Threats · 133 days ago
Cargo theft is no longer just a physical security problem. Criminal groups are turning broker email, carrier accounts, and load boards into theft infrastructure, so a legitimate shipment can be redirected without anyone breaking into a warehouse or truck yard.
The FBI says this has been happening since at least 2024, and losses topped $700 million in 2025, up 60% from 2024. The warning lines up with earlier alerts from Proofpoint and NMFTA, and it affects brokers and carriers handling high-value freight across the transportation sector.
The practical risk is persistence. Once attackers control broker workflows and carrier identities, they can keep stealing loads through normal business processes, even if the original phishing or malware entry point is closed.
5 sources covering this story
FBI warns cyber-enabled cargo theft is surging as losses hit $725 million in 2025 - Industrial Cyber
FBI warns cyber-enabled cargo theft is surging as losses hit $725 million in 2025, driven by phishing and spoofed logistics attacks.
Physical Cargo Theft Gets a Boost From Cybercriminals
Supply chain theft is no longer just criminal groups operating locally, but transnational cybercriminal syndicates exploiting IT systems to reroute goods.
FBI Warns of Surge in Hacker-Enabled Cargo Theft
A new alert from the FBI says criminal enterprises are hacking both brokers and carriers to steal cargo for resale.
The Record from Recorded Future
Hackers earning millions from hijacked cargo, FBI says
In an advisory this week, FBI officials said cyber actors have spent the last two years breaking into the systems of brokers and carriers — allowing them to pose as victim companies and post fraudulent listings on freight delivery message boards.
FBI links cybercriminals to sharp surge in cargo theft attacks
Federal Bureau of Investigation (FBI) warned the transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada reaching nearly $725 million in 2025.
Part of the PlainSec briefing for 2026-05-05