From Steel to Screens: How Cargo Theft Went Digital

Douglas Hindman

Chief Executive Officer

Gulf Relay Holdings | Clinton, Mississippi

Thefts fell by a quarter last quarter and losses doubled, because the freight now moves through a compromised inbox rather than a cut lock.

Stealing a truckload of copper no longer requires going near the truck. It requires a password, a convincing email, and a few days of quiet access to someone else's system.

Verisk CargoNet documented 677 supply chain theft incidents across the United States and Canada in the second quarter of 2026, down 26% from a year earlier, while estimated losses more than doubled to $304.6 million against $135.7 million in the same quarter of 2025. The average reported commodity value reached $564,009. Keith Lewis, who runs operations for CargoNet, put the warning plainly: “Lower incident volume should not be mistaken for lower risk.”

Events classified as straightforward theft fell from 488 to 378, and non-delivery fraud involving recently acquired motor carriers dropped sharply, particularly in California and Texas. Fictitious pickups barely moved, from 165 to 158. Compromise-based schemes, meaning business email fraud and shipment misdirection, held steady while everything cruder around them fell away.

They are not trying to steal more freight. They are trying to identify the right shipment.

What that leaves is a smaller number of thefts executed by people who no longer need to touch the trailer. The FBI made the mechanics explicit in an April 30 public service announcement on cyber-enabled cargo theft. Attackers spoof a broker by email, usually with a link to a carrier broker agreement or a request to address poor service ratings. The link goes to a phishing site hosting a malicious executable, which installs legitimate remote monitoring software and gives the attacker what the Bureau calls “total, undetected access” to the broker's or carrier's systems.

From there the compromised account becomes the weapon. Attackers post fake loads on the boards under a verified company's name, sometimes in the tens of thousands, and legitimate carriers who bid on them receive the same malicious agreement and get compromised in turn. Real shipments get booked under stolen authority, cross-docked or transloaded to complicit drivers, and resold. Some attackers reconnect with the broker afterward to demand a ransom for the load's location.

Attackers have also been altering the compromised carrier's registration details with FMCSA and updating its insurance records, so the legitimate company's public credentials end up being maintained by someone else. A carrier in that position does not discover the breach through its own systems. It finds out when a broker calls about a load booked in its name that it never booked.

A carrier in this position finds out when a broker calls about a load it never booked.

The targeting has narrowed at the same time. Metal theft rose from 54 incidents in the second quarter of 2025 to 80 a year later, with copper most frequently taken alongside aluminum, nickel and tungsten, and enterprise technology climbed with it. Lewis framed the shift as organized groups following value and resale opportunity rather than volume, which is what produces a quarter with a quarter fewer thefts and twice the losses.

One quarter is not a trend. Travelers' transportation crime lead cautioned against reading the Q2 decline as a turning point, and the underlying capability that produced these losses has not gone anywhere.

The FBI's own guidance runs toward the unglamorous: verify shipment requests through a secondary channel, enforce multi-factor authentication on load board and broker platform accounts, validate unexpected communications before acting on them, and keep detailed records of vehicles and drivers. None of that is new to anyone who has been paying attention, and all of it fails the moment a company treats the inbox as the trusted channel.

That is the discipline behind how we handle every load, and the protocol we have described before for high-value freight starts from the same assumption: the system that presented you with a document is not the system that can confirm it. A rate confirmation that arrives from a verified address, referencing a real load, under an authority that checks clean in FMCSA, can still be the theft. Confirm it somewhere the attacker does not already live.

About the Author

Douglas Hindman is the Chief Executive Officer of Gulf Relay Holdings, a full-service truckload carrier headquartered in Clinton, Mississippi, offering local, regional, national/OTR, dedicated, drayage, and heavy haul transportation services. Gulf Relay is a multi-year SmartWay Excellence Award recipient and Nissan Top Carrier. www.gulfrelay.com | Connect with Douglas on LinkedIn