The Federal Bureau of Investigation (FBI) has issued a public warning of a sharp increase in cargo theft cyberattacks, as threat actors increasingly use digital tactics to impersonate legitimate businesses, hijack cargo, and steal high-value shipments.
See also: iOS 26.4.2: Fixes vulnerability that allowed the FBI to read Signal messages

According to the FBI, cybercriminals are targeting shipping and accounting companies involved in the transportation, receiving, and insurance of cargo. The agency said these attacks have been ongoing since 2024 and are now becoming more sophisticated and widespread.
Losses associated with cargo theft cyberattacks have increased significantly. In 2025, estimated cargo theft losses in the United States and Canada reached nearly $725 million, a 60 percent increase over the previous year.
Confirmed incidents increased by 18 percent, while the average value per theft increased by 36 percent to $273,990, reflecting a shift toward more targeted, high-value shipments.
How Cargo Theft Cyberattack Works
The FBI has described a structured process used in cargo theft cyberattack schemes. Attackers begin by compromising broker and carrier accounts through phishing techniques such as forged emails, fake websites and malicious links.
Victims often receive emails that appear to be legitimate business communications, such as carrier agreements or service complaints. These emails include links that lead to phishing websites designed to mimic trusted platforms. Once accessed, these websites install malware or remote monitoring tools, allowing attackers to gain complete control of systems without detection.
Once they gain access, cybercriminals exploit online freight marketplaces known as load boards. They pose as legitimate brokers or carriers and post fake shipping lists, sometimes in large volumes. Unsuspecting carriers bid on these lists and are further compromised through fraudulent deals or malicious downloads.
See also: FBI Destroys APT28's DNS Hijacking Network

In the next stage, the attackers use the compromised accounts to accept real shipping contracts. They then engage in illegal double brokerage, redirecting shipments to unintended locations. Shipping documents are falsified, including bills of lading, and delivery destinations are changed without the knowledge of the original parties.
The final stage of a cargo theft cyberattack involves the physical diversion of the cargo. The goods are transferred via cross-docking or transloading to other drivers, often accomplices, and then stolen for resale. In some cases, the attackers demand ransom payments in exchange for information about the location of the shipment.
The FBI has identified several warning signs that may indicate a cyberattack to steal cargo. These include unexpected communications about shipments made in the name of a company, spoofed domain emails, and requests to download documents from suspicious links.
Other signs include emails referring to negative reviews of services with embedded links, unauthorized changes to email account settings, and slight variations in domain names designed to mimic legitimate organizations. Attackers may also use temporary or online phone numbers to contact victims.
These tactics are designed to create a sense of urgency or legitimacy, increasing the likelihood that employees will interact with malicious content.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Steps to Prevent Theft
To reduce the risk of cargo theft cyberattacks, the FBI is urging organizations to adopt stronger verification and security practices. Companies are advised to independently verify shipping requests using multiple communication channels before releasing goods.
The service recommends implementing multi-layered verification processes and not relying solely on known names or email addresses. Businesses should also maintain detailed records of all transactions, including driver identification, vehicle details and communication records, to support investigations if needed.
See also: FBI: Cybercrime led to $20 billion in losses in 2025

Recognizing phishing attempts and avoiding interaction with suspicious links remain critical preventive measures.
