Home › Insights › Logistics Security · Business Email Compromise
Logistics Security · Business Email Compromise

How compromised business email can contribute to freight fraud—and how to reduce the risk

A hijacked mailbox or convincing impersonation can turn a routine logistics message into a costly mistake. Practical checks for trucking, brokerage, and shipping teams.

Defenssive Security Insights·6 minute read·General guidance

Email is part of how freight gets coordinated: teams exchange quotes, pickup details, bills of lading, delivery changes, and invoices. That makes a trusted-looking message useful to criminals. They may impersonate a broker, carrier, shipper, or employee—or use a real compromised account—to make a fraudulent request feel like normal business.

Scope: This is a general security explainer, not a report about a Defenssive customer or a specific trucking company. It summarizes publicly documented fraud patterns and practical safeguards.

How email fraud can put a load at risk

Business email compromise (BEC) is not limited to fake payment requests. In a logistics workflow, the same trust in names, email threads, and familiar processes can be abused to influence who gets a load, where it goes, or whether a shipment is released. The precise method varies; email may be one part of a wider fraud operation.

Federal agencies have publicly described BEC-enabled theft of physical goods, including food shipments, and more recent cyber-enabled freight theft schemes involving compromised accounts, spoofed emails, and rerouted loads. Those advisories show why shipment verification and account security need to work together. See the source links below for the specific cases and scope.

Practical safeguards for logistics teams

1Verify changes out of band. For a new pickup, destination, payment instruction, or carrier contact, call a phone number already on file—not a number included in the change request.
2Confirm the shipment and the people. Use a documented process for validating the broker, carrier, driver, vehicle, load reference, pickup location, and delivery details before releasing freight.
3Protect Microsoft 365 sign-ins. Require multifactor authentication, prioritize phishing-resistant methods where practical, remove stale accounts, and tightly control administrator access.
4Watch for mailbox changes. Investigate unexpected forwarding rules, delegates, inbox rules, app consents, and sign-ins—especially after a user reports a suspicious link or unexpected prompt.
5Separate approval from execution. Use a second person to approve high-impact changes to payment details, credit, carrier records, or load destinations.
6Secure every account in the workflow. Review access to transportation management systems, load boards, vendor portals, and shared mailboxes; use unique credentials and MFA wherever available.

No single control prevents every fraud attempt. The goal is to make an attacker’s request harder to trust, harder to execute, and quicker to detect.

If a request or shipment seems suspicious

  1. Pause the release, reroute, or payment while your team independently verifies it.
  2. Contact the supposed broker, carrier, or partner using a trusted number already in your records.
  3. Notify your security and operations leads. Preserve the email, headers, load documents, call details, and relevant account activity.
  4. If an account may be compromised, use your incident process to contain access and review sign-ins, mailbox rules, delegated access, and connected apps.
  5. If freight or money has been lost, contact law enforcement and the appropriate financial institution promptly; report cyber-enabled crime to the FBI’s Internet Crime Complaint Center (IC3).

A short checklist to take back to your team

  • Which shipment or payment changes require a callback to a known number?
  • Who can update carrier, destination, or payment records—and who approves those changes?
  • Do dispatch and finance teams know how to report suspicious emails and unexpected MFA prompts?
  • Can your IT team quickly review Microsoft 365 sign-ins, inbox rules, forwarding, and app access?

Sources and further reading

The article above is general guidance. These public advisories describe the documented patterns and recommendations:

← Back to all Insights