P&C the October 2026 issue

Stealing the Supply Chain

Inside the multibillion-dollar underworld of cyber-enabled cargo theft, where criminal rings deceive shippers, freight brokers, and motor carriers into unwittingly providing the goods.
By Russ Banham Posted on September 29, 2026

If freight is left vulnerable, thieves will steal it. But while criminals still break into trailers at truck stops and rail yards, organized syndicates have found a more profitable approach, leveraging identity fraud and phishing to trick shippers, freight brokers, and motor carriers into handing over the goods.

Targeted high-value freight ranges from raw metals like copper, aluminum, nickel, and tungsten to enterprise-grade computer networking equipment, electronic components, and cryptocurrency mining hardware. According to Verisk CargoNet, this freight catapulted estimated cargo theft losses in Q2 2026 to $304.6 million in Canada and the United States, more than double the $135.7 million total tally from Q2 2025. While the financial severity of losses is soaring, the volume of individual cargo thefts actually fell by 26% year over year in the quarter, demonstrating that criminal syndicates scrutinize product value, market demand, and immediate resale opportunities when planning their heists.

Freight theft has moved beyond strictly physical crimes to encompass digital tactics including phishing, business email compromise, cloned identities, and manipulation of the online marketplace for cargo and motor carriers. Criminals have found multiple ways to intercept or misdirect cargo so it ends up in their hands.

Estimated Q2 2026 cargo theft losses more than doubled to $304.6 million in Canada and the United States. This happened even as the number of thefts in total has dropped, indicating that criminal syndicates have grown more efficient at identifying and stealing high-value freight.

Cargo underwriting has evolved as well, from solely a safety net for clients into a catalyst to ensure they have sufficient cyber hygiene and coverage. Policy riders tailored for today’s freight risks include fraudulent and fictitious pickup endorsements, social engineering endorsements, and cyber theft and extortion extensions.

The steep increase in stolen freight values also suggests that thieves have assembled unusually precise intelligence about specific shipments and their destinations. This information is accumulated through digital means to perpetrate what state and federal law enforcement officials classify as “strategic” thefts, distinguishing them from traditional “straight” cargo heists.

“Historically, cargo theft was a volume game where criminals got lucky catching a good load using physical, on-the-ground methods,” says Wayne Jacobs, special agent in charge of the FBI’s Philadelphia Field Office. “Today, they gain deep intelligence by exploiting public load boards. They are incredibly strategic about what they target, matching the thefts directly to black-market demand to fetch the highest price.”

A load board is an online marketplace where shippers, brokers, and truckers connect to list and claim available freight-hauling jobs. It’s also a digital resource for criminal operators to identify loads of expensive items that can be quickly sold at a high price, Jacobs explains. Stealing a few shipments of valuable goods means they don’t have to conduct large numbers of thefts.

Insurers corroborate this trend. “We have seen a reduction in the overall frequency of cargo thefts, but an exponential increase in the financial value of the losses,” says Ryan Kiefer, national director of Travelers’ Special Investigations Group, a dedicated, in-house cargo theft and recovery unit. “The thieves are selective, data-driven, and highly targeted in what they choose to steal.”

Based on confirmed incidents, Verisk CargoNet estimated approximately $725 million in freight theft losses in 2025 across Canada and the United States, a 60% increase from the prior year. However, broader econometric projections by the U.S. Department of Homeland Security and the National Insurance Crime Bureau suggest this amount is a drop in the bucket; in reality, total cargo theft losses cost the U.S. economy between $15 billion and $35 billion annually. (CargoNet tracks only the immediate sticker price of stolen freight, while federal estimates account for compounding economic damage including halted assembly lines, rising insurance premiums, and lost tax revenue.)

Part of the discrepancy in dollar amounts can also be attributed to reporting failures by various parties, according to the American Transportation Research Institute. For example, local law enforcement across multiple states often misclassifies cyber-enabled, physical strategic thefts as civil contract disputes or cyber fraud. Furthermore, to protect brand reputation and avoid skyrocketing commercial premiums, cargo owners frequently hide losses through corporate underreporting and settle financial liabilities with motor carriers via quiet, out-of-pocket payouts.

“When public reports say there are 10 [cargo theft] incidents, the reality might be 75; when they say it rises to 20 the next month, the real number could be 150,” says Kiefer.

Strategic thefts comprise approximately one-third of domestic cargo theft incidents, BSI Consulting and Munich Re Specialty reported in June 2026. To illustrate the scale of these modern scams, consider the priciest strategic theft on record. The heist was perpetrated by an international cargo fraud syndicate based in Armenia that used stolen motor carrier identities, cloned credentials, and manipulated digital load boards to intercept shipments entirely through cyber means. The group successfully tricked logistics providers into voluntarily releasing over $10 million in high-value freight between 2023 and 2026 before the FBI uncovered the scheme. The stolen cargo included high-value items such as electronics, liquor, meat, fish, eggs, clothing, skincare products, and cryptocurrency mining machines. “The higher the dollar amount, the better the profit margin,” says Jacobs. “Whatever product has an active black market, criminals will leverage cyber techniques to gain access to it.”

We have seen a reduction in the overall frequency of cargo thefts, but an exponential increase in the financial value of the losses. The thieves are selective, data-driven, and highly targeted in what they choose to steal.
Ryan Kiefer, national director of the Special Investigations Group, Travelers

Upending Trusted Relationships

Of the widespread cyber-enabled scams committed by criminal enterprises, business email compromise and shipment misdirection remain the most persistent, triumphing in large part because they successfully manipulate corporate trust.

Regarding email compromise, Jacobs says criminal groups steal a legitimate freight broker’s system credentials, allowing them to log into public load boards and mimic that broker to post fake loads. The postings entice innocent, legitimate independent truckers into becoming unwitting conduits for the syndicate.

In shipment misdirection frauds, syndicates exploit existing relationships between freight brokers and motor carriers. A motor carrier spots a cargo load posted by a familiar freight broker; however, the name has been altered by a single letter. The carrier engages with what they assume is a verified partner. The unsuspecting motor carrier receives a digital agreement from the presumed freight broker containing a hidden, malicious file. When the carrier opens the document to finalize the transport deal, the threat actor gains backdoor access to the company’s internal network. “Once inside, the criminals lock onto the load data and redirect the cargo to a different location,” Jacobs says.

While public load boards like the DAT Freight & Analytics platform assist shippers with bypassing freight brokers entirely, these digital marketplaces are primarily used by brokers themselves. When a freight broker’s contracted networks of trusted motor carriers lack the capacity to handle a specific shipment, the broker posts the freight onto a public load board to source an outside carrier from the open market.

That’s when syndicates pounce. Once a load is posted to the open market, they masquerade as legitimate independent truck companies to bid on the opportunity. To build a convincing disguise, they rely on the transparency of federal regulatory portals. The Federal Motor Carrier Safety Administration maintains a public database—the Safety and Fitness Electronic Records (SAFER) System—featuring a “Company Snapshot” portal that displays a motor carrier’s Department of Transportation (DOT) number, Motor Carrier (MC) authority number, the owner’s name and phone number, cargo volume, and operating status. The site also provides direct public links to the Licensing and Insurance system and the Central Registration System.

While these interconnected databases and systems were designed to provide shippers, brokers, and logistics companies with resources to vet trucking companies before doing business with them, they inadvertently offer the means for criminals to cross-reference them in crafting a multilayered digital forgery. “The criminals can go onto these [federal portals], pick and choose which motor carrier profile to impersonate on any given day, and essentially steal that motor carrier’s profile to claim a load,” says private investigator and cargo theft consultant Gerardo Pachuca, who spent 19 years with the Los Angeles Sheriff’s Department’s Cargo Criminal Apprehension Team (Cargo CATs).

Some criminal syndicates, instead of impersonating an existing motor carrier, will acquire legitimate trucking companies purely to leverage their established business histories, pristine reputations, and safety records, says Laura Block, senior vice president and head of U.S. marine claims at specialty insurer Ascot Group. “Even with proper due diligence, [shippers] may have no idea that in the background, ownership has changed hands to a criminal shell LLC,” she adds, noting that the hidden change in ownership challenges law enforcement to catch up.

Certificates of Insurance

When a motor carrier’s identity is digitally impersonated, criminals must manipulate and falsify certificates of insurance (COI) to bypass contractual barriers. Freight brokers legally cannot assign expensive shipments to trucks lacking equivalent insurance coverage, explains Valorie Steinbeck, national general adjuster for inland marine in Crawford & Co.’s commercial transportation unit. Most standard freight broker-motor carrier agreements mandate a minimum cargo insurance limit of $100,000. “While this amount is sufficient for basic commodities, it is entirely inadequate in today’s market when transporting expensive electronic goods or specialized technology components, which frequently exceed $500,000 in value,” she says.

To circumvent these strict insurance thresholds, fraudsters execute subtle document changes to forge a motor carrier’s coverage limits. For example, if a shipper has a load valued at $500,000, but the assigned motor carrier only carries $100,000 in coverage, the COI is altered to reflect a $500,000 limit, tricking the broker into releasing the freight. “In many cases, the legitimate carrier is entirely unaware of the true value of the cargo they are hauling or that their email networks have been compromised to facilitate the forgery,” Steinbeck says.

The Physical Theft

Once a cargo load is booked digitally using a cloned identity and a forged COI, the syndicate executes the physical theft at the shipping bay using one of two distinct methods: hiring an independent and innocent driver to pick up the shipment or deploying their own transport personnel. In the first scenario, “The drivers don’t suspect they are being manipulated; they present their real driver’s licenses and leave their legitimate DOT and MC placards on their tractors,” Pachuca says.

Once the load is in transit, the criminals, pretending to be the freight broker, contact the driver with secondary instructions to redirect the freight away from the intended receiver. “They tell the driver, ‘This load now needs to go to Dallas instead of Abilene.’ The driver abides by those instructions, receives secondary paperwork online with the new location, and the cargo disappears,” Pachuca says.

If the criminal network uses its own personnel and vehicles to collect the goods, unsuspecting warehouse personnel are caught in the trap because syndicates manufacture a false sense of security immediately at the shipping bay. “Criminal actors will physically redress their trucks to look like well-known, trusted vehicles that a shipper or broker is already familiar with,” Jacobs says. Warehouse workers hand over freight because the visual cues match their expectations; they assume the truck is legitimate and the driver belongs to a recognized brand. Removing an independent middleman from the transport leg gives the syndicate uninterrupted access to the stolen goods using their own equipment. The criminal drivers can simply accept the freight and disappear, Jacobs says.

An added threat involves fully digital invoice manipulation via business email compromise, a widespread tactic that occurs irrespective of the value of the physical freight. In this scenario, a criminal isn’t looking to divert the physical cargo using traditional social engineering to change the shipping address; instead, they infiltrate email networks to alter bank routing details on digital invoices, ensuring the freight broker or shipper pays the bad actor instead of the legitimate party, says Mario Paez, national cyber risk leader at insurance broker Marsh McLennan Agency. The true carrier eventually calls to say they never received payment, which results in accounts receivable fraud.

Tracking the End Point

Once a strategic heist succeeds, the stolen cargo enters a shadow distribution network where tracking the goods is extremely challenging. Travelers’ Kiefer points out that because many companies outsource their supply chains through fragmented third-party logistics networks, the layered separation makes it incredibly difficult for investigators to reconstruct the digital paper trail after a load vanishes. “We know that some of it crosses the border to Canada and Mexico, and some of it goes overseas,” Kiefer says.

Since moving physical goods internationally requires precise coordination, organized crime groups typically secure buyers for the illicit freight before committing the actual theft. “The fences and black-market buyers want these specific assets, so the syndicates target those exact loads. That’s how the life cycle works,” Kiefer says.

Nevertheless, tracing the origins of these operations reveals distinct global hubs. Cargo CATs’ intelligence, for instance, indicates that many of the individuals orchestrating the digital phishing infrastructure operate out of India, while the primary threat networks financing and managing the broader physical distribution operations are linked to Russia, Armenia, and, to a lesser extent, Mexico. Brazil and South Africa are other distinct regional hubs, according to industry reports.

A prime example of this international network is Diesel Vortex, a Russia-linked cybercrime network that targeted the logistics sector from September 2025 to February 2026. Using look-alike domains to mimic legitimate transit companies, the syndicate harvested more than 1,600 unique login tokens from major digital freight platforms across the United States and Europe. Armed with the compromised accounts, the group executed widespread cargo diversions— relabeling shipments to hand them off to unsuspecting secondary motor carriers, then manipulating bills of lading and issuing fraudulent alternate routing instructions to siphon high-value shipments into staging yards.

While the final step in this life cycle involves liquidating the stolen inventory, the end buyers are not always complicit. “There are buyers who are an active part of the criminal element and understand the goods were obtained by illegitimate means, but you can also end up in a situation where the thieves are relisting the stolen items on trusted public marketplaces,” says Jacobs. “Because the true origin of the freight is obscured, innocent buyers think they’re purchasing from a legitimate vendor who happens to have a deal on surplus goods.”

The vast majority of trucking in the United States is done by small operators running just one to five rigs; large fleets are actually the minority.… Many of these small business owners do not have the time, budget, or capability to deploy sophisticated digital defenses or tech-driven fraud detection systems.
Laura Block, senior vice president and head of U.S. marine claims, Ascot Group

Cargo Values Add Up

While high-value cargo thefts receive significant media attention, the frequency of high-volume thefts of lower-value commodities is consistently higher and increasing. CargoNet’s Q1 2026 report cited food and beverages as remaining the No. 1 most targeted category of cargo theft overall, while hijackings of personal care and beauty products rose by 178% from the same period a year prior. “Criminal syndicates run highly successful operations targeting everyday goods,” says Block at Ascot. “We’re seeing a surge in smaller-value claims by our shipping clients. The commodities we insure run the entire gamut, including manufactured goods, machinery, oil and gas, and general merchandise.”

Repeated thefts of low-value freight can jeopardize the businesses of shippers and transportation providers of any size, Block notes, as cascading costs, contractual penalties, and replacement of freight can outpace the value of the stolen cargo itself.

“We have seen instances where multiple lower-value shipments—whether it’s a basic widget, raw materials, consumer electronics, tequila, or large pallets of KitKat candy—are stolen sequentially, and nobody realizes what’s happening until the losses reach massive dollar amounts,” Marsh McLennan’s Paez says.

Over the course of a single week, multiple shipments fail to arrive, leaving companies scrambling. The crime only comes to light when the receiving company reports that the cargo has not arrived, he adds. “We hear from clients who say, ‘Why would anyone target these specific plastic components or pieces of paper?’ The reality is that as prices rise, everything becomes worth the economics of crime.”

At Ascot, this surge in the pilferage of lower-value cargo is increasingly attributable to social engineering and identity theft via phishing, fake documents, and AI-assisted communications designed to deceive honest transport operators.

“The vast majority of trucking in the United States is done by small operators running just one to five rigs; large fleets are actually the minority,” Block says. “As a result, you have less technologically sophisticated operators simply trying to do their jobs—picking up and dropping off freight. Many of these small business owners do not have the time, budget, or capability to deploy sophisticated digital defenses or tech-driven fraud detection systems.”

Insurance Market Repercussions

The global surge in freight theft losses has severely strained the cargo insurance market, which is evident in CargoNet’s nearly $725 million in total losses last year in Canada and the United States alone. Current figures on insurance premium increases are unavailable; however, reporting in 2024 by trucking and freight news website Transport Topics suggested average rate hikes between 8% and 12%, depending on loss history.

To compensate, insurance carriers are actively reducing their capacity on theft-related claims by slashing policy limits and tightening underwriting criteria, making basic coverage for high-value shipments difficult to secure for transportation providers and freight brokers.

“When we have a client moving a $5 million load, which happens way more often than people think, we have to help on the front end by providing as much detailed risk-mitigation data as possible to the insurer just to get the load covered,” says Christina Reiz, executive director of insurance broker Gallagher’s transportation practice.

According to Reiz, policy renewals across the industry now demand exhaustive advanced planning. Insurance brokers must evaluate an insured party’s specific risk tolerance and audit their physical security protocols before underwriters will even consider a contract. The sheer frequency of these exposures complicates the timeline, compelling many shipping clients to secure specialized single-shipment coverage for multimillion-dollar loads several times a week. When losses become unwieldy, domestic insurers often pull back, leaving brokers to look across the Atlantic to find adequate capacity.

“We frequently have to access the specialized London market [to structure] annual policies and specific one-off endorsements for when a shipper faces large, concentrated cargo exposure,” Reiz explains.

A critical coverage gap in standard domestic policies also draws insurance brokers to the London market: the fine-print “voluntary parting” exclusion. Under standard Insurance Services Office forms in the United States, if a business is deceived by a “fraudulent scheme, trick, device or false pretense”— such as a spoofed email or a cloned identity—into willingly handing over freight to a criminal entity, the domestic insurer can deny the theft claim entirely. Unsuspecting logistics providers then face devastating out-of-pocket losses, as the insurer restricts the total payout to a minor sublimit cap of $1,000.

By contrast, the London market offers the flexibility to bypass this coverage gap. Through innovative frameworks like the London market-based Joint Cargo Committee’s recent cyber-theft endorsements, foreign underwriters can structure affirmative coverage that explicitly protects physical cargo loss, even if cyber deception was used to gain access to the shipping dock.

We hear from clients who say, ‘Why would anyone target these specific plastic components or pieces of paper?’ The reality is that as prices rise, everything becomes worth the economics of crime.
Mario Paez, national cyber risk leader, Marsh McLennan Agency

To close these financial gaps and loopholes, transportation providers and freight brokers partner with specialized insurance brokers to design policies that define exactly when a cyber-enabled loss triggers. Working together, they can explicitly request tailored policy riders from underwriters to override legacy exclusions, including:

  • Fraudulent Pickup or Fictitious Pickup Endorsements: Cover physical losses when a load is released to an impostor driver who used cloned carrier identities.
  • Social Engineering Endorsements: Protect against digital deception and phishing scams that trick employees into parting with goods.
  • Cyber Theft and Cyber Extortion Extensions: Bridge the coverage gap by insuring physical cargo losses, spoilage, or systemic delays resulting from a network hack or ransomware attack.
  • Funds Transfer Fraud Riders: Secure financial recovery when bad actors intercept digital freight communications to redirect wire and payment routing.
  • Joint Cargo Committee Physical Theft Endorsements: Allow first-party shippers to bridge the gap between digital breaches and physical cargo losses via a hybrid policy, ensuring financial recovery if a network compromise results in stolen physical goods.

This evolution has transformed cargo underwriting from a reactive financial safety net into a catalyst for cyber hygiene. Insurers are replacing basic compliance checklists of their clients with strict IT security audits, requiring companies to prove their defenses before policies are issued. Underwriters now demand explicit proof of robust controls, including mandatory multifactor authentication, dual-verification freight release protocols, documented employee training, and formal carrier vetting procedures.

Perhaps best of all, the strict insurance mandates are helping to align corporate liability with real-world defense. By dictating cybersecurity standards, underwriters are essentially helping law enforcement shrink the digital attack surface used by organized crime syndicates.

The ultimate goal, says Jacobs at the FBI, is to create an environment where a security breach is a rare anomaly rather than a repeating pattern. “If you do get compromised and suffer the loss of a load, it should happen only once; it shouldn’t be something that hits your company several times,” he explains. “Ultimately, it’s about making this type of illicit activity much harder for criminal networks while building true operational resilience.”

More in P&C

Worse Than Asbestos?
P&C Worse Than Asbestos?
As personal injury and contamination claims proliferate across the nation, insur...
P&C The Causation Gap
Two evidentiary obstacles may forestall some PFAS-related litigation.
Steady as She Goes
P&C Steady as She Goes
While seeming to falter just a few years ago, the property market for personal l...
Fortifying the Castle
P&C Fortifying the Castle
While it might not seem obvious, workforce management is critical to sustaining ...
Sponsored By Travelers
Leading on Legal System Abuse
P&C Leading on Legal System Abuse
If brokers and carriers want a stable and predictable legal ...
Sponsored By CNA
Understanding Multinational Insurance in a Complex World
P&C Understanding Multinational Insurance in a Complex World
Q&A with Brian Grabek, Executive Vice President and Head of ...
Sponsored By Sompo