By Ivan Tsybaev, founder and CEO of Ten8. I co-founded Trucker Path and was its founding CEO, and I spent more than a decade in freight before starting Ten8.
Carrier identity fraud is a bad actor using a carrier's identity, real or invented. The goal is simple: book a load, collect the payment, or steal the cargo before anyone notices. In 2025, estimated cargo theft losses in the US and Canada climbed to nearly $725 million. That is up about 60% from 2024, according to Verisk CargoNet. The FBI's Internet Crime Complaint Center puts a sharper point on it. Confirmed cargo theft incidents rose 18% in 2025. The average value per theft jumped 36% year over year, because criminals are going after fewer, higher-value loads instead of a broad spread of small ones. This playbook covers the patterns behind that number, where each one shows up in a load's lifecycle, and what to do when one gets through anyway.
How this guide is sourced
The loss figures below come from named trackers (Verisk CargoNet, the National Insurance Crime Bureau) and federal sources (FMCSA, the FBI's IC3). Where a number comes from a single customer, Fura Freight, it is flagged as one data point, not a benchmark. This page gets updated as the regulations and the fraud tactics change, and 2026 has already brought three federal changes worth tracking, covered further down.
The five patterns brokers are seeing
Most carrier fraud that reaches a brokerage falls into one of five patterns. The FBI's own casework this year added a fifth to the older four. It is also the one growing fastest, because it does not require stealing a physical identity at all. Just a login.
| Pattern | What happens | Highest-value signal | Where it's caught |
|---|---|---|---|
| MC or identity hijacking | A bad actor takes over a real carrier's identity, banking, or dispatch contact, and books under it | Banking change soon after onboarding; a phone or email that does not match FMCSA records | Onboarding, payment |
| New-MC and chameleon-carrier scams | A brand-new MC runs a few clean loads to build trust, then vanishes on a bigger one; or a carrier shut down for safety violations reopens under a new name | MC registered within the last 60 days; little history with other brokers | Onboarding |
| Double brokering | A carrier accepts a load, then secretly re-brokers it to another carrier at a lower rate and pockets the difference | Accepts a high rate with no negotiation; truck not in the carrier's fleet records | Booking, dispatch |
| Fraudulent dispatch | Someone poses as a real carrier's dispatcher and routes the load to their own driver | Dispatcher name new to the MC; wrong email domain; unusual time zone | Dispatch, pickup |
| Cyber-enabled load-board takeover | Attackers phish a broker's or carrier's login, install remote-access software, then post large batches of fake loads or hijack real bookings | Spoofed sender domains; a "resolve this complaint" link; new mailbox forwarding rules the user did not set | Booking, dispatch |
The last row is the one the FBI's April 2026 advisory walks through step by step. A threat actor spoofs a broker in an email. The target clicks a shortened link, and a remote-monitoring tool lands on their machine. From there, the attacker can post loads, bid on real ones under a compromised carrier's name, and cross-dock the freight to a driver who partly does not know what they picked up. It is double brokering and MC hijacking. The entry point is just a phishing email instead of a forged document.
No single signal proves fraud. It is the combination that catches the pattern, which is why it is hard to spot by eye when a rep is juggling dozens of live loads at once.
Why this is a broker-of-record problem, not just a carrier problem
I think the framing most brokers use is backward. Carrier fraud gets talked about as a risk carriers create and brokers defend against. But the party holding the operating authority carries the regulatory and financial exposure when it goes wrong. That is true whether the authority belongs to a standalone brokerage or to a network the freight agent operates under. A fraudulent load booked under your MC number is your liability with FMCSA. It is your claim with your cargo insurer, and your conversation with the shipper who trusted your name on the rate confirmation.
That is a different problem than "watch out for scammers." It means the vetting layer is not optional overhead you get to when things are slow. It is part of what holding the authority means, the same way carrying the federal bond or passing a safety audit is.
Where the checks belong in the load lifecycle
Fraud gets caught at different points depending on the pattern, so the defense has to run in layers. A miss at one layer should be a catch at the next.
- Onboarding. Run every new MC through an authority check on FMCSA's SAFER system: active, not revoked. Confirm the safety rating and out-of-service history. Verify insurance with the insurer directly, not just by reading the certificate. Confirm the carrier's phone number matches what SAFER shows on file. New-MC scams and chameleon carriers get caught here, or not at all.
- Pre-booking. Before each load with an existing carrier, confirm the dispatcher's name and email domain match the MC's history, and flag any rate accepted with no negotiation.
- Dispatch and pickup. Match the truck and driver to the carrier's known fleet, confirm the pickup driver's ID, and check that the bill of lading signature matches the assigned driver.
- Payment. Verify banking has not changed since booking. If it has, confirm the change through a channel other than the one that requested it, not a reply to the same email thread.
What federal regulators changed in 2026
Three separate federal actions landed this year, and together they say the same thing: identity at registration and identity at payment are both getting harder to fake.
| Date | Change | What it means for brokers |
|---|---|---|
| January 16, 2026 | FMCSA's new financial responsibility rule took effect | A broker whose bond or trust fund falls below the federal minimum and is not restored within 7 calendar days gets its operating authority suspended; only cash, irrevocable letters of credit, and US Treasury bonds count toward that fund |
| March 19, 2026 | FMCSA bulletin on USDOT-number sales | Any sale or lease of an operating authority outside a real corporate transaction now triggers inactivation of the number and revocation of related registrations |
| May 19, 2026 | FMCSA launched Motus, a new registration platform | Registration now requires a government-issued ID and a facial scan, aimed directly at the "several thousand suspicious registration numbers" FMCSA said were tied to fraudulent carriers under the old system |
Sources for the table: the financial responsibility rule, the USDOT-number bulletin, and the Motus launch announcement.
None of these close the loop by themselves. Motus makes it harder to register a fraudulent MC in the first place. But it does not stop an existing, legitimately registered carrier's identity from being hijacked after the fact. That is exactly what the FBI's April advisory describes.
If you think fraud is already in motion
Some fraud gets past any defense. When it does, speed matters more than anything else.
- Lock down the carrier record. Freeze it in your TMS, hold any pending payments, and stop booking new loads under that identity.
- Confirm with the real carrier through a verified channel. Call the phone number listed on SAFER, not the one in your file, since that may be exactly what got hijacked.
- Document everything. Rate confirmations, bills of lading, proof of delivery, and every message tied to the load. This is what your insurer and any investigation will need.
- File with FMCSA and the FBI's IC3. FMCSA's own fraud and identity theft guidance points to its National Consumer Complaint Database; the FBI's IC3 takes reports on the cyber-enabled version directly.
- Notify your insurer and the customer. Get ahead of the shipper conversation. A customer who hears it from you first tends to stay a customer.
- Audit what let it through. Which signal existed but was not checked, and what changes so the same pattern does not work twice.
What continuous verification looks like operationally
A single check at onboarding leaves a carrier's identity open. It stays open for as long as that carrier keeps hauling for you. The shift that closes the gap is re-checking on every change, not just at the start: a banking update, a new dispatcher contact, a rate posture that suddenly breaks from the carrier's history. Watched individually, those changes look routine. Watched together and continuously, the fraud-indicating combination shows up faster than a rep working fifty open threads could catch it by hand. That is the operational shift. Not a piece of software bolted onto an existing workflow, but how the checking itself gets run, at the volume a real book of business requires.
What stays a human call
Continuous checking is a routine task. Deciding what to do with a confirmed fraud is not. A bond claim, a hard conversation with a shipper about a lost load, a long-standing carrier flagged by a false positive: those go to a person with full context, not an automated action. The goal is narrow. Run the constant checking no one can do by hand at volume, and get the genuine judgment calls to a human fast, rather than pretending a system can make them.
What this looks like in practice
The clearest reference point is Fura Freight, running more than 5,000 shipments a month across 16,000 carriers. Fura brought continuous verification into its carrier-sales and back-office workflow. Its gross margin per load moved from 8.2% to 14.9%. Its carrier-call coverage went from 60% to 100%, according to Ten8's own reporting on that account. Those are one customer's reported results, not a portfolio average. But the mechanism behind them is not glamorous. Cross-checking dispatcher names, email domains, banking changes, and rate posture against history on every interaction is pattern work. It does not scale by adding more reps.
What to do this quarter
- Run a fraud audit on the last 12 months. Pull every incident and near-miss, and map which signals existed before each one and which were not being checked.
- Move insurance and banking verification off the paper trail. Reading a certificate instead of calling the insurer, or approving banking changes by email reply: that is exactly where the next hijacking will land.
- Add re-verification after onboarding, not just at it. A carrier vetted once and never again is exactly the carrier a hijacker wants to find.
Where this goes
Carrier identity fraud is not a problem that gets solved once. It gets managed continuously, by whoever holds the authority the fraud is committed under. That is true whether you run a standalone brokerage or a book of business inside a broker network. It is the same reason ten8.ai treats vetting as part of the operating model, not a bolt-on tool.
FAQ
Does cargo insurance cover a load that turns out to have been double-brokered?
Not automatically, and the answer depends on the policy. Many contingent-cargo and all-risk policies exclude coverage specifically when the broker did not hire the carrier that physically picked up the freight, which is exactly the situation double brokering creates. Read the exclusions before assuming a claim will pay out.
What should a carrier contract include to reduce fraud exposure?
At minimum, a clause requiring notice before any change in dispatch contact or banking details, the right to audit driver and equipment records tied to a specific load if fraud is suspected, and language that ties payment to verified delivery documentation, not a submitted invoice alone.
Is it safe to book a carrier again after its MC was linked to identity fraud, even once it looks reinstated?
Treat it with more scrutiny, not less. FMCSA's own language for this pattern, a carrier that shuts down and reopens under a new identity to shed a bad history, is a "chameleon" or "reincarnated" carrier. A clean-looking MC number does not undo a prior fraud flag on the people behind it.
What internal signal shows a book of business has a fraud problem, not just one bad incident?
Watch three things together: a rising rate of banking-change requests relative to load volume, more than one carrier sharing the same dispatcher contact or address, and a cluster of new-MC carriers concentrated in the same lane. Any one alone is normal noise. Two or more together, across a short window, is worth a manual review of the whole segment.
How do phishing attacks on booking or payment staff usually start?
Per the FBI's IC3, the pattern is an email that looks like it comes from a legitimate broker or carrier domain. It often carries a link about a carrier agreement, or a "negative service review" to resolve. The link leads to a lookalike site that installs remote-access software. That gives the attacker control of the account without the user noticing. Training staff to verify unexpected links through a second channel, not by clicking to check, catches most of this before it starts.
Can a broker be personally liable for fraud that slips through weak vetting?
Operating without required authority carries a federal civil penalty of up to $10,000 per violation, and that liability applies individually to officers, directors, and principals of the business, not only to the company. Vetting failures that lead to fraud add insurance and shipper-relationship exposure on top of that.
What happens if someone tries to sell or lease a USDOT or MC number?
FMCSA treats that as fraud on its face. Selling, purchasing, or leasing a USDOT number or operating authority outside a legitimate corporate sale triggers two things: inactivation of the number, and revocation of the related registrations. FMCSA restated the policy directly in a March 2026 bulletin.
Keep reading

How AI handles every inbound carrier call 24/7
Inbound carrier calls drop volume on the floor every night and weekend at most brokerages. Here's how an AI picks up every call, handles the routine ones end-to-end, and routes the rest.

How Fura Freight answered 100% of carrier calls without adding headcount
Fura Freight runs 5,000+ shipments a month across 16,000 carriers. They were answering 60% of inbound carrier calls. Here is what changed when Ten8 deployed across voice, email, and Teams.

Carrier fraud is getting worse. Here's how we catch it
Double brokering, identity theft, and ghost carriers cost the freight industry billions. Automated vetting catches patterns humans miss.
