Freight Fraud Is Now a Board-Level Risk for Importers
Supply chain crime is no longer a trucking industry problem that importers can leave to their carriers and forwarders. In the second quarter of 2026, Verisk's CargoNet unit recorded 677 cargo theft incidents in the United States, down 26% from the prior year, but the estimated dollar losses more than doubled to $304.6 million. For all of 2025, total supply chain crime losses reached nearly $725 million, a 60% jump from 2024. The pattern is clear: fewer incidents, but each one is bigger, more organized, and more likely to involve technology rather than a crowbar and a dark parking lot.
The shift that matters most for importers is where the fraud now originates. Organized groups increasingly compromise a single business email account or freight platform login and use that access to touch multiple parts of the shipment lifecycle: rerouting a load, redirecting a payment, or booking a pickup under a stolen carrier identity with no intent to deliver. A theft that used to require physical access to a yard now starts with a phishing email to your logistics coordinator or a spoofed invoice to your accounts payable team.
For importers moving 5 or more containers a month, this matters because the exposure is direct. You are not a passive party protected by your carrier's insurance. Fraudulent diversions hit your inventory, fake carriers disappear with your goods, and business email compromise schemes drain your payment accounts directly. Cargo insurance covers some of this, but not fraud committed by a party you unknowingly authorized, and not the customer relationships and revenue you lose while goods sit missing.
This guide covers the technology and process controls that close the gaps fraud rings exploit: carrier identity verification before booking, payment workflow controls that stop business email compromise, visibility data configured as a fraud detection layer, access controls that limit what a compromised login can do, and an incident response protocol for when something goes wrong anyway. None of this requires a security team. It requires configuring the tools you likely already have correctly, and adding two or three narrow-purpose verification steps that fraud rings are betting you will skip.
The Four Fraud Vectors Targeting High-Volume Importers
Freight fraud schemes have consolidated around four patterns. Understanding which one is hitting you determines which controls actually stop it. Generic "be careful" advice fails because each vector requires a different technical fix.
Carrier identity theft and double brokering
A fraud ring obtains the MC number, DOT number, and insurance certificate of a legitimate, reputable carrier, often by purchasing dormant operating authorities or compromising a small carrier's credentials. They then present themselves as that carrier to book your load, either directly or by inserting themselves into a load board transaction as an unauthorized second broker. The truck that shows up may look legitimate. The paperwork may look legitimate. The load never arrives, or arrives at the wrong destination for resale.
Business email compromise and invoice redirection
An attacker compromises or spoofs the email account of your supplier, your forwarder, or your own accounts payable staff, then inserts themselves into an active conversation about an invoice or a wire transfer. The email looks like it comes from a known, trusted contact, often mid-thread in a real conversation the attacker has been silently monitoring for weeks. The request is simple: update the bank account on file before the next payment. By the time anyone notices, the funds are gone and unrecoverable in most jurisdictions within 72 hours.
Account takeover of TMS and freight platform logins
Credential theft, often through phishing or credential-stuffing attacks using passwords leaked in unrelated breaches, gives an attacker direct access to your transportation management system, your forwarder's client portal, or your customs broker's filing system. From inside, they can reroute shipments, change delivery addresses, download your full customer and supplier list, or approve fraudulent bookings that look routine because they originate from a legitimate, authenticated account.
Targeted cargo theft from operational data leaks
The highest-value thefts in 2026 increasingly target specific high-value shipments rather than opportunistic hits. This requires the thieves to know what is moving, when, and where, information that leaks through compromised tracking portals, careless sharing of shipment manifests, or social engineering of warehouse and drayage staff. Electronics, pharmaceuticals, and specialty metals are the most targeted categories because of resale value and because their supply chains generate the most predictable, trackable data trails.
Every control in this guide maps back to one of these four vectors. Before investing in any anti-fraud tool, identify which vector represents your actual exposure. An importer sourcing exclusively through long-standing supplier relationships with wire transfers has different priorities than one running a marketplace of spot-market carriers for domestic drayage.
Want to see how Cubic compares to your current forwarder?
Carrier and Forwarder Identity Verification: Closing the Double-Brokering Gap
Double brokering and carrier impersonation succeed for one reason: verification is treated as optional friction rather than a mandatory gate. The fix is not complicated. It takes under 5 minutes per new carrier relationship and should never be skipped, regardless of how much time pressure a booking is under.
The minimum verification checklist
- MC and DOT number cross-check: Confirm the carrier's operating authority is active, not revoked, and matches the company name on the quote using the FMCSA SAFER system. A mismatch between the name on the paperwork and the name on file is the single most common red flag and the easiest to catch.
- Insurance certificate validation: Request a current certificate of insurance directly from the carrier's insurance broker, not from the carrier itself. Fraudulent carriers frequently present forged or expired certificates because they know most shippers never call the issuing broker to confirm.
- Authority tenure check: Operating authorities registered within the last 6 months carry meaningfully higher fraud risk. This does not mean rejecting new carriers, but it means applying additional verification steps, including a call-back to a phone number independently sourced from FMCSA records rather than the number on the carrier's paperwork.
- Call-back verification for first-time carriers: Before the first pickup with any new carrier, call the phone number listed in the FMCSA registration, not the number provided in the booking email or on the paperwork. This single step defeats the majority of impersonation schemes because the fraud ring does not control the legitimate carrier's registered phone line.
Automating verification at scale
Manual verification does not scale past a handful of carrier relationships per month. Purpose-built carrier verification platforms (Highway, Carrier Assure, RMIS, and similar tools) automate the MC number, insurance, and authority-tenure checks and integrate directly into TMS booking workflows, blocking a booking from being confirmed until verification passes. For importers who work through a forwarder rather than booking carriers directly, confirm during forwarder selection that this verification layer exists in their carrier network. See our guide on forwarder evaluation and RFP questions for the specific questions to ask about carrier vetting during procurement.
Configuring your TMS as a verification gate
If your transportation management system supports configurable booking rules, set a hard rule that no shipment can be marked as booked or dispatched until carrier verification status shows as passed. This removes the judgment call from a coordinator under time pressure to move a load and makes the verification step a system requirement rather than a best practice that gets skipped during a busy week. For importers booking ocean freight through a forwarder, the equivalent control is confirming that your ocean freight partner verifies drayage and inland trucking carriers with the same rigor applied to ocean carriers, since the inland leg is where most identity-based fraud occurs.
Locking Down Payment Workflows to Stop BEC and Invoice Fraud
Business email compromise is the highest-dollar-value fraud vector for most importers because a single successful attack can redirect an entire freight invoice or supplier payment, often tens of thousands of dollars, in one transaction. The good news is that BEC is also the vector with the most reliable, low-cost control: mandatory callback verification on any change to payment details.
The one rule that stops most BEC losses
No bank account change, whether for a carrier, a forwarder, a customs broker, or a supplier, should ever be processed based on an email request alone. Every change requires a verbal callback to a phone number sourced independently, from your existing vendor file or a public company directory, never from the email requesting the change or a phone number provided in that same message. This single rule, enforced without exception, defeats the overwhelming majority of BEC payment redirection attempts, because the fraud ring does not control your vendor's real phone line.
Domain and email authentication controls
Configure DMARC, SPF, and DKIM email authentication on your own domain to prevent your company's domain from being spoofed to attack your suppliers and partners, and ask your key vendors, forwarders, and customs brokers to confirm they have done the same. Set your email security tooling to flag lookalike domains (a single character swapped, an extra hyphen, a different top-level domain) that closely resemble your regular freight and supplier contacts. Most email platforms, including Microsoft 365 and Google Workspace, support this configuration at no additional cost, and it is one of the highest-leverage security investments available to a mid-market importer.
Dual approval and vendor master file controls
Require two-person approval for any change to vendor banking details in your ERP or accounts payable system, with the second approver confirming the callback verification was completed before approving. Maintain a locked vendor master file where banking details can only be edited by a small, named group, and log every change with a timestamp and the name of the approver. This creates an audit trail that both deters internal fraud and speeds up recovery efforts if an external attack does get through.
AP automation with anomaly detection
Modern accounts payable automation platforms flag payment requests that deviate from historical patterns: a payment amount significantly above the vendor's typical invoice, a request for expedited or same-day payment outside normal terms, or an invoice number format that does not match the vendor's historical numbering pattern. These anomalies do not prove fraud, but they warrant a manual hold and a callback before payment releases. Configure this threshold conservatively at first (flag anything more than 20% above the vendor's trailing 6-month average) and tighten it as you learn your normal payment patterns.
What to do when a payment has already gone out
If a fraudulent payment is discovered within hours, contact your bank immediately and request a recall or hold on the wire. Banks can sometimes intercept a fraudulent wire before it fully clears if notified within the first 24 to 72 hours, particularly for international transfers that route through correspondent banks. File a complaint with the FBI's Internet Crime Complaint Center (IC3) immediately, since IC3 works with financial institutions on a fraud recovery program that has successfully frozen and recovered funds in a meaningful share of cases reported within 72 hours.
Using Real-Time Visibility as a Fraud Detection Layer
Most importers already pay for real-time visibility tracking to manage ETAs and exceptions. Few configure it to also serve as a fraud detection layer, despite the fact that the same GPS and telematics data that predicts arrival times is highly effective at catching cargo diversion in progress, while there is still time to act.
Geofencing and route deviation alerts
Configure geofence boundaries around your expected route corridor, origin facility, and destination facility. A shipment that departs the expected corridor by more than a defined threshold, typically 10 to 15 miles for line-haul trucking or a comparable deviation for drayage moves, should trigger an immediate alert to your logistics team, not a note in a weekly report. For high-value shipments, tighten this threshold further. The window between a route deviation and an unrecoverable theft is often measured in hours, so the alert has to reach a human who can act, not just populate a dashboard no one is watching in real time.
Cross-checking GPS data against carrier paperwork
A meaningful share of double-brokering and diversion schemes are caught by a simple discrepancy check: does the truck's actual GPS location and movement pattern match the carrier and route information on the bill of lading? If your visibility platform shows a different carrier's ELD data than the one listed on your paperwork, or shows the truck idling at an unfamiliar facility outside normal transit patterns, that is a strong signal worth an immediate phone call before the shipment proceeds further.
Unscheduled stop and dwell time monitoring
Set alerts for unscheduled stops exceeding a defined duration, particularly outside business hours or in locations that are not known truck stops, rest areas, or your facilities. Legitimate delays happen constantly in freight, so the goal is not to flag every stop, but to flag the combination of an unscheduled stop with a subsequent route change, which is a much stronger fraud indicator than either signal alone.
Building this into your exception management workflow
Fraud detection alerts should route through the same exception management process you already use for delay and disruption alerts, but with a distinct escalation path. A delay alert goes to your inventory planning team. A route deviation or carrier mismatch alert should go directly to a named security or operations lead with authority to halt payment, contact law enforcement, and notify your insurance carrier without waiting for a committee decision. Our guide on AI control towers for peak season covers the broader exception orchestration architecture that fraud alerts should plug into, since the infrastructure for catching operational disruptions and the infrastructure for catching fraud overlap significantly.
Data Access Controls: Limiting What a Compromised Account Can Expose
Account takeover of a TMS, forwarder portal, or ERP login is increasingly the entry point for sophisticated fraud, because a single compromised credential can give an attacker visibility into your entire shipment pipeline, your supplier list, and in poorly configured systems, the ability to approve bookings or payments directly. The defense is not a single tool but a set of access discipline practices that limit the blast radius of any one compromised login.
Least-privilege access by role
Review every user account with access to your TMS, forwarder portal, and freight-related ERP modules, and confirm each person's permissions match what their role actually requires. A warehouse coordinator who needs to view shipment status does not need permission to edit delivery addresses. A logistics analyst who runs reports does not need payment approval authority. Segregating booking permissions from payment permissions means that even if an attacker compromises one account, they cannot both redirect a shipment and approve the payment for it. Conduct this review at least twice a year, and immediately when an employee changes roles or leaves the company.
Multi-factor authentication without exception
Every account with access to booking, payment, or shipment routing functions should require multi-factor authentication, with no exceptions for convenience or for accounts used by multiple team members. Shared logins are a particular liability: they make it impossible to trace which individual took an action, and they are frequently reused across other, less secure systems where they are more likely to be compromised in an unrelated breach. Move away from shared credentials even where it adds friction to daily operations.
API key and integration hygiene
Importers with API integrations between their ERP, TMS, and forwarder platforms accumulate API keys and service account credentials over time, many of which outlive the integration project that created them. Audit active API keys quarterly, rotate keys for any integration that has changed ownership or is no longer actively maintained, and scope each key to the minimum set of endpoints it actually needs rather than granting broad account-level access by default. A forgotten, over-permissioned API key from a discontinued integration is a common and entirely avoidable entry point.
Monitoring for anomalous login activity
Configure alerts for logins from new geographic locations, unusual login times, or rapid, repeated failed login attempts, all of which most modern SaaS platforms support natively without additional cost. Review these alerts weekly at minimum, and treat any unexplained anomaly as a signal to force a password reset and review recent account activity for unauthorized changes, even if nothing else appears obviously wrong.
Vendor and integration risk
Every third-party system connected to your freight data, customs filing software, a supplier portal, a freight audit tool, is a potential entry point regardless of how well you secure your own accounts. Ask each vendor with access to your shipment or payment data about their own security practices: do they enforce MFA, how quickly do they patch known vulnerabilities, and what is their incident notification commitment if they are breached. A vendor unwilling to answer these questions directly is a signal to reconsider the relationship, particularly for any tool with write access to booking or payment workflows.
Building an Incident Response Protocol for Suspected Fraud
Even well-controlled importers will eventually face a suspected fraud event. What separates a contained incident from a large loss is not the sophistication of the attack, it is how fast a defined response protocol kicks in. Improvising a response after the fact costs time that fraud rings are actively counting on.
The first hour
The moment fraud is suspected, whether it is a payment that looks redirected, a carrier that cannot be reached, or a shipment that has deviated from its expected route, three actions need to happen in parallel, not sequentially. First, halt any pending payment or booking action related to the suspected fraud. Second, contact your bank if a payment is involved, since the recovery window for wire fraud narrows sharply after the first 24 hours. Third, notify your named internal fraud response owner, who should have pre-authorized authority to pause operations without waiting for a chain of approvals.
Documentation from the start
Preserve every email, document, and communication related to the suspected fraud immediately, including headers and metadata, not just the visible message content. This documentation is required for law enforcement reports, insurance claims, and bank recovery requests, and email systems do not always retain full header information indefinitely. Screenshot or export everything before taking any action that might alter or delete records, such as replying to the fraudulent email or changing account settings.
Who to notify and when
- Your bank or financial institution: Immediately for any payment-related fraud, to request a wire recall or hold.
- FBI Internet Crime Complaint Center (IC3): Within 24 to 72 hours for BEC and wire fraud, to access the Recovery Asset Team's freeze request program.
- Verisk CargoNet or NICB: For suspected cargo theft, to log the incident in the shared industry database that carriers, brokers, and law enforcement use to identify patterns and recover stolen freight.
- Your cargo insurance carrier: As soon as a loss is confirmed or strongly suspected, since most policies have notification deadlines that affect claim eligibility. Review your policy's specific fraud and theft provisions with your broker in advance, not during an active incident, since coverage for fraud committed by an impersonated party can differ meaningfully from coverage for straightforward theft. Our guide on cargo insurance covers how these policy distinctions typically work.
- Your forwarder and customs broker: To flag the incident across your full shipment pipeline in case the same fraud vector is being used against other shipments in transit.
Post-incident review
Every confirmed fraud attempt, successful or blocked, should trigger a short review: which control caught it or failed to catch it, and what specific process or system change closes that gap going forward. Treat near-misses with the same seriousness as successful attacks, since a blocked attempt today often means the same fraud ring will try a slightly modified approach against your team next month.
Evaluating Anti-Fraud Technology: What Actually Works
The market for freight verification and fraud prevention tools has grown quickly, and not every product delivers on its claims. Use these criteria when evaluating carrier verification platforms, AP fraud detection tools, or visibility platforms marketed with fraud prevention features.
Does it integrate into an existing workflow, or add a new one?
A verification tool that requires your team to log into a separate system and manually copy data will get skipped during busy weeks, which defeats its purpose. Prioritize tools that plug directly into your existing TMS or booking workflow and block progress until verification passes, rather than tools that generate a report someone has to remember to check.
What is the actual data source behind the verification?
Ask any carrier verification vendor exactly where their MC number, insurance, and authority data comes from, and how frequently it refreshes. Data pulled directly from FMCSA and insurance issuers in near real time is meaningfully more reliable than data cached and refreshed weekly, since fraud rings specifically exploit the lag between a real change and a stale database update.
Track record with your specific lane and cargo type
Ask vendors for references from importers with a similar cargo profile and lane mix to yours. A verification platform built primarily for full truckload dry van freight may have gaps in coverage for specialized drayage, reefer, or LCL consolidation moves that make up a meaningful share of many importers' domestic legs.
Total cost against realistic loss avoidance
Most carrier verification and AP fraud detection platforms price on a per-shipment or per-transaction basis that is a small fraction of a single average fraud loss. Build the business case using your own shipment volume: at 15 to 20 containers per month with domestic drayage on each leg, even a modest reduction in fraud exposure typically pays for a verification platform within the first prevented incident.
Red flags in vendor claims
Be skeptical of vendors promising to eliminate fraud entirely, since no technology control stops a sufficiently well-resourced, patient attacker with insider knowledge. Favor vendors who talk specifically about which fraud vectors their tool addresses and which ones remain your responsibility to control through process, since that specificity is a better signal of a mature, honest product than a broad promise of complete protection.
Your 30-60-90 Day Fraud Prevention Roadmap
Implementing every control in this guide at once is unrealistic for most operations teams already managing daily booking volume. A phased rollout gets the highest-impact controls in place first, while building the habits and system configuration that make later phases easier.
Days 1-30: Stop the two highest-dollar-value gaps
Implement mandatory callback verification for any change to payment or banking details across all vendors, carriers, and suppliers, with no exceptions regardless of how routine the request appears. In parallel, implement MC number and insurance verification as a hard gate before any new carrier relationship is booked, using FMCSA SAFER lookups at minimum even before investing in an automated verification platform. These two controls alone address the fraud vectors responsible for the largest average dollar losses, and both can be implemented with existing staff and no new software spend.
Days 31-60: Configure detection layers on tools you already have
Configure geofencing and route deviation alerts on your existing visibility platform, and set up DMARC, SPF, and DKIM email authentication on your company domain if not already in place. Conduct the access control review across your TMS, ERP, and forwarder portal accounts, removing unnecessary permissions and enforcing multi-factor authentication across every account with booking or payment access. None of this requires new vendor contracts, only configuration time from your IT and operations teams.
Days 61-90: Formalize the incident response protocol and evaluate automation
Document your incident response protocol in writing, name the individuals responsible for each step, and run a tabletop exercise with your logistics and finance teams to confirm everyone knows the process before a real incident tests it. Use this period to evaluate carrier verification platforms and AP fraud detection tools against the criteria in this guide, scoping a pilot with your highest-volume lanes or vendor relationships first rather than a full rollout.
Ongoing: Treat fraud prevention as a maintenance discipline, not a project
Fraud tactics evolve continuously, and controls that work today will be tested with new approaches within months. Review your incident log quarterly, even when the count is zero, to confirm the team is still following the callback verification and access control practices under daily time pressure. The importers who avoid becoming a statistic in next year's cargo theft report are not the ones with the most expensive tools. They are the ones who make a small number of verification steps non-negotiable, every time, regardless of how legitimate a request appears.
Cubic's platform verifies carrier identity and insurance on every booking across our network and gives importers real-time visibility configured for exception and fraud alerting out of the box. If you want to review your current exposure across carrier verification, payment controls, and visibility configuration, our team can walk through a gap assessment against the framework in this guide.