Cargo Theft

The Driver Was the Scheme: What $110.6M in Data Center Cargo Theft Reveals About the Carrier Vetting Gap

CRIM Report Team
August 18, 2026 · 6 min read
The Driver Was the Scheme: What $110.6M in Data Center Cargo Theft Reveals About the Carrier Vetting Gap

$110.6 Million and a Security Escort That Wasn't Enough

Since June 3, 2026, known reported data center freight thefts have reached $110.6 million, according to Scott Cornell, chair of TAPA Americas and a 30-year cargo theft investigator. The headline number is alarming. The mechanism behind it is more alarming still.

On two of those thefts, shipments were being escorted by security teams. Individuals intentionally crashed into the security escorts on those loads — a method Cornell called a significant change for cargo theft in the United States. It sounds like a physical-security failure. It wasn't. It was a carrier-vetting failure.

The tactic required cooperation from each shipment's driver. "If the drivers are bad guys, when the escorts get bumped, the drivers then take off," Cornell said. A legitimate operator would stop, call 911, or reach a safe location. "The drivers weren't properly vetted," Cornell added.

The security escort was theater once a compromised operator sat behind the wheel. No physical deterrent survives a driver who is part of the theft ring.

Individual Load Values Tell the Full Story

These were not incidental losses. Individual cases ranged from $2 million to $38 million. Cornell also cited thefts valued at $8 million, $12 million, $14 million, $20 million, and $24 million. The freight category driving these numbers is precise: the stolen shipments carried data center equipment and other high-value technology cargo.

The broader market context makes this a sustained target, not a spike. Verisk CargoNet documented 677 supply chain theft incidents in the U.S. and Canada in Q2 2026, down 26% from a year earlier, yet estimated losses jumped from $135.7 million to $304.6 million over the same period. The average theft with a reported value hit $564,009. Fewer incidents, dramatically higher per-event losses. Organized theft groups are selecting targets, not stumbling into them.

What This Means for Carrier Vetting

The conventional carrier vetting model stops at the entity level: confirm the DOT number, check authority status, pull an insurance certificate, scan the safety rating. That process answers one question — is this a real carrier? It does not answer the question that the data center heists expose: who is actually driving this load?

From a broker's perspective, the responsibility is usually limited to vetting the trucking company itself. If the carrier passes every check, there is often no practical way for a broker to identify a compromised driver in real time. The exposure exists inside the carrier's hiring and screening process. That creates a major gap.

Cornell is specific about how organized groups are exploiting this gap. "The bad guys, instead of trying to pass through some of these vetting platforms that are out there, send one of their crew members to go work as a driver at a legitimate trucking company." The carrier entity is clean. The carrier's authority is active. The carrier's insurance is current. The driver is not.

This is the Trojan Driver problem, and it invalidates the assumption that a verified carrier file means a verified load.

The Vetting Signals That Actually Apply Here

Brokers tendering high-value freight — data center equipment, semiconductors, electronics, copper — need to push the verification layer past the entity and toward the driver and the carrier's internal controls. The signals that matter:

At the carrier level:

  • Authority age: A carrier that obtained its MC number recently and is already tendering for high-value tech loads deserves hard scrutiny. Organized theft groups sometimes acquire dormant authority or stand up new entities to avoid pattern recognition. Check the Operating Authority & Insurance record for the original grant date, not just current status.
  • Shared contact details across multiple DOT numbers: A phone number or email address that appears across several carrier entities — especially entities with staggered registration dates — is a strong indicator of shell-company infrastructure built for fraud, not operations.
  • SOS officer records that don't match the FMCSA principal: When the registered agent or officer on the state Secretary of State filing is different from the person named in the carrier's FMCSA Company Snapshot, ask why. Mismatches between state-level business registration and federal operating-authority records are a red flag in chameleon-carrier patterns.
  • Prior revocation links: Run the carrier's principal address and phone number against DOT numbers with revoked or inactive authority. Theft rings reuse contact infrastructure across entities.

At the driver level:

  • Driver tenure: Cornell says trucking companies should conduct thorough background checks on drivers. For freight brokers, Cornell recommends requesting drivers who have been employed for more than six months for high-value loads. This is a concrete, contractual ask — not a courtesy.
  • PSP history: The Driver Safety History (PSP) report surfaces inspection violations, out-of-service orders, and crash events tied to a specific CDL. A driver with a thin or inconsistent inspection history at a carrier with substantial claimed operating history is worth questioning.
  • Drug & Alcohol Clearinghouse status: Drivers prohibited from operating under the FMCSA Clearinghouse should not be behind any load. Confirm the driver is not on the prohibited list before the truck rolls.

Red Flags to Check Before Releasing High-Value Freight

  • ☐ Authority active for fewer than 12 months on a carrier bidding high-value tech or electronics loads
  • ☐ Carrier's phone number or email matches another DOT entity, active or revoked
  • ☐ SOS officer name does not match FMCSA principal contact
  • ☐ Carrier cannot confirm named driver's CDL number or tenure at the company
  • ☐ Driver has fewer than six months on record with the carrier (per Cornell's high-value-load standard)
  • ☐ No out-of-service or inspection history for a carrier claiming years of active operation
  • ☐ Carrier declines to provide driver identity for pre-dispatch confirmation
  • ☐ Load pickup location is a drop lot, truck stop, or address that does not match the carrier's principal place of business

The Operational Fix

Tendering a load worth $8 million, $20 million, or $38 million to a carrier is a risk decision, not just a compliance checkbox. The bump-and-run heists work because every layer of physical security was neutralized by one variable no one confirmed: the person holding the steering wheel.

Entity-level vetting is the floor, not the ceiling. For high-value freight, require the carrier to identify the assigned driver by name and CDL number before dispatch. Cross-reference that CDL against the carrier's stated hiring date. Confirm the driver is not on the FMCSA Drug & Alcohol Clearinghouse prohibited list. Ask how long that driver has been employed — and document the answer in your file.

Proper verification could have neutralized the entire operation, according to Cornell. That is not a vague principle. It is a checklist item.

Frequently asked questions

How do I verify a carrier driver's identity before releasing high-value freight?

Request the driver's full name and CDL number from the carrier before dispatch. Cross-reference the CDL against the carrier's stated hire date, confirm the driver is not on the FMCSA Drug & Alcohol Clearinghouse prohibited list, and document both confirmations in your load file. For loads above seven figures, require drivers with at least six months of tenure at that carrier.

What is the bump-and-run cargo theft tactic?

In a bump-and-run theft, criminals deliberately ram or disable a security escort vehicle protecting a high-value shipment. A pre-planted compromised driver then accelerates away with the load instead of stopping. The tactic requires an insider behind the wheel — making carrier-level entity vetting insufficient on its own.

What cargo theft red flags should brokers watch for on high-value tech loads?

Flag any carrier with authority active fewer than 12 months bidding on electronics or data center freight. Also check for phone numbers or emails shared across multiple DOT entities, mismatches between SOS officer records and FMCSA principal contacts, and carriers that cannot confirm the assigned driver's CDL or tenure before dispatch.

Does vetting a carrier's MC number protect against insider cargo theft?

No. Confirming active MC authority verifies the entity, not the people operating under it. Organized theft groups place their own members inside legitimate carriers as drivers. Entity-level checks — MC number, authority status, insurance certificate — cannot detect a compromised driver. Driver-level verification is a separate, required step for high-value loads.

How much has data center cargo theft cost shippers in 2026?

Known reported data center freight thefts reached $110.6 million between June 3 and mid-August 2026, according to Scott Cornell, chair of TAPA Americas. Individual incidents ranged from $2 million to $38 million per load. Broader Q2 2026 cargo theft losses across the U.S. and Canada hit $304.6 million, more than double the prior year's Q2 total.

Spotted fraud, or vetting a carrier?

Sign up free to report freight fraud — once filed, the whole industry sees it — and to check any carrier's reports, identity, and authority in seconds.

Get fraud-prevention insights in your inbox

New carrier-vetting and freight-fraud guides. No spam.