Eight Indicted, Six Loads Stolen: How a $4.49M Carrier Impersonation Ring Beat Depot-Level Verification

What Happened
On June 4, 2026, the Manhattan District Attorney's Office unsealed a felony indictment charging eight individuals with participating in a multi-state cargo theft conspiracy that prosecutors allege produced $4.49 million in stolen freight across six separate incidents. The scheme ran from October 2025 through April 2026, targeting logistics facilities in New Jersey, Pennsylvania, and Virginia.
The core tactic was simple and devastatingly effective: the defendants allegedly obtained the identity credentials of licensed trucking carriers — specifically their Motor Carrier (MC) numbers and Department of Transportation (DOT) numbers — and presented those credentials at freight depots to collect shipments they had no legal right to pick up. Once the cargo left the dock, it was transported to New York City, transferred, stored, and sold.
The goods targeted were high-value and easily liquidated. Prosecutors allege the group stole approximately $165,000 in frozen lamb (November 2025), $432,000 in cheese and $295,000 in frozen beef (December 2025), $266,000 in copper (February 2026), and two separate cigarette loads in March 2026 worth $709,000 and $2.6 million respectively — with cigarettes alone accounting for nearly 60 percent of the total alleged losses.
The eight defendants named in the indictment are Murodullo Khasanov, Nodir Kobilov, Shavkatbek Mamadjanov, Rakhmiddin Abdullaev, Aleksey Vorobyev, and three others. Arrests were made across multiple jurisdictions.
What This Means for Vetting Carriers
This case is not about shell companies or freshly registered DOT numbers. It is about real carriers whose identities were stolen and used at the point of pickup. That distinction matters enormously for how brokers and shippers think about verification.
When a fraudster registers a brand-new carrier entity with a new MC number, there are detectable signals: the authority is days or weeks old, the address does not match any real business, and a search of state secretary of state records turns up nothing. Those are the chameleon-carrier tells.
But when someone walks onto a dock holding the legitimate MC and DOT numbers of a carrier that has been operating for years, has a clean safety record, and holds active authority, the standard vetting workflow produces a clean result — because the carrier being vetted is clean. The fraud is not in the registration. It is in the physical handoff.
That is the gap this indictment exposes. The defendants allegedly succeeded across six separate pickup events before prosecutors say they were identified. Each of those six events represents a moment when someone at a shipper or broker verified a credential and got a green light — because the credential itself was legitimate.
The question every broker must now ask is: did we verify that the driver presenting that MC number is actually connected to that carrier, or did we just confirm that the number exists?
A confirmed MC number tells you the carrier is registered. It does not tell you that the person holding the paperwork at dock 7 works for that carrier. Closing that gap requires contact verification — independently calling the carrier's phone number as it appears in FMCSA records, not the number provided by the entity requesting the load. It requires confirming dispatch instructions through a channel you initiated, not one they handed you.
For more on how to read an active authority record and cross-reference it against what a carrier is actually presenting, see our guide to Operating Authority & Insurance.
How to Protect Your Business
The six-incident timeline in this indictment — October 2025 through April 2026 — means the same crew successfully repeated this method for six months across three states before charges were filed. That repetition is a structural failure, not a one-time slip. Here is how to close the specific gaps this case reveals:
Red Flags to Check Before Every Load Tender
- Inbound contact mismatch: The phone number or email used to book the load does not match what FMCSA's SAFER database shows for that MC number. Treat any discrepancy as a hard stop, not a soft flag.
- Pickup confirmation not independently verified: You accepted dispatch details from the carrier without calling back the number on file in FMCSA records. Always initiate the callback yourself.
- Driver identity not cross-referenced at pickup: The driver or truck presented at the facility was not confirmed against the carrier's known equipment list or dispatch contact before the BOL was signed.
- Authority age inconsistent with carrier's claimed experience: If a carrier presents itself as experienced but its MC authority was granted recently, or if the DOT number traces back to a different legal entity name than the one on the paperwork, stop and investigate.
- No physical address match: The carrier's listed address in FMCSA records is a P.O. box, a UPS Store, or does not return a verified business location on a satellite map check.
- Shared credentials across recent load bookings: The same MC or DOT number was recently used to book loads with other brokers under a different carrier name — a pattern that surfaces when freight community intelligence is shared across broker networks.
- Commodity targeting pattern: High-value, easily resold, low-traceability goods — cigarettes, alcohol, copper, electronics — are disproportionately targeted in identity theft pickups. Apply stricter contact verification protocols to these load types regardless of how clean the carrier's authority appears.
- Geolocation device removal at origin: If your carrier agreement requires a tracking device and the carrier declines or delays activation at origin, treat it as a red flag with immediate escalation.
The Verification Layer That Actually Matters
The defendants in this case did not beat a sophisticated vetting system. They beat the assumption that a valid credential and a driver showing up on time equals a legitimate pickup. Those are two different things.
Freight brokers and shippers who survived 2024 and 2025 without major theft exposure largely did so because they built verification workflows that do not end at credential lookup. They call the number on record. They confirm the driver at the door. They flag any instruction that routes communication away from FMCSA-listed contact information.
This indictment is a concrete example of what it costs when those steps are skipped — six times, across three states, over six months, totaling $4.49 million. The credential was always clean. The verification was not.
Frequently asked questions
What is carrier impersonation fraud and how is it different from double brokering?
Carrier impersonation fraud occurs when thieves steal the MC and DOT numbers of a legitimate, licensed carrier and present those credentials at a freight depot to pick up a load they have no right to take. Double brokering involves re-tendering a load without authorization. Impersonation targets the physical pickup, not the brokering chain.
How do I verify a carrier is who they claim to be at pickup, not just that their MC number is valid?
Confirming an MC number is active in FMCSA records only proves the carrier exists. To verify identity, independently call the carrier's phone number exactly as listed in FMCSA — never the number the driver or dispatcher provides. Confirm dispatch instructions through a channel you initiate. This contact verification step is what the indicted crew exploited when it was skipped.
Can standard carrier vetting catch identity theft fraud using a real, active MC number?
No. Standard vetting workflows return clean results when a stolen MC number belongs to a legitimately registered, long-operating carrier with active authority and a clean safety record. The fraud exists at the physical handoff, not in the registration data. Vetting must extend beyond database checks to include independent contact confirmation with the actual carrier entity.
What cargo is most targeted in carrier impersonation and freight theft schemes?
High-value, easily liquidated goods are the primary targets: cigarettes, copper, electronics, and perishable proteins like meat and cheese. In the Manhattan indictment, cigarettes alone represented nearly 60 percent of the $4.49 million in alleged losses across six loads, making tobacco products a consistent high-priority target for organized freight theft rings.
What verification steps stop a chameleon carrier versus a carrier impersonation scheme?
Chameleon carriers use newly registered MC numbers, so authority age, mismatched addresses, and missing secretary of state officer records are the key tells. Carrier impersonation uses aged, legitimate MC numbers, so those signals do not trigger. The defense against impersonation is independent contact verification — calling FMCSA-listed numbers directly and never accepting contact details supplied by the party requesting the load.
Spotted fraud, or vetting a carrier?
Sign up free to report freight fraud — once filed, the whole industry sees it — and to check any carrier's reports, identity, and authority in seconds.
Related posts

The Breach Was Inside the Account: What the Labor Day $31.8M Theft Pattern Tells Brokers About Identity Risk
Verisk CargoNet's five-year Labor Day analysis doesn't just document 273 cargo thefts — it documents a threat that moved inside the wire. Organized groups are now compromising carrier accounts, phone systems, and compliance-platform credentials to make fraudulent pickups look legitimate.

The Reciprocity Loophole: How a Miami-Dade CDL Scheme Exposes a Vetting Gap Brokers Can't Afford to Ignore
Three Miami-Dade county employees were arrested on felony charges after allegedly processing fraudulent CDL applications as qualifying out-of-state transfers. Here's what the scheme reveals about the carrier identity signals brokers must verify before a truck ever touches their freight.
