Email is part of how freight gets coordinated: teams exchange quotes, pickup details, bills of lading, delivery changes, and invoices. That makes a trusted-looking message useful to criminals. They may impersonate a broker, carrier, shipper, or employee—or use a real compromised account—to make a fraudulent request feel like normal business.
How email fraud can put a load at risk
Business email compromise (BEC) is not limited to fake payment requests. In a logistics workflow, the same trust in names, email threads, and familiar processes can be abused to influence who gets a load, where it goes, or whether a shipment is released. The precise method varies; email may be one part of a wider fraud operation.
One message can cross the boundary from inbox to operations.
Illustrative sequence only; real incidents do not always follow these steps or begin with email.
Federal agencies have publicly described BEC-enabled theft of physical goods, including food shipments, and more recent cyber-enabled freight theft schemes involving compromised accounts, spoofed emails, and rerouted loads. Those advisories show why shipment verification and account security need to work together. See the source links below for the specific cases and scope.
Practical safeguards for logistics teams
No single control prevents every fraud attempt. The goal is to make an attacker’s request harder to trust, harder to execute, and quicker to detect.
If a request or shipment seems suspicious
- Pause the release, reroute, or payment while your team independently verifies it.
- Contact the supposed broker, carrier, or partner using a trusted number already in your records.
- Notify your security and operations leads. Preserve the email, headers, load documents, call details, and relevant account activity.
- If an account may be compromised, use your incident process to contain access and review sign-ins, mailbox rules, delegated access, and connected apps.
- If freight or money has been lost, contact law enforcement and the appropriate financial institution promptly; report cyber-enabled crime to the FBI’s Internet Crime Complaint Center (IC3).
A short checklist to take back to your team
- Which shipment or payment changes require a callback to a known number?
- Who can update carrier, destination, or payment records—and who approves those changes?
- Do dispatch and finance teams know how to report suspicious emails and unexpected MFA prompts?
- Can your IT team quickly review Microsoft 365 sign-ins, inbox rules, forwarding, and app access?
Sources and further reading
The article above is general guidance. These public advisories describe the documented patterns and recommendations:
- FBI / IC3, “Cyber-Enabled Strategic Cargo Theft Surging” (April 30, 2026) — compromised broker and carrier accounts, spoofed links, and redirected loads.
- FBI, FDA OCI, and USDA, “Criminal Actors Use Business Email Compromise to Steal Large Shipments of Food Products and Ingredients” (December 15, 2022) — documented BEC schemes involving food orders and shipments, plus verification recommendations.
- FBI, Business Email Compromise guidance — common BEC patterns and protective steps.
