They're Calling From Inside the Carrier: How Fraudsters Hijacked Verified Phone Numbers — and What to Do About It

The Phone Rings. The Number Checks Out. The Carrier Doesn't Exist.
On approximately July 1, 2026, Verisk CargoNet issued a holiday advisory that went further than its usual warnings about parked trailers and opportunistic theft. The report documented a concrete shift in how organized fraud groups are impersonating legitimate motor carriers: they are no longer just spoofing emails or fabricating DOT numbers. They are compromising the actual phone systems carriers operate on — VoIP and software-based business lines — so that when a broker calls to verify a pickup, the call is answered using the legitimate carrier's own verified number.
CargoNet also documented a parallel escalation: fraud actors are targeting carrier accounts on the compliance platforms brokers use to validate load tenders, harvesting credentials through phishing and remote access tools to operate from inside a trusted carrier's identity rather than imitating it from the outside.
Those two tactics together close the gap that most broker verification workflows leave open.
What Changed — and Why It Matters for Vetting
The old impersonation model had a detectable seam. A fraudster would register a lookalike entity, clone a carrier's DOT number on a forged rate confirmation, and hope the broker didn't call back on a number pulled independently from FMCSA records. Brokers who called FMCSA-listed numbers instead of numbers provided by the booking party caught a meaningful share of those attempts.
The new model eliminates that seam. When a criminal group gains remote access to a carrier's VoIP platform — through credential theft, social engineering, or by adding themselves as an authorized user — they can answer calls made to the carrier's genuine, FMCSA-listed phone number. The broker dials the right number. Someone answers. The verification step passes. The load moves to the wrong truck.
CargoNet estimated cargo theft loss values exceeded $359 million in just the first six months of 2026, with the average stolen commodity value climbing to approximately $341,518 — a figure driven by organized groups targeting high-value metals, enterprise electronics, and food-and-beverage shipments worth well over $1 million per load.
The phone-system attack is designed precisely for those loads. A group running this infrastructure is not stealing $8,000 in blueberries. They are positioning to accept a tender for a $400,000 copper shipment or a $1.2 million rack of server components — freight categories where a single successful diversion funds the entire operation.
What This Means for Carrier Vetting
This tactic does not defeat every layer of carrier verification — it defeats one specific layer: the callback. Brokers who rely on a phone call as the final confirmation that a carrier is who they claim to be are now operating on a signal that can be faked from the inside.
The fraud infrastructure described in CargoNet's advisory requires criminals to have already established access to a real carrier's systems. That means the underlying carrier is real — active authority, valid insurance, safety record intact. The FMCSA Company Snapshot will show nothing wrong. The MC number will pull clean. The carrier's history on load boards may be spotless. None of that changes, because the identity hasn't been fabricated. It's been borrowed.
Borrowed identity attacks are harder to detect at the point of dispatch, which is why the verification work has to happen before the load is tendered. The signals that matter are structural, not transactional:
- Authority age and ownership continuity. A carrier whose authority changed hands recently — or whose registered officers changed in the last 90 days — warrants extra scrutiny before a high-value load is awarded. Fresh officer filings at the state SOS level, particularly when they do not match the carrier's prior operating history, are a flag.
- Contact information consistency. When the phone number or email address a carrier uses to communicate with your team does not match the contact on file with FMCSA, the discrepancy is material. Fraud actors who have compromised a carrier's VoIP system may still route communications through a different number or domain during the booking phase. Cross-reference every contact detail against the FMCSA record independently.
- Shared identifiers across entities. Phone numbers and email addresses that appear on multiple MC records — especially records with revoked or dormant authority — are a documented marker of shell-company and chameleon-carrier operations. A number that rings legitimately today may be linked to a revoked entity filed two years ago under a different name.
- Compliance platform login anomalies. CargoNet specifically flagged criminals adding themselves as authorized users on carrier accounts. Any carrier whose compliance platform profile shows recent user additions, contact modifications, or login activity from unfamiliar geolocations should be treated as potentially compromised until confirmed otherwise.
Red Flags to Check Before You Tender the Load
- ☐ Does the carrier's FMCSA-listed phone number match the number your team received during outreach — and have you dialed the FMCSA number independently, not the number provided by the booking party?
- ☐ Has the carrier's registered address, phone, or email changed in the last 60–90 days without a corresponding operational explanation?
- ☐ Do the state SOS officer records align with the current operating principals — or has there been a recent officer change that doesn't match the carrier's historical profile?
- ☐ Does the phone number or email used in this booking appear on any other MC record, including revoked or inactive ones?
- ☐ Is the carrier's authority age consistent with the load type and value being offered? Newly registered carriers — or carriers that recently reactivated dormant authority — warrant elevated scrutiny on high-value tenders.
- ☐ Has the carrier been added to any known fraud or watchlist databases within the past 90 days?
- ☐ If the load is high-value (metals, electronics, food/beverage over $100K), have you verified driver identity at pickup against a pre-submitted, broker-confirmed photo ID — not a document provided at the gate?
The Takeaway
Verification workflows built for the old threat model — fake DOT numbers, lookalike entity names, forged insurance certificates — are necessary but no longer sufficient. When a fraud actor answers your callback from the carrier's actual number, the only defenses left are the ones you ran before you picked up the phone: authority history, identity continuity, contact-record consistency, and cross-entity data that the carrier themselves can't alter.
The July 4 advisory is a signal that organized groups are now investing in fraud infrastructure, not just fraud attempts. The carriers being compromised are real. The verification gaps being exploited are process gaps, not data gaps. Close them before the load posts.
Spotted fraud, or vetting a carrier?
Sign up free to report freight fraud — once filed, the whole industry sees it — and to check any carrier's reports, identity, and authority in seconds.
Related posts

The Carrier That Wasn't: Inside the $10M Impersonation Ring That Just Got Eight People Arrested
A federal indictment unsealed June 30 charged eight people in an organized, international scheme that used carrier impersonation to steal at least $10 million in freight since March 2023. Here's what the playbook looks like — and the specific checks that stop it.

When a Carrier Sells Its Identity: The Hilder Herd Case and the Vetting Checks That Can't See It Coming
A carrier sold its MC number and digital credentials to a fraud ring that used them to steal $3.5 million in computer equipment — and every standard vetting check cleared. Here is what brokers need to look at instead.
