The System Built to Stop Fraud Is Now Being Used to Commit It
What Happened
The FMCSA's new registration system, Motus, was created in part to prevent freight fraud — but cybersecurity experts say it has also created new attack vectors that could offset that purpose.
The system launched May 19, 2026, replacing the outdated Unified Registration System. The transition was bumpy by design — FMCSA knew migration friction was unavoidable — and that friction opened a window that threat actors walked straight through.
Ole Villadsen, a staff threat researcher at cybersecurity company Proofpoint, discovered a substantial amount of malicious email traffic targeting truckers in Fall 2024. Cybercriminals were using compromised email accounts to email truckers malicious links that, if clicked on, would leave behind malware on their computers. A year later, he picked up another trail of a threat actor using remote monitoring and management (RMM) tools to access truckers' computer systems — and this time he was able to link the activity directly to cargo theft.
The Motus rollout handed bad actors a new hook. Criminals are sending carriers and brokers emails with fake URLs that guide them to a credential-harvesting site disguised as trusted industry brands — prompting victims to enter their username and password, then providing a fake multi-factor authentication code.
Scammers are targeting trucking companies with emails impersonating FMCSA's new Motus registration system. The notices direct recipients toward four bogus websites resembling the federal portal, with each message claiming an off-cycle profile update requires immediate attention.
FMCSA has publicly identified four fake domains — dot.motusdatasboard.com, dot.motusdatadesk.com, dot.motuswebdeck.com, and dot.motusfunction.com — alongside the only legitimate portal: motus.dot.gov.
The psychological engine driving the scam is well-documented. "They know people are anxious to lose their authority, and so suddenly there's these emails that look like they're coming from the government," as one industry product manager explained at the NMFTA Cybersecurity Conference.
What This Means for Vetting Carriers
Most brokers read the Motus story as a carrier problem — a phishing campaign aimed at trucking companies. That framing misses the direct exposure to brokers and shippers.
When a carrier's Motus credentials are harvested, the fraudster gains access to the company's FMCSA registration profile. Under Motus, no existing authority registration profile can be changed without completing an identity verification check first — but the scam bypasses that safeguard by stealing the verified human's own login. The attacker is not pretending to be someone else to FMCSA. They are that person, authenticated and logged in.
The downstream consequence for brokers is specific: a carrier whose Motus account has been compromised can have its contact details — phone number, email address, dispatch information — silently updated by an attacker. The next broker who pulls that carrier's profile from FMCSA data is calling a phone number or emailing an address now controlled by the fraudster. The DOT number is real. The MC authority is real. The insurance on file is real. The voice on the other end is not.
FMCSA officials acknowledged the disruptions but maintained that the overhaul was overdue and necessary after years of insufficient oversight allowed fraudulent operators and chameleon carriers to proliferate. That is true — but it does not help the broker who tendered a load to a phone number that changed yesterday.
Fifty thousand carriers registered with Motus within days of the launch. The agency pushed it live despite knowing a new system would cause friction, because the fraud and account-takeover problem had grown large enough to force the move. With over 70,000 carriers now registered through Motus as of late September 2026 — and nearly 21,000 applications still pending — the volume of accounts in transition is a permanent targeting surface.
The attack is not a Motus bug. It is a social engineering campaign timed to a system migration. That pattern repeats every time a major government platform changes. Brokers who rely exclusively on point-in-time FMCSA data checks are exposed to contact-detail drift they will not detect until after a load disappears.
How to Protect Your Business
The vetting signals that matter here are not the ones that show up on day one of onboarding. They are the ones that change between onboarding and tender — and the ones that confirm the human on the other end of the call is who the DOT record says they are.
Start with the FMCSA registration data itself. CRIM Report surfaces operating authority and insurance records in real time, which means contact-detail changes that appear between your initial carrier onboard and a new load tender are visible. A phone number that did not exist in the profile 30 days ago is a concrete flag, not a hunch.
Beyond the data check, the following steps cut the risk of credential-theft-enabled impersonation:
Red Flags to Check Before Every Tender
- Contact details changed recently. If the dispatch phone number or email on the FMCSA record differs from what you captured at onboarding, stop and verify through a second, independent channel before releasing freight.
- Domain mismatch in carrier email. A carrier registered under "Smith Logistics LLC" using a Gmail or generic webmail address — rather than a matching business domain — is consistent with a freshly harvested or newly created identity.
- Shared phone number across multiple DOT accounts. A single phone number linked to two or more distinct carrier profiles is a reliable indicator of either a chameleon-carrier network or a spoofed contact used for freight pickup.
- Authority age under 6 months combined with high-value commodity offer. New authority is the cheapest entry point for fraud. Motus has reduced but not eliminated new fraudulent registrations.
- Off-cycle "update required" pressure. If a carrier or someone claiming to represent FMCSA contacts you urgently about updating credentials outside of a routine biennial cycle, treat it as a social engineering attempt until proven otherwise.
- Email URL not ending in .gov. Any Motus-related communication from an address that does not terminate in a verified .gov domain is fraudulent. Remind every carrier in your network: the only legitimate Motus portal is motus.dot.gov.
- MCS-150 update timestamp inconsistent with carrier's stated operating history. A carrier claiming five years of operation but with an MCS-150 last filed in the past 60 days warrants an explanation.
The Durable Fix
Motus will harden over time. Phishing campaigns against any new government platform tend to peak in the first six to twelve months of rollout and decline as users become familiar with legitimate communication patterns. That is not a reason to lower vigilance — it is a reason to build verification habits now that survive the next system transition, because there will be one.
The carriers that fraudsters impersonate are almost always real, active, and clean in the public record. That is the point. The fraud lives not in the DOT file but in the gap between what the file says and who actually answers the phone. Closing that gap is a broker responsibility, not a federal one.
Frequently asked questions
What is the FMCSA Motus system and how does it relate to carrier fraud?
Motus is FMCSA's new USDOT registration system, launched May 19, 2026, replacing legacy platforms. It introduced biometric identity verification to block fraudulent carrier registrations. However, cybercriminals now target it with phishing emails and fake portals to harvest carrier login credentials, which they then use to alter contact details on real carrier accounts.
How do I know if a carrier's FMCSA contact information has been changed by a fraudster?
Compare the phone number and email on the carrier's current FMCSA record against what you captured at onboarding. A change in dispatch contact details between onboarding and load tender is a concrete red flag. Always verify through a second independent channel — not the number listed on the updated profile — before releasing freight.
What does a fake Motus phishing email look like?
Fake Motus emails claim an off-cycle profile update is required immediately and route recipients to .com domains like dot.motusdatasboard.com or dot.motuswebdeck.com. The only legitimate portal is motus.dot.gov. Fraudulent messages also capitalize the name as 'MOTUS' — FMCSA writes it as 'Motus' in all official communications.
Can a carrier's DOT number be valid but still be used fraudulently?
Yes. When a real carrier's Motus account is compromised, the DOT number, MC authority, and insurance on file remain legitimate. Only the contact information changes — routing calls and emails to the fraudster. A broker checking FMCSA data sees a clean, active carrier while communicating with someone who has hijacked that identity.
What carrier vetting checks should brokers run to catch credential-theft fraud?
Check whether dispatch phone numbers or emails changed recently compared to your onboarding record. Flag any carrier email on a generic webmail domain. Look for a single phone number linked to multiple DOT accounts. For new authority under six months old, apply additional scrutiny. Verify all load details by calling a number you independently sourced — not one from the FMCSA profile alone.
Spotted fraud, or vetting a carrier?
Sign up free to report freight fraud — once filed, the whole industry sees it — and to check any carrier's reports, identity, and authority in seconds.
Related posts

The Trucks That Never Hauled a Load: What the AKL Transport Indictment Reveals About Carrier Identity Verification
A federal grand jury indicted Kristopher Lunsford on September 25, 2026, charging him with operating a $105 million Ponzi scheme built on phantom trucking operations. The case exposes a verification blind spot that freight brokers and shippers cannot afford to ignore.

The Pickup Looked Perfect. The Documents Were Fake. What the $680K New Castle Theft Tells Every Shipper About Release-Point Risk.
Two men showed up at a Delaware electronics warehouse with fraudulent CDLs, forged shipping documents, and a false license plate — and drove away with $680,000 in cargo. Here's what the layered document fraud in this case reveals about where your real verification gap lives.
