They're Calling From Inside the Carrier: How Fraudsters Hijacked Verified Phone Numbers — and What to Do About It

The Phone Rings. The Number Checks Out. The Carrier Doesn't Exist.
On approximately July 1, 2026, Verisk CargoNet issued a holiday advisory that went further than its usual warnings about parked trailers and opportunistic theft. The report documented a concrete shift in how organized fraud groups are impersonating legitimate motor carriers: they are no longer just spoofing emails or fabricating DOT numbers. They are compromising the actual phone systems carriers operate on — VoIP and software-based business lines — so that when a broker calls to verify a pickup, the call is answered using the legitimate carrier's own verified number.
CargoNet also documented a parallel escalation: fraud actors are targeting carrier accounts on the compliance platforms brokers use to validate load tenders, harvesting credentials through phishing and remote access tools to operate from inside a trusted carrier's identity rather than imitating it from the outside.
Those two tactics together close the gap that most broker verification workflows leave open.
What Changed — and Why It Matters for Vetting
The old impersonation model had a detectable seam. A fraudster would register a lookalike entity, clone a carrier's DOT number on a forged rate confirmation, and hope the broker didn't call back on a number pulled independently from FMCSA records. Brokers who called FMCSA-listed numbers instead of numbers provided by the booking party caught a meaningful share of those attempts.
The new model eliminates that seam. When a criminal group gains remote access to a carrier's VoIP platform — through credential theft, social engineering, or by adding themselves as an authorized user — they can answer calls made to the carrier's genuine, FMCSA-listed phone number. The broker dials the right number. Someone answers. The verification step passes. The load moves to the wrong truck.
CargoNet estimated cargo theft loss values exceeded $359 million in just the first six months of 2026, with the average stolen commodity value climbing to approximately $341,518 — a figure driven by organized groups targeting high-value metals, enterprise electronics, and food-and-beverage shipments worth well over $1 million per load.
The phone-system attack is designed precisely for those loads. A group running this infrastructure is not stealing $8,000 in blueberries. They are positioning to accept a tender for a $400,000 copper shipment or a $1.2 million rack of server components — freight categories where a single successful diversion funds the entire operation.
What This Means for Carrier Vetting
This tactic does not defeat every layer of carrier verification — it defeats one specific layer: the callback. Brokers who rely on a phone call as the final confirmation that a carrier is who they claim to be are now operating on a signal that can be faked from the inside.
The fraud infrastructure described in CargoNet's advisory requires criminals to have already established access to a real carrier's systems. That means the underlying carrier is real — active authority, valid insurance, safety record intact. The FMCSA Company Snapshot will show nothing wrong. The MC number will pull clean. The carrier's history on load boards may be spotless. None of that changes, because the identity hasn't been fabricated. It's been borrowed.
Borrowed identity attacks are harder to detect at the point of dispatch, which is why the verification work has to happen before the load is tendered. The signals that matter are structural, not transactional:
- Authority age and ownership continuity. A carrier whose authority changed hands recently — or whose registered officers changed in the last 90 days — warrants extra scrutiny before a high-value load is awarded. Fresh officer filings at the state SOS level, particularly when they do not match the carrier's prior operating history, are a flag.
- Contact information consistency. When the phone number or email address a carrier uses to communicate with your team does not match the contact on file with FMCSA, the discrepancy is material. Fraud actors who have compromised a carrier's VoIP system may still route communications through a different number or domain during the booking phase. Cross-reference every contact detail against the FMCSA record independently.
- Shared identifiers across entities. Phone numbers and email addresses that appear on multiple MC records — especially records with revoked or dormant authority — are a documented marker of shell-company and chameleon-carrier operations. A number that rings legitimately today may be linked to a revoked entity filed two years ago under a different name.
- Compliance platform login anomalies. CargoNet specifically flagged criminals adding themselves as authorized users on carrier accounts. Any carrier whose compliance platform profile shows recent user additions, contact modifications, or login activity from unfamiliar geolocations should be treated as potentially compromised until confirmed otherwise.
Red Flags to Check Before You Tender the Load
- ☐ Does the carrier's FMCSA-listed phone number match the number your team received during outreach — and have you dialed the FMCSA number independently, not the number provided by the booking party?
- ☐ Has the carrier's registered address, phone, or email changed in the last 60–90 days without a corresponding operational explanation?
- ☐ Do the state SOS officer records align with the current operating principals — or has there been a recent officer change that doesn't match the carrier's historical profile?
- ☐ Does the phone number or email used in this booking appear on any other MC record, including revoked or inactive ones?
- ☐ Is the carrier's authority age consistent with the load type and value being offered? Newly registered carriers — or carriers that recently reactivated dormant authority — warrant elevated scrutiny on high-value tenders.
- ☐ Has the carrier been added to any known fraud or watchlist databases within the past 90 days?
- ☐ If the load is high-value (metals, electronics, food/beverage over $100K), have you verified driver identity at pickup against a pre-submitted, broker-confirmed photo ID — not a document provided at the gate?
The Takeaway
Verification workflows built for the old threat model — fake DOT numbers, lookalike entity names, forged insurance certificates — are necessary but no longer sufficient. When a fraud actor answers your callback from the carrier's actual number, the only defenses left are the ones you ran before you picked up the phone: authority history, identity continuity, contact-record consistency, and cross-entity data that the carrier themselves can't alter.
The July 4 advisory is a signal that organized groups are now investing in fraud infrastructure, not just fraud attempts. The carriers being compromised are real. The verification gaps being exploited are process gaps, not data gaps. Close them before the load posts.
Frequently asked questions
Can freight brokers still trust a callback to a carrier's FMCSA-listed phone number?
No. Organized fraud groups now compromise carrier VoIP systems directly, allowing them to answer calls made to a legitimate carrier's genuine FMCSA-listed number. The callback confirms the phone number is real — not that the person answering controls the carrier. Phone verification alone is no longer a reliable final check.
What is a borrowed identity attack in freight fraud?
A borrowed identity attack occurs when criminals gain access to a real, active carrier's systems — through credential theft or phishing — and operate loads under that carrier's verified identity. The DOT number, MC authority, and insurance all check out because the underlying carrier is legitimate. The identity is stolen, not fabricated.
What carrier vetting signals catch phone-system fraud that callbacks miss?
Focus on structural signals before tendering: authority ownership changes in the last 90 days, fresh officer filings at the state Secretary of State level that conflict with operating history, phone numbers or emails shared across multiple carrier profiles, and any DOT links to previously revoked authorities. These patterns surface compromised or shell carriers before dispatch.
How do freight fraudsters get access to a carrier's VoIP or compliance platform accounts?
Fraudsters use phishing emails, social engineering, and remote access tools to steal login credentials from real carriers. Once inside a carrier's VoIP platform or compliance system account, they can answer verification calls, accept load tenders, and intercept freight — all while appearing to operate as the legitimate carrier.
What freight categories are organized cargo theft groups targeting with carrier impersonation?
Groups running phone-system and borrowed-identity fraud target high-value loads: copper and other metals, enterprise electronics, and food-and-beverage shipments. CargoNet data shows average stolen commodity values reached $341,518 in early 2026, with single loads in targeted categories exceeding $1 million — freight worth funding an entire fraud operation.
Spotted fraud, or vetting a carrier?
Sign up free to report freight fraud — once filed, the whole industry sees it — and to check any carrier's reports, identity, and authority in seconds.
Related posts

The Reciprocity Loophole: How a Miami-Dade CDL Scheme Exposes a Vetting Gap Brokers Can't Afford to Ignore
Three Miami-Dade county employees were arrested on felony charges after allegedly processing fraudulent CDL applications as qualifying out-of-state transfers. Here's what the scheme reveals about the carrier identity signals brokers must verify before a truck ever touches their freight.

The Carrier With No Name: What the FBI's 'No Name Given Kamal' Case Reveals About Identity Gaps in Your Freight Network
Operation Hard Ball charged 37 defendants tied to India-based transnational crime syndicates — and federal prosecutors say those networks moved narcotics across the US-Canada border using long-haul semi-trucks. Here's what that means for every broker and shipper who thinks a DOT number is enough.
