Freight fraud controls must bind a verified company to the specific dispatcher, driver, equipment, pickup, route change, invoice, and bank account used on the load.
A carrier can have an active registration and still not be the company emailing you. An insurance certificate can look correct and still be altered. A driver can present a valid license and still have no relationship with the carrier on the rate confirmation.
That is the central problem in modern freight fraud: the individual artifacts may look plausible while the chain between them is false.
The practical control is:
Bind the regulated entity to a verified contact, the contact to the accepted tender, the tender to the actual driver and equipment, every change to an independently authenticated approver, and payment to the legal party that performed the agreed role.
No database check completes that chain by itself. It takes layered controls across onboarding, tender, pickup, transit, and payment.
Separate the schemes before designing the controls
“Double brokering” is often used as a catch-all for several failures. The response depends on which one occurred.
Unauthorized rebrokering or double brokering
A carrier accepts a brokered load and passes it to another carrier without the original broker's or shipper's knowledge or authorization. The hauling carrier may perform the work but not get paid because the original broker pays the carrier it hired. The load may also be diverted or stolen.
Identity theft and account takeover
A criminal impersonates a real carrier or broker, uses its USDOT or docket number, copies insurance or tax documents, compromises email, changes public contact data, or takes over a load-board account. The real company can be entirely uninvolved.
Fictitious pickup and strategic cargo theft
The facility releases cargo to a person or truck presented as the authorized carrier. The paperwork and pickup details were obtained through deception, compromise, or an unauthorized handoff.
Straight and cyber-enabled theft
Cargo is physically stolen from equipment or a facility, or an intrusion yields shipment data and documents. The FBI's cargo-theft taxonomy distinguishes straight, strategic, cyber, and pilferage methods and includes identity theft, fictitious pickups, account takeover, fraudulent carriers, and double-brokering scams.
Legitimate co-brokering, interlining, or authorized substitution
Not every second participant is fraudulent. Two properly authorized brokers may have a disclosed co-broker arrangement. Carriers may interline in circumstances recognized by law and the operating agreement. A shipper or broker may approve a replacement carrier.
The decisive questions are whether the role was disclosed, authorized, permitted by contract, accepted by the party controlling the tender, and documented before custody changed.
Legal role matters more than the name on the email signature
Under 49 CFR § 371.2, a broker arranges or offers to arrange property transportation by an authorized motor carrier for compensation. A motor carrier is not treated as a broker under that definition when arranging a shipment it is authorized to transport and has accepted and legally bound itself to transport. The boundary is fact-specific; calling an operation “dispatch,” “co-brokerage,” or “subcontracting” does not decide it.
FMCSA's final guidance on brokers and bona fide agents addresses this role boundary. 49 U.S.C. § 14916 addresses unlawful brokerage activity and penalties. Operators should escalate a recurring or ambiguous business model to transportation counsel rather than turning a fraud SOP into an improvised legal opinion.
The shipper's and broker's contract should be operationally plain:
- no transfer, substitution, co-brokering, or subcontracting without defined written authorization;
- no instruction to a driver or facility to misstate the carrier's identity;
- named process for an approved recovery carrier;
- obligation to disclose the legal carrier and registration performing the move;
- immediate notice of compromised credentials or public registration changes;
- audit and record-retention rights;
- payment consequences for unauthorized transfer, subject to applicable law.
Onboarding: verify the entity and the person separately
Authority checks answer whether a government record exists. Identity checks answer whether the person contacting you controls or legitimately represents that entity. Perform both.
1. Pull the current federal record from the source
As of this article's July 27, 2026 review, FMCSA directs public users to search entity registration records in Motus. The FMCSA Motus resource page describes public registration-record search and the current entity and authority structure. FMCSA also says filings and motor-carrier record activity after May 18, 2026 should be checked through Motus rather than relying on the legacy Licensing & Insurance system.
For the proposed role, confirm:
- legal and DBA names;
- USDOT identifier and any displayed registration suffix or docket reference;
- entity type;
- operating-authority type and status;
- physical and mailing addresses;
- public contact information;
- recent application, reinstatement, revocation, or update activity;
- required financial-responsibility filing status.
Use SAFER's Company Snapshot as an additional operational record where useful, but do not treat one “active” field as proof of identity, insurance, or safe performance. The motor-carrier vetting checklist covers operating history, safety, lane fit, and insurance in greater depth.
2. Establish a trusted contact route
Do not verify a suspicious email by calling the telephone number in that email.
Source the main number or account contact from the current FMCSA record, a previously verified vendor master, the company's established website, or another independent record. Call that route and confirm:
- the employee or agent exists;
- the email domain and address are authorized;
- the office tendered or accepted the specific load;
- the dispatch telephone number is legitimate;
- the company has not recently reported identity theft.
If the public record changed recently, add secretary-of-state records, prior transactions, independently sourced insurer or surety contacts, known executives, and load-board identity controls. A change warrants stronger verification; it is not proof of fraud.
FMCSA's broker and carrier identity-fraud alert recommends confirming phone numbers through federal records, warns that search results can contain fake profiles, and notes that even insurance certificates can be fraudulent.
3. Verify role-appropriate financial responsibility
FMCSA's insurance filing requirements show that property brokers and freight forwarders generally require a $75,000 BMC-84 surety bond or BMC-85 trust filing. That filing is a registration requirement and potential recovery source under its terms; it is not proof that a particular tender, email, or payment instruction is legitimate.
For a general for-hire property motor carrier, federal filings commonly concern bodily injury and property-damage financial responsibility, not a general federal cargo-insurance requirement. Household-goods and specialized operations differ. Independently call the agent or insurer to verify the named insured, dates, limits, commodities, exclusions, and certificate.
Do not set insurance limits by copying a competitor's packet. Match them to cargo value, theft attractiveness, mode, temperature exposure, and contractual liability.
4. Bind tax, payment, and company identity
Match the legal name across FMCSA registration, tax record, contract, rate confirmation, insurance, invoice, factoring assignment, and—where confirmation is available—the bank-account holder.
Generic email domains, unrelated remittance names, virtual addresses, and new accounts are not each proof of fraud. Combined with authority or contact inconsistencies, they justify enhanced review.
5. Protect your own registration and accounts
Carrier and broker identities are valuable credentials. Restrict who can update FMCSA registration, load-board profiles, insurer records, and payment data. Require phishing-resistant MFA where supported; CISA's implementation guidance for phishing-resistant MFA identifies FIDO/WebAuthn as the widely available option and also discusses public-key infrastructure. Log and review new users, tokens, forwarding rules, recovery-contact changes, unusual logins, payment edits, public-record changes, and bulk tender downloads.
Tender: bind one verified carrier to one load
Company approval is not pickup authorization. The tender record should identify the shipper and original broker; performing carrier and USDOT registration; verified dispatcher; expected driver and equipment; commodity risk; route, stops, and appointment; substitution rule; single-use pickup credential; and the owner and callback route for changes.
If the carrier says it cannot cover the load, cancel or execute the approved recovery process. Do not let a dispatcher forward the PDF to an unknown carrier and explain the change after pickup.
Red flags that should stop release, not merely add a note
Stop and authenticate when:
- the driver is told to present a different carrier name;
- the driver, tractor, trailer, or plates do not match the approved record;
- the carrier asks to change pickup or delivery through an unverified email, text, or messaging account;
- a dispatcher refuses callback through the verified main number;
- the rate is far outside the expected lane context without an operational explanation;
- insurance, W-9, authority, and payment names conflict;
- the load is re-tendered after pickup;
- someone requests a “blind” move without an approved, documented commercial reason;
- a newly supplied domain closely resembles a known company's domain;
- a bank or factoring change arrives with unusual urgency.
FMCSA specifically flags instructions to lie about carrier identity, suspicious blind-load directions, and extreme rates. Those are escalation triggers, not a complete fraud model.
Pickup: the facility is the cargo-release control
A beautifully vetted packet has no value if the guard shack releases freight based on a pickup number alone.
Send the facility a controlled release record containing only the information it needs:
- load and appointment number;
- performing carrier legal name and USDOT number;
- driver's expected name or another privacy-appropriate identity field;
- tractor and trailer identifiers;
- single-use pickup credential;
- shipper or broker escalation contact sourced from the facility's own approved directory;
- instruction that changes require out-of-band confirmation.
At arrival, the facility should:
- compare the person, carrier, tractor, and trailer with the release record;
- call the approved escalation route if any element differs;
- record driver and equipment details appropriate to policy and law;
- photograph or otherwise document tractor, trailer, and plates where risk and site policy justify it;
- record seal number after loading;
- issue a pickup or gate receipt;
- invalidate the release credential.
For higher-risk loads, use two-person release approval and avoid staging a loaded trailer where it can be collected without repeating identity checks. The FBI recommends positive driver identity, secure pickup numbers, and recording truck and trailer identifiers.
The driver's license is personal identity evidence, not proof that the driver works for the authorized carrier. Confirm the employment or dispatch relationship through the verified carrier contact.
In transit: authenticate changes more strongly than the original plan
Fraud often succeeds after legitimate pickup through a false diversion, changed delivery, compromised email, or purported recovery instruction.
Require out-of-band approval for any delivery or consignee change, cross-dock or storage instruction, trailer drop or relay, route exception, new contact, seal break, reconsignment, or change in performing carrier.
The approver should call a known number, not reply to the message requesting the change. Record who authorized it, when, why, and what source was used to authenticate the person.
For theft-attractive freight, select controls by risk:
- route and geofence monitoring;
- scheduled check-ins through a verified application or number;
- safe-parking and no-unattended-load rules;
- high-security locks and seal protocol;
- no-stop or minimum-distance plan where lawful, safe, and feasible;
- covert tracking independent of the tractor;
- rapid escalation for signal loss, route deviation, or unexpected door opening;
- team service or escort where economics justify it.
The security plan must remain executable without pressuring a driver to violate hours-of-service, parking, weather, or safety requirements.
Payment: verify the party that hauled and the party entitled to collect
Double-brokering fraud frequently becomes visible when two carriers seek payment or a carrier invoice names a different entity from the tender.
Before release of funds, match:
- accepted rate confirmation;
- carrier that physically appeared at pickup;
- tractor, trailer, driver, and gate record;
- bill of lading and proof of delivery;
- invoice legal entity and registration;
- verified factoring assignment;
- vendor-master bank account;
- duplicate load, invoice, and payment checks.
Verify every bank or factoring change through a previously trusted contact and hold payment while inconsistencies are investigated. Do not use the new telephone number included with the change request.
Broker records can aid reconciliation. 49 CFR § 371.3 requires transaction records including the originating carrier's identity and registration, bill or freight number, compensation, charges collected, and payment date, and gives each party a right to review the required record. It makes “we do not know who hauled it” an unacceptable operating outcome.
If competing payment claims emerge, preserve funds and obtain legal guidance. Do not tell a carrier to hold cargo hostage or encourage unsafe self-help. FMCSA notes that the real broker and hauling carrier may both be victims and urges them to cooperate.
Assign controls to the teams that can execute them
| Stage | Primary owner | Required release artifact |
|---|---|---|
| Company onboarding | carrier compliance | verified entity, role, contact, authority, insurance and payment record |
| Load tender | broker or transportation planner | load-specific performing-carrier authorization |
| Pickup | facility security and shipping lead | identity and equipment match, pickup credential, gate record, seal |
| In transit | carrier dispatch and shipper/broker operations | tracking, exception log, authenticated change record |
| Delivery | receiver | seal, equipment, condition, count and proof of delivery |
| Payment | accounts payable and broker audit | tender-to-gate-to-POD-to-payee match |
| Incident | security, claims, legal and insurer | preserved evidence, location, reports, recovery actions |
Carrier compliance cannot own fraud alone. It is not present when the wrong tractor arrives, an email changes destination, or finance accepts a new bank account.
Incident response: move faster than the paperwork
If a load may be compromised:
- Protect people and stop the next irreversible action. Do not confront suspected thieves; pause release, diversion, account change, or payment where possible.
- Locate the freight. Use verified contacts, telematics, independent trackers, and facility records.
- Preserve evidence. Export messages with headers, calls, login records, tender versions, documents, gate images, GPS, bank instructions, and payment records.
- Notify and report. Alert the real shipper, broker, carrier, facilities, insurer, security provider, load board, factor, and bank as relevant. Contact law enforcement and use the FBI, FMCSA, and DOT OIG channels identified in FMCSA's fraud guidance.
- Secure accounts and open recovery clocks. Revoke sessions, reset credentials from a clean device, inspect forwarding rules and recent transactions, notify insurers, and preserve the records needed for the freight-claims process.
The incident log should distinguish confirmed facts from hypotheses. A real carrier whose identity was stolen may be a witness and victim, not the perpetrator.
Measure whether the control catches anything
Track tenders stopped for identity mismatch; pickups escalated for driver or equipment mismatch; unapproved substitutions; bank changes confirmed or rejected; route and seal exceptions; response time; false positives; losses and recoveries; and high-risk loads with complete release records.
A control that produces hundreds of alerts and no release decisions will be bypassed. Tune thresholds, but do not remove independent authentication from the events that transfer cargo or money.
The operating takeaway
Freight-fraud prevention is a chain, not a carrier score.
Verify the regulated company. Verify the human through an independent route. Authorize the performing carrier on the individual tender. Match the driver and equipment at pickup. Authenticate every material change out of band. Pay only after the custody and legal-entity records reconcile.
The criminal needs only one uncontrolled handoff. Your process must make each handoff prove continuity.
This article provides operational education, not legal, cybersecurity, insurance, or law-enforcement advice. Registration, brokerage, privacy, contract, and reporting obligations are fact-specific; involve qualified professionals in policy design and active incidents.
Sources and further reading
- FMCSA: Broker and carrier fraud and identity theft prevention and reporting
- FBI: Cargo-theft methods, prevention, and reporting
- 49 CFR Part 371: Federal broker definitions, records, and misrepresentation rules
- FMCSA: Final guidance on broker and bona fide agent definitions
- 49 U.S.C. § 14916: Unlawful brokerage activities
- FMCSA: Motus registration and public-search resources
- FMCSA: Where to check filings and record activity after the Motus transition
- FMCSA: Insurance and broker financial-responsibility filing requirements
- CISA: Implementing phishing-resistant multifactor authentication
