect shipments. In 2025, estimated cargo theft losses across the United States and Canada reached nearly $725 million, but these figures are skewed slightly as that is just the number of incidents that were reported. The true financial impact could be considerably higher, as cargo theft and freight fraud often go unreported.
This is because businesses in logistics and haulage may not want to publicise theft incidents, because of concerns around higher insurance bills, customer relationships, reputational damage, and wider consequences of stolen shipments. When this happens, if the the company can, they usually absorb the financial loss themselves.
So, it leaves the difficult question for shippers. If the carrier collecting your freight looks legitimate, how do you really know who you’re handing your cargo to?
It’s a question that repeatedly came up at our National Agency Meeting this year and we wanted to bring more light on the current challenges shippers, carriers and brokers are facing. So, in this blog, we will discuss carrier identity theft, how it slots into the wider freight fraud landscape and what shippers can do to reduce their exposure to the growing problem.
What Is Carrier Identity Theft In Freight?
Carrier identity theft is like any other identity theft, someone impersonating another. But the FMCSA describes broker and carrier identity theft as the unauthorised use of identity, credentials or operating information of a legitimate motor carrier to gain access to freight or carry out fraudulent activity.
In this day and age, fraudsters don’t even need to set up a fake trucking company, which in the past would have been a lot easier to detect. It’s quite scary, because as the FMCSA also speaks of how they’re using real carrier USDOT numbers, MC numbers, business information, email identities or compromised accounts to appear legitimate. Meaning that the carrier being represented may well be a genuine operating business, but the person behind the communication might not be.
This adds another layer of complexity when shippers are doing their due diligence. Checking that a carrier exists is important, but not enough on its own anymore. The real challenge now is verifying that the person booking your load, communicating with you, or arriving to collect your freight genuinely represents the carrier that you believe you’re working with.
When Freight Fraud Looks Legitimate
A common and more traditional perception of cargo theft, is that it is someone physically stealing your freight at a truck stop or similar. However, the modern reality is that freight can be stolen by someone convincingly pretending to be authorised to collect it. This is what makes carrier identity theft particularly dangerous.
Traditional freight theft still happens, but modern freight fraud can look very different. Like we’ve briefly mentioned above, criminals can now use genuine carrier information, all of the business details might check out like carrier name, USDOT, MC number, but the person you’re communicating with might have nothing to do with the business at all!
The person communicating with you may appear to know the industry, understand the shipment, and have all information you’d expect a genuine logistics partner to have. In some of the more elaborate schemes, the criminal might even gain access to genuine email accounts or carrier profiles, making the usual warning signs harder to spot, which we will go into more detail on below.
So if everything seems legitimate on the surface, how’re they doing it and what should shippers look out for?
Stolen Credentials
Many freight fraud criminals hijack existing carrier profiles on load boards or misuse real carrier identifiers, USDOT numbers, and MC numbers taken from public databases. Some even offer legitimate carriers and brokers money to buy their disused credentials.
How To Combat Stolen Credentials?
Don’t rely solely on MC and USDOT numbers. Use a carrier vetting platform like Highway to verify the identity of the person behind the carrier profile and check that they’re genuinely authorised to act on that carriers behalf. Working with a responsible freight partner like us at PEI can save you time, and assist in choosing a reliable and vetted carrier.
Forged Documents
Bad actors have begun using AI tools to quickly manufacture fake insurance certificates, liability policies, and compliance paperwork, and billings.
How To Combat Forged Documents?
Forged documents can be made in a variety of ways, but if you suspect a document has been generated or modified with AI you can check using that document’s meta data. You can do this by manually checking, below are instructions ⬇️
Windows
- Right-click the file.
- Select Properties.
- Open the Details tab.
- Check fields such as Author, Created, Modified, Software and Application.
Mac
- Right-click the file.
- Select Get Info.
- Review the More Info and date fields.
- For PDFs or images, open the file in Preview → Tools → Show Inspector for additional metadata.
Tip: Look for unusual software names, recent creation/modification dates, missing author information or details that don’t match the document’s claimed origin.
Spoofing
Spoofing is when “bad actors” imitate a person or organisation with the intent to deceive. This comes in many different forms, most commonly and often most effectively by creating email domains very similar to a legitimate business or organisation.
With this in mind, it’s important to also discuss a tactic that some fraudsters use taking it one step even further. That is using something called a lookalike character from other alphabets to again imitate legitimate business domains, these are known as homograph attacks. So not all fake email addresses contain more obvious spelling mistakes. For example a Latin “a” and a Cyrillic “a” can appear identical, despite being technically different, but almost impossible to spot.
How To Combat Spoofing?
If you are worried about homograph attacks, then click through this link to a guide all about how homograph attacks work. There is also a tool available on the website that uses punycode to help detect scam email addresses using other alphabets MailTester.com
Phishing
Phishing is often the first step used by hackers to infiltrate a person or an organisations private accounts. This could be email, bank accounts, social media, and many more. What many people chalk up to “hacking” is usually a fairly simple trick, it often involves sending clickable links to fake login pages. Once on these fake pages a user might unknowingly put in their account details at which point the scammer now has a record of that users real login details for that account.
Phishing works in different ways, but a very common trick is one of manufactured urgency. This is where they will send a seemingly legitimate email from, for example a bank with the subject “fraudulent activity detected on your account”. The email will then use urgency to get you to act fast, pressuring you to login through a their own phishing link. This phishing link might take you to a page which mimics the real banks login page.
But, not all phishing emails are designed to create panic. In freight the most convincing phishing attempts work because they look completely normal. So many documents move between shippers, brokers, and carriers every day so receiving an email with the subject “Rate confirmation – Load #87346” along with a simple message asking you to review attached documents might not immediately raise red flags. But those documents could contain malicious software, and a link to “view” or “sign” could instead direct the recipient to a fake Microsoft 365, Google or document sharing login page designed to steal credentials. These attacks are even more convincing when the criminals know an employee name, load number, route or customer, giving the recipient even less reasons to question it.
How To Combat Phishing?
To avoid falling for phishing scams, never click any links in emails or messages without being certain of their authenticity. If you’re ever unsure go directly to the official website or app, alternatively, pick up the phone and call an official verified phone number, never one from a suspicious email.
Thread Interception
This is when a “bad actor” already has access to a broker, carrier or shippers email account. They could have gained access to these email accounts through hacking or a phishing scam. With access, they intercept active email threads and wait for an opportunity to act. There are two main objectives from thread interception including:
- Sending updated invoices with their payment details. This results in funds being diverted to their bank accounts instead of the legitimate parties.
- Changing delivery addresses. This reroutes a shipment to a location controlled by the fraudster, once delivered to the new address, the scammer can then steal the goods without a trace.
How To Combat Thread Interception?
Here’s the important part, this scam is so sophisticated, because unless you know you that have been hacked there are no clear signs that anything is afoul. So instead of looking for other signs like spoofed emails, be vigilant and pay attention when either someone in yours, your vendors or your customers organisation suddenly requests changes to invoices, other documentation or pickup and delivery addresses.
See example of thread interception below ⬇️

Off Platform Communication
Many fraudsters contact brokers via spoofed emails and pressure them to move the conversation away from secure logistics platforms.
How To Combat Off Platform Communication?
Never take work communications off platform. We’re not talking about arranging a coffee date with your desk buddy. But when it comes to organising shipments, payments, documents or delivery changes, keep the conversation on the relevant apps, software, and platforms.
If someone suddenly asks you to move the conversation elsewhere, especially to text message, whatsapp, a personal email or an unfamiliar messaging app then treat it as a red flag and verify who you’re speaking with before continuing conversations.
How To Minimize Your Exposure To Freight Fraud & Identity Theft

At PEI we’ve developed an internal motto: stop, check, protect. The idea is simple, our team always take a moment to pause when anything, no matter how trivial, seems unusual. As we’ve shared with you in this blog, we have trained ourselves to look out for and identify risks of fraud, in order to thoroughly protect ourselves and our customers.
1. Stop
Trust your gut, it’s usually right. If something feels off, or there’s a sudden change in request of a shipment, i.e. delivery location, contact information, email address, or bank details, etc. Then these should be BIG red flags 🚩 and enough to make you stop before taking any further action. Fraudsters rely on people making hasty decisions, so take your time.
2. Check
Do your due diligence, if you suspect foul play, independently verify any requests extensively. Check email domains carefully, review carrier information and contact the customer, carrier or vendor using details you already know to be genuine, not via the phone number or link contained within a suspicious message. Confirm everything.
3. Protect
If you think you have identified fraudulent activity, you must act immediately. Alert your colleagues, partners, vendors and customers as soon as possible and prevent any possible transactions from progressing. Do not release the freight and do not make any payment until the issue is resolved. If you believe an account may have been compromised, involve your IT team, secure affected accounts and alert the legitimate parties involved through verified communication channels. You or your IT team may need to change passwords, revoke suspicious sessions and enable/reset MFA (multi-factor authentication).
The main takeaway is that the challenge with freight fraud and carrier identity theft isn’t always about identifying a fake carrier. Sometimes it’s identifying a fake person operating behind a real carrier’s identity. Therefore, the fraudulent element may be very well hidden inside what would otherwise appear to be a normal transaction. But these fraudulent activities can have detrimental consequences for your business.
So remember whenever you suspect fraud…Stop. Check. Protect.
Need help planning a shipment?
Talk with PEI about expedited freight, specialized freight, or your next shipping challenge.