The most expensive fraud in freight right now does not touch the trailer at all — it touches the remittance. The load picks up on time, delivers clean, the POD is signed, and six weeks later the carrier finds out the check went to someone else’s bank account because a broker received a very convincing email asking to update payment details. Verisk CargoNet’s Q2 2026 data makes the pattern explicit: business email compromise is now the top access point for the most sophisticated schemes. Here is the protocol that stops it.
Why the Money Is the Target Now
Cargo theft incidents actually fell 26 percent year over year in the second quarter of 2026, to 677 events. Losses went the other way, more than doubling to $304.6 million from $135.7 million, according to Verisk CargoNet’s Q2 theft trends. The average loss on a theft with a reported value hit $564,009, up 177 percent from $203,586 a year earlier.
Fewer thefts, far bigger hits. That happens when criminals stop cutting fences and start compromising inboxes. A hacked account hands them shipment details, contact lists, and portal logins — everything needed to impersonate a broker or a carrier and redirect either the freight or the payment, as FreightCaviar summarized in its breakdown of the CargoNet numbers.
Lower incident volume should not be mistaken for lower risk.
Keith Lewis, VP of Operations, Verisk CargoNet
How a Fake NOA Actually Works
A notice of assignment is the document a factoring company sends telling a broker that a carrier’s receivables have been assigned and payment must go to the factor. It is routine, it arrives by email, it carries a logo, and almost nobody verifies it. That combination is why it has become a preferred instrument for payment-redirection fraud.
The three common variants: a fraudulent NOA sent in the name of a real factoring company but with different remit-to details; a fake release letter claiming a carrier has left its factor, so payment should now go direct to a new account; and a plain banking-change request that appears to come from the carrier’s own domain after that inbox has been compromised. All three look like paperwork, not like theft. As England Logistics has documented, the giveaway is almost never the document — it is the channel it arrived through.
The Verification Checklist
- Treat every payment-detail change as unverified until proven otherwise. No exceptions for urgency, for a familiar name, or for a signature block that looks right. Urgency is the tell, not the excuse.
- Call back on a number you already had, never the number in the email or on the letterhead. Spoofed caller ID and cloned signature blocks are standard tooling now, per Highway’s Freight Fraud Index.
- Verify the NOA directly with the factoring company, using the factor’s published main line — not a contact on the notice. Ask them to confirm the client relationship and the remit-to account.
- Demand a release letter for any "we left our factor" claim, and verify that release with the outgoing factor. A carrier cannot unilaterally redirect assigned receivables, and a factor will tell you plainly whether the assignment is still in force.
- Check the sending domain character by character. Lookalike domains with a swapped letter or an added hyphen are the most common delivery vehicle, and they survive a quick glance every time.
- Impose a 24-hour cooling period on any banking change, and notify the carrier through a second channel — a phone call to the number on file, not a reply to the email.
- Never accept a banking change on the same day as a large invoice. The timing of a change relative to a big receivable is one of the strongest signals available to you.
Protect the Inbox That Makes the Fraud Possible
The verification protocol above only helps if you are the one being asked. If your own mailbox is compromised, the fraud is committed in your name and you find out from an angry carrier. Turn on multifactor authentication on email and every load-board and portal account, review forwarding rules and delegate access monthly (attackers create a quiet forwarding rule and read your mail for weeks), and keep the FMCSA-listed contact information for the carriers you dispatch accurate — FMCSA contact manipulation is a known technique for making a stolen identity look verified.
One more piece of hygiene that costs nothing: put your remit-to instructions in a fixed, unchanging place — on your rate confirmation template and your invoice footer — with a stated policy that they will never change by email. Making your process predictable makes any deviation from it obvious, which is a defense you can extend to every broker you work with. Denim’s guide to freight fraud is a solid reference for tightening the rest of the payment chain.
What to Do Today
Write the seven checklist items into a one-page document, put it where whoever handles your invoicing can see it, and add one line to your standing carrier agreement: banking and remit-to details will only be changed after a verified voice callback to the number on file, with a 24-hour hold. Then call each of your carriers’ factoring companies once and record the correct main line and remit-to details somewhere you control. That is a ninety-minute job. The average loss it prevents is measured in six figures.
If you suspect a redirected payment has already occurred, stop the wire with your bank immediately, notify the factoring company and the broker in writing the same day, and file with the FBI’s Internet Crime Complaint Center — recovery odds fall sharply after the first 72 hours.