How a Compromised Dispatcher Email Led to a Stolen Load

Why email, phone verification, and pickup numbers alone may not be enough to secure freight

By LoadShield
Category: Freight Fraud & Security

This article is based on a real freight-fraud incident experienced by a carrier and the circumstances that helped inspire the development of LoadShield.

A Load Can Be Stolen Before the Truck Arrives
Freight fraud does not always begin at the warehouse.
Sometimes, it begins with a compromised email account.
A criminal who gains access to a carrier’s communication can potentially obtain a rate confirmation, manipulate driver information, spoof a phone number, and communicate directly with a broker while appearing to represent the legitimate carrier.
In one real-world incident, that is exactly what happened.
The incident demonstrated a critical weakness in the traditional freight process: A shipment can remain vulnerable even after the legitimate carrier discovers the fraud and asks for the load to be canceled.


It Started With a Rate Confirmation
A broker sent a rate confirmation PDF to a dispatcher’s email address.
Unknown to the carrier, the dispatcher’s email account had been compromised.
The criminal responded to the broker from the compromised email account and requested that the driver’s name and phone number be changed to another name and phone number.
Because the carrier was a small operation and knew its dispatchers and drivers personally, the request immediately raised a red flag.
The carrier called the dispatcher and asked: “Who is the driver you want to use to move this load instead of the assigned driver?”
The dispatcher confirmed that he had not made the request.
The carrier now knew that someone else was communicating with the broker while appearing to represent the company.


The Criminal Was Already Inside the Communication Chain
The carrier immediately contacted the broker and explained that the communication channel had been compromised. The carrier instructed the broker to cancel the load.
While the carrier was on the phone with the broker, the criminal called again using the dispatcher’s spoofed phone number. The call was merged with the broker.
As the carrier explained that the communication had been compromised and that the load needed to be canceled, the criminal attempted to talk over the carrier and told the broker not to cancel the load.
At that point, it was clear that this was more than a suspicious email. Someone was actively attempting to impersonate the carrier and take control of a legitimate shipment.
The carrier ended the call and immediately sent the broker an email instructing the broker to cancel the load. The carrier believed the situation had been stopped.
It wasn’t.


The Broker Lost the Load
The following day, the broker called the carrier.
The broker asked: “Did your driver go pick up the load?”
The carrier reminded the broker that they had spoken the previous day and that the load was supposed to have been canceled because the communication had been compromised.
Then came the critical information: The criminal had picked up the load.
The broker had lost the shipment to the criminal.
The broker had sent an email to the warehouse instructing them to cancel the pickup. However, the cancellation apparently did not reach the warehouse—or was not acted upon—in time.
The pickup information was already contained in the compromised rate confirmation.
The criminal had enough information to impersonate the authorized party and obtain the freight.
This incident exposed an important weakness in the traditional process: Canceling a load through email is not necessarily the same as revoking the authorization to pick up the freight.


The Problem With Relying on a PDF and Pickup Number
The traditional freight process relies heavily on documents and communications. A broker sends a rate confirmation. The carrier receives it. Driver information is exchanged. A pickup number is provided. The driver arrives at the facility and provides the required information. The warehouse releases the freight.
The process can work efficiently—until the communication channel is compromised.
An email account can be compromised. A PDF can be forwarded. A phone number can be spoofed. Driver information can be manipulated. A pickup number can be shared.
And once a criminal has obtained that information, an email telling the warehouse to “cancel the load” may not be enough.
The industry needs another layer of authorization.


What If the Load Had a Digital Pickup Token?
This type of incident helped inspire the concept behind LoadShield.
Instead of relying solely on a PDF rate confirmation and a pickup number, a broker can issue a digital pickup token associated with the specific shipment and its authorized transportation parties.
The authorization can be connected to:
• Verified carrier
• Verified driver
• Assigned truck
• Specific shipment
• Pickup location
• Load assignment
The driver presents the digital token at pickup. The authorization can then be verified before the freight is released.
Now consider what happens when a broker discovers that a carrier’s communication channel has been compromised. Instead of relying solely on another email to the warehouse, the broker can revoke the digital pickup authorization.
The criminal might still possess the original PDF. The criminal might still know the pickup number. The criminal might still have access to the compromised email account. The criminal might even spoof the carrier’s phone number.
But those things alone would not constitute a valid digital pickup authorization. The authorization itself can be revoked.


Securing the Shipment—Not Just the Communication
This distinction is central to the LoadShield approach.
The objective is not simply to protect email. The objective is to protect the shipment assignment and pickup authorization.
A secure shipment assignment should establish:
Who is the carrier?
Who is the driver?
What truck is assigned?
What shipment are they authorized to move?
Where is the pickup?
Is the pickup authorization still valid?
When those elements are digitally connected, a discrepancy can be identified before the freight is released.
This creates another layer of protection between a compromised communication channel and the physical movement of the freight.


Connecting the Carrier, Driver and Truck
A digital pickup token becomes more meaningful when it is connected to verified transportation information.
The authorization can establish a relationship between:
Carrier → Driver → Truck → Load → Pickup
The broker knows which carrier was assigned. The carrier knows which driver was assigned. The driver is connected to the assigned equipment. The shipment is connected to the pickup location. The digital authorization connects those elements.
This makes it more difficult for someone to simply change a driver’s name in an email and become the person authorized to pick up the shipment.


Helping Reduce Unauthorized Load Transfers and Double Brokering
The same approach can help address unauthorized load transfers and double brokering.
Suppose a broker assigns a shipment to Carrier A. Carrier A has a verified driver and assigned truck. If a different carrier or driver attempts to pick up the shipment without authorization, the pickup information may not match the original shipment assignment.
That discrepancy can trigger additional verification before the freight is released.
Instead of asking only: “Do you have the pickup number?” the process can ask: “Are you the verified carrier, driver, and truck authorized for this shipment?”
If a load is legitimately transferred, the transfer can be documented and the shipment authorization updated. If the transfer is unauthorized, the discrepancy can be identified before the freight changes hands.


Freight Fraud Is an Identity and Authorization Problem
This incident demonstrates that freight fraud is not simply a paperwork problem. It is not only an email problem. And it is not only a carrier-verification problem.
At its core, freight fraud is also an identity and authorization problem.
The industry needs to know not only which carrier was assigned a shipment, but also who is actually authorized to take possession of it.
That is why LoadShield is designed around several connected concepts:
Verify the carrier.
Verify the driver.
Verify the truck.
Secure the load assignment.
Authenticate the pickup.
Maintain shipment visibility.
Capture delivery documentation.
The goal is to create another layer of protection between legitimate freight and unauthorized parties attempting to impersonate the carrier, driver, or other participants in the shipment.


From a Carrier’s Experience to a Security Solution
The incident that inspired this approach began with something ordinary: a rate confirmation sent by email.
It ended with a criminal successfully picking up a legitimate shipment.
The legitimate carrier had identified the compromise. The broker had been notified. A cancellation had been requested. But the freight was still vulnerable because the pickup authorization itself had not been securely revoked.
That experience helped establish an important principle behind LoadShield:
DON’T JUST SECURE THE COMMUNICATION. SECURE THE AUTHORIZATION TO MOVE THE FREIGHT.


The Future of Secure Freight Pickup
Freight moves through a complex network of brokers, carriers, drivers, shippers, warehouses and receivers. Each participant depends on accurate information from the others.
As criminals become more sophisticated, the industry needs security mechanisms that go beyond traditional communication methods.
Digital shipment authorization can provide another layer of protection by connecting the carrier, driver, truck, load and pickup into a verifiable chain.
That is the direction LoadShield was designed to pursue.
Secure the assignment.
Verify the pickup.
Protect the freight.


About LoadShield
LoadShield is a freight security and execution platform designed to help brokers and carriers verify transportation participants, secure shipment assignments, authenticate pickups, maintain shipment visibility, and manage electronic freight documentation.
Protecting What Moves the World.