
The U.S. Federal Bureau of Investigation (FBI) warned the transportation and logistics business of a pointy upward push in cyber-enabled shipment robbery, with estimated losses in the US and Canada achieving just about $725 million in 2025.
This represents a 60% surge in losses in comparison to the former 12 months, fueled through criminals more and more the use of hacking and impersonation techniques to hijack high-value freight. Showed shipment robbery incidents have risen 18 p.c remaining 12 months by myself, whilst the typical cost consistent with robbery grew 36 p.c to $273,990, because of extra selective focused on of high-value quite a bit.
The bureau stated in a public provider announcement on Wednesday that risk actors were infiltrating the pc techniques of freight agents and carriers via spoofed emails and pretend internet hyperlinks since a minimum of 2024.
As soon as within, criminals submit fraudulent listings on on-line load forums (virtual marketplaces utilized by shippers, agents, and carriers) and impersonate official corporations to divert shipments.
For example, in February, the typosquatting tracking platform Have I Been Squatted reported that the Diesel Vortex financially motivated risk crew was once stealing credentials from freight and logistics operators within the U.S. and Europe in phishing assaults that have been operating since September 2025 and have been the use of 52 domain names.
“The Federal Bureau of Investigation is publishing this Public Provider Announcement (PSA) to warn the general public of cyber risk actors more and more the use of refined, cyber-enabled techniques to impersonate official companies to hijack freight, thieve high-value shipments, and reroute deliveries, leading to a surge of strategic shipment robbery,” the FBI warned.
“Cyber risk actors goal US transportation and logistics sectors, together with corporations with pursuits in delivery, receiving, handing over, and insuring shipment.”

Attackers first compromise dealer or provider accounts through luring workers to phishing websites that set up far off tracking device, after which acquire undetected get right of entry to to the centered corporate’s techniques.
Within the subsequent level, they submit tens of 1000’s of pretend freight listings, tricking official carriers into downloading malicious recordsdata, after which settle for actual shipments underneath a stolen provider identification. The quite a bit are rerouted to complicit drivers, stolen for resale, and, in some circumstances, the criminals additionally call for ransoms for the site of diverted quite a bit.
Risk actors related to cyber-enabled shipment robbery assaults may also adjust the compromised provider’s registration main points with the Federal Motor Service Protection Management and replace insurance coverage information, thus making sure that official corporations will uncover they’ve been hacked till agents document lacking shipments booked of their identify with out their wisdom.
To dam cyber-enabled shipment robbery makes an attempt, the bureau steered transportation and logistics corporations to make sure all cargo requests via secondary channels, put into effect and put in force multi-factor authentication when conceivable, validate all surprising communications the use of a two-factor authentication procedure, and handle detailed information of all automobiles and drivers.
The FBI additionally suggested sufferers of cyber-enabled shipment robbery schemes to report a criticism with the Web Crime Criticism Heart (IC3) along with submitting police stories for the stolen shipment.
In its 2025 Web Crime File, launched previous this month, the FBI stated IC3 won over 1 million lawsuits remaining 12 months, related to almost $21 billion in reported losses from quite a lot of cyber-enabled crimes, together with funding scams, tech give a boost to fraud, industry e-mail compromise, and information breaches.
AI chained 4 zero-days into one exploit that bypassed each renderer and OS sandboxes. A wave of latest exploits is coming.
On the Self sustaining Validation Summit (Might 12 & 14), see how self reliant, context-rich validation reveals what is exploitable, proves controls dangle, and closes the remediation loop.
Declare Your Spot



