The fastest-growing way to steal a truckload now starts in an email account. Somebody takes a carrier's identity, passes a broker's vetting, books the load and sends it somewhere else, and nobody touches a lock the whole time.
Estimated cargo theft losses across 2025, up 60% on the year before. The average single loss reached $273,990, itself up 36%.
1,475%
Growth in strategic theft between 2022 and 2024, against 93% for cargo theft overall. Strategic theft is now around a third of all cargo crime, from under 5% in 2010.
1,218
Incidents in California during 2025, more than any other state. If you move freight through this state you are operating in the worst of it.
Loss and incident figures from Verisk CargoNet's 2025 analysis, which adjusts for delayed reporting by comparing 2025 data as at 12 January 2026 with 2024 data as at 12 January 2025. Strategic theft growth from trucking industry reporting on the same period. Neither is our data.
How the load actually goes missing
Nobody cut a lock. They logged in.
Strategic theft works through paperwork and credentials, which is why it grew fifteen times faster than the kind involving a crowbar. Every step below is a step your IT can make harder.
How they get in
Your own mailbox books the load
The cleanest version of this crime uses a real account. Somebody gets into a carrier's or a broker's email, watches the traffic for a while, then books shipments from inside the business using the address everyone already trusts. The shipper sees a familiar sender, correct signature block and a history of prior messages, because all of it is real. Nothing about the message looks wrong, so the controls that matter are the ones that stop the account being taken in the first place and the ones that notice a login from somewhere strange.
The load board password reset that is not one
A message arrives that looks like your load board asking you to reset a password, and the link goes to a copy of the site that harvests whatever gets typed into it. Dispatchers work fast and click fast, which is exactly what the message is built for. Two things blunt it: filtering that catches most of them before anybody sees one, and short repeated training so the ones that get through meet somebody who has seen the pattern recently.
The tracking portal is a target too
Access to a tracking portal tells a thief which trailer is worth taking and where it will be. The same access supports spoofed location data that hides a route change for long enough to matter. These accounts tend to be shared, rarely reviewed and often left active for people who moved on, because nobody thinks of a tracking login as a security asset. It is one, and it wants the same treatment as your email.
What stops it
Multifactor on every account that touches a load
Email first, because that is where the impersonation starts, then the load boards, the tracking portals and anything that can change where a truck goes. The gap we find most often is not the main mailbox, which usually has it. It is the shared dispatch account, the old address that still forwards, and the portal login three people know the password to. Those are the ones worth an afternoon.
A rule for changing where a truck goes
Mid-haul rerouting and banking detail changes are where the money leaves, and both usually arrive as a plausible message during a busy hour. The control is procedural and it costs nothing: a reroute or a payment change gets confirmed on a number already on file, never a number in the message asking for it. We write it down and put it where dispatch can see it, so a new hire meets the rule in their first week instead of their first incident.
Who still has access, and who left
Freight runs on turnover, seasonal staff and owner-operators who come and go. Access tends to outlast all of them. Rights get handed out by whoever was on shift and reviewed by nobody. We keep a list of who can reach what and take access away the day somebody leaves, with each person holding only the rights their job needs. It is unglamorous and it removes a whole category of problem, including the one where a former dispatcher still has the tracking portal on their phone.
The question this industry always asks
You run nights and weekends. Here is exactly what we cover, and what we do not.
Most providers answer this with two words and hope nobody reads the agreement. You are going to get the actual shape of it, because finding out at 2 AM is how a relationship ends.
Around the clock
Your systems are monitored
Servers, workstations and network gear report in continuously, every day of the year. Disks, backups, services that stopped, patches that failed. If something goes down at 3 AM the record of it starts at 3 AM, not when somebody arrives and finds it.
Around the clock
Security has a person on shift
Security alerts go to Huntress, whose analysts are on shift at every hour, and they triage and act on it there and then. That matters here because the theft described above happens through an account takeover, and an account takeover at 2 AM is the one you most want interrupted.
Weekdays, 5 AM to 6 PM Pacific
The help desk
Ordinary support runs on staffed hours, and we are not going to pretend otherwise on a page you will hold us to. A 5 AM start covers a dispatch shift that begins before dawn. If your operation needs a person reachable outside those hours, say so early and we will price it honestly or tell you we are the wrong fit.
The full detail of what gets watched, what raises an alert and what happens next is on the monitoring page.
Who we do this for
Child Truck Line, and the backup that went home in a bag
Child Truck Line has hauled full truckload freight across Washington and Oregon since 1979, and Child Logistics is their brokerage division. When we assessed them in 2018 the nightly backup was a physical copy that a member of staff carried home. The server dropped a few times a month, and each time the operation stopped for hours because access ran through one person.
What we did was unglamorous. We moved the data to cloud services and replaced the infrastructure, with real processes put around both. Then we designed and oversaw a Wi-Fi network across their new warehouse so inventory could be scanned live on the floor.
Over the years that followed they moved from an 80,000 square foot building to 385,000, roughly tripled revenue and more than doubled headcount. We are not going to tell you IT did that. What we will say is that the technology stopped being the thing holding it back, and it kept up as they grew.
In their words
“We were constrained by an archaic system, relying on inferior equipment and technology with a rat's nest of wires in the backroom. We knew we needed to make significant changes so we could compete and grow.”
James Carroll, President, Child Truck Line
The whole engagement is written up as a case study.
Common questions
Do you support us outside business hours?
Monitoring runs continuously, so a failure overnight is recorded at the time it happens. Security alerts reach analysts who are on shift at any hour and who act on them. The help desk runs weekdays from 5 AM to 6 PM Pacific, which covers an early dispatch shift but is not the same as somebody answering a phone at midnight. Plenty of providers blur those three into one phrase. If a person reachable overnight is a hard requirement for your operation, tell us at the start and we will either price it properly or say we are not the right fit.
Is cargo theft an IT problem?
About a third of it, yes, and that share is the part growing fastest. Strategic theft rose fifteen times faster than cargo theft overall between 2022 and 2024, and it runs on stolen identities and compromised email instead of physical entry. The controls the freight industry recommends against it are the ones a managed provider installs anyway: multifactor authentication, access limited to what a role needs, a verification step before a reroute or a banking change, and a plan for the day something goes wrong. We cannot help with a fence or a yard camera. We can make the version of this that happens through your mailbox considerably harder.
Our warehouse Wi-Fi drops when the scanners move to the back racks. Is that fixable?
Usually, and it is rarely solved by adding another access point where the signal drops. Racking changes as stock changes, and metal moves signal around in ways an empty building never predicts. A design done before the shelves went in stops matching the room. We survey the space as it actually is, loaded, then place and tune coverage for the aisles people scan in. We have designed this across a 385,000 square foot warehouse for live scanning, so the scale is familiar.
What happens to dispatch if the internet goes down?
That depends entirely on decisions made before it happens, which is the useful part of the question. A second connection on a different carrier that fails over on its own costs less than most people assume and is the single best spend in this industry, because a dispatch floor that cannot reach its systems is an operation that has stopped. Beyond the line itself: which systems have to keep working, how people reach them from a phone, and who has the numbers if the phone system is the thing that broke. We work that out with you and write it down, so nobody is inventing it during the outage.
Do you work with our transportation and warehouse management systems?
We look after everything those systems depend on and we coordinate with the vendor who supports the application itself. That means the servers or the connections they run over, the identities and the multifactor in front of them, the network in the building, the backups, and the performance of the machines your dispatchers work on. When something breaks it is often unclear whether it belongs to the application or the environment underneath, and sitting between those two is where we are useful. Tell us which products you run and we will be straight with you about where our knowledge ends and the vendor's begins.
We are a broker rather than an asset carrier. Does any of this apply?
More of it, if anything. Brokers sit at the exact point the fraud targets, because the scheme depends on impersonating one to a carrier or a carrier to one. Your reputation with shippers rests on load information and payment instructions coming from you and only from you, and both travel by email. Everything on this page about account takeover, verification before a payment change, and knowing who still has access matters more to a brokerage than to a fleet. One of our longest-standing clients runs both sides of that business.
Which of your dispatch accounts is missing multifactor?
It is almost never the main mailbox. It is the shared one.