The most valuable thing in your office is not a truck or a customer list — it is the password to your load board. Cargo thieves stopped needing bolt cutters. They need one dispatcher to click one link in one email that looks like a broker asking you to review a service rating. Federal investigators spent this year warning about exactly that pattern, and the loss numbers behind it are the worst on record. Here is how the compromise actually happens and the checklist that closes the door.
How the Login Becomes the Load
The FBI’s Internet Crime Complaint Center issued a public service announcement on April 30, 2026 describing a surge in cyber-enabled strategic cargo theft. The mechanics are worth knowing in order, because each step is a place you can break the chain.
First, a spoofed email arrives appearing to come from a broker — typically with a link to a “carrier broker agreement” or an invitation to review a poor service rating. The link is shortened and points to a spoofed site imitating a real one. That site delivers a file that quietly installs legitimate remote monitoring and management software, which hands the attacker undetected access to the machine. From there they read your email, learn your customers and your voice, and take over accounts. As CDLLife reported on the same warning, the payoff is posting fraudulent listings on load boards and bidding on real shipments using hijacked carrier identities — then altering documents and rerouting the freight.
Notice what this defeats. Every carrier-vetting step you run — authority, insurance, safety rating — checks out, because the criminal is using a real, clean carrier’s credentials. The verification has to happen at the identity layer, not the paperwork layer.
The Numbers Behind the Warning
The FBI pointed to a 60% surge in cargo theft losses across the U.S. and Canada in 2025 over 2024, with losses estimated at $725 million. The second-quarter picture this year is stranger and more instructive: Verisk CargoNet documented 677 supply chain theft incidents in Q2 2026, a 26% decline from a year earlier — while total estimated losses more than doubled to $304.6 million, with an average reported loss of $564,009 among thefts with a stated commodity value.
Fewer thefts, far bigger hits. CargoNet also noted that while physical theft of loaded equipment fell, compromise-based schemes like business email fraud and shipment misdirection continued at a steady clip. That is the shape of a professionalized threat: fewer opportunistic grabs, more targeted operations that start with a stolen credential.
Familiar names or email addresses alone do not confirm authenticity; validate unexpected communications through a two-factor authentication process.
FBI Internet Crime Complaint Center, April 30, 2026
The Account-Hardening Checklist
- Turn on multi-factor authentication everywhere, today. Email first, then every load board, your TMS, your factoring portal and your FMCSA Portal login. Prefer an authenticator app over SMS, because SIM swaps are part of the same playbook.
- Give every account its own password. Reuse is what turns one breach into five. A password manager makes this a ten-minute setup instead of a discipline problem.
- Never click a link in an unexpected email about an agreement, a rating or a payment change. Open the load board or broker portal yourself from a bookmark and look for the notice there. If it does not exist in the portal, it does not exist.
- Verify any banking or remit-to change by phone — using the number in your own records. Not the number in the email signature. A change to where money goes is the highest-risk event in your week and deserves a callback every single time.
- Refuse to install remote-access software on request. No legitimate broker, factor or load board ever needs you to download an executable to fix a rating dispute. That request alone is the tell.
- Lock down your DOT/MC identity. Keep the FMCSA Portal PIN and login off shared inboxes, review who has access, and monitor your carrier’s authority record for unauthorized address or contact changes — those edits are how a hijack gets set up.
- Audit account access monthly. Remove former VAs, contractors and drivers from every system the day they leave. Check the login history and active sessions on your load board accounts while you are in there.
- Separate accounts by function. The email address you post publicly should not be the one that recovers your banking or load board passwords.
- Write down the incident plan before you need it. Who you call, in what order, if you suspect a compromise: load board security line, factoring company, affected brokers, then a report to IC3. Thirty minutes matters.
Red Flags That an Account Is Already Compromised
Compromise is quiet by design. Watch for mail rules you did not create — especially ones that forward or auto-delete messages from brokers or your factor. Watch for sent-items gaps, replies to threads you never saw, or a broker referencing a conversation you do not remember. Watch for load board logins from unfamiliar locations, bids posted under your account that you did not place, and a sudden increase in “verification” calls from brokers about loads you never booked. Any one of those means you change passwords from a different device and start calling.
Industry security groups including the National Motor Freight Traffic Association publish free cybersecurity guidance aimed at exactly this problem for small operations. It is worth an hour of your time; the alternative education is much more expensive.
What to Do in the Next Hour
Pick the three accounts that would hurt most if someone else controlled them — for most independent dispatchers that is email, the primary load board, and the factoring portal — and turn on multi-factor authentication on all three before you book another load. Then open your email settings and read every forwarding rule and filter. Those two steps take under thirty minutes and close the most common path in the FBI’s description.
After that, put a monthly access audit on the calendar and tell your carriers what your verification standard is, in writing: no banking changes without a callback to a known number, no software installs, no exceptions for urgency. Urgency is the pressure the criminal is manufacturing. A dispatcher who is boringly consistent about verification is a bad target — and in a year where the average reported theft runs well into six figures, being a bad target is the entire strategy.