New research by Proofpoint shows that criminal hacking groups are penetrating trucking carriers and freight brokers to obtain remote access and impersonate legitimate operators in logistics workflows. With freight markets still competitive and load-board activity elevated, attackers are exploiting urgency and fragmented communication to slip into dispatch operations before safeguards catch up.
Cargo Theft Goes Fully Digital
Proofpoint analysts say they have “high confidence” that criminal hackers are collaborating with established cargo-heist networks, using social engineering and industry knowledge to divert shipments. Instead of spoofed pickups alone, recent attacks involve compromising carrier systems through fraudulent load postings, malicious links disguised as onboarding documents, and remote-access tools that appear legitimate at first glance.
The approach reflects a significant shift: criminals are not only exploiting freight documentation but embedding themselves into logistics platforms. Once inside a brokerage or carrier system, attackers can alter pickup details, impersonate dispatchers, and reroute freight, often without detection until the truck never arrives. “It is a full-scale supply chain threat,” Proofpoint analyst Selena Larson said in an official statement.
Cargo losses surged 27% in 2024 and are expected to climb another 22% this year, according to the National Insurance Crime Bureau, which pegs annual losses around $35 billion. Food, beverages, and consumer electronics remain top targets, with researchers noting energy drink shipments are frequently resold overseas where certain products are restricted. Over the past two months, Proofpoint identified nearly two dozen related campaigns involving at least three distinct cyber threat groups coordinating these schemes.
Load Boards and Urgency Provide Attack Surface
The attackers’ playbook leans on speed and trust in broker-carrier relationships. Fraudulent postings on load boards, a core tool for matching freight, serve as entry points for phishing emails posing as dispatch confirmations. With capacity tight in certain lanes and carriers eager to secure loads quickly, malicious onboarding packets can go unnoticed until remote-access tools are installed.
According to the research, one October incident involved a broker impersonation email claiming a carrier was “ready to go,” complete with weight, pickup window, and delivery details, a level of operational realism that pressures teams to move fast. “There’s a huge sense of urgency to get loads,” Proofpoint researcher Ole Villadsen noted, emphasizing that dispatchers “may not think twice” before clicking a trusted-looking link.
While the observed activity centers on North America, analysts say the operational playbook is spreading globally. Indicators point to hacker activity potentially originating from Russia or Eastern Europe, consistent with patterns observed in broader cybercrime ecosystems. Freight-fraud monitoring firms and insurance carriers have also recently warned of cross-border collaboration between cybercriminals and cargo rings, highlighting the convergence of digital intrusion and physical theft.
A New Competitive Line of Defense
The shift toward cyber-enabled cargo theft may accelerate the divide between companies treating digital security as a compliance checkbox and those building it into everyday freight decisions. Recent industry reporting shows insurers already adjusting premiums and coverage terms around cyber-driven logistics fraud, signaling where accountability is headed. As markets harden and capital stays selective, the companies that prove they can secure freight transactions end-to-end, from load boards to loading docks, may find themselves with pricing leverage and preferred-shipper status in lanes where trust becomes as valuable as capacity.