Identity Verification

Vetting Isn't Enough Anymore: The Q2 2026 Data That Should Change How You Onboard Carriers

CRIM Report Team
July 31, 2026 · 6 min read
Vetting Isn't Enough Anymore: The Q2 2026 Data That Should Change How You Onboard Carriers

The Numbers Don't Lie — and They're Getting Worse

On July 28, 2026, industry fraud-tracking data for Q2 2026 landed with a figure that every freight broker needs to internalize: communication-based attacks — compromised inboxes, spoofed emails, account takeovers, and impersonation calls — now account for 50% of all classified freight fraud vectors, up from 42.7% in Q1 2026. In a single quarter, the dominant fraud mode shifted.

The volume behind that percentage is staggering. One industry fraud-detection network blocked 784,201 fraudulent inbound emails during Q2 2026 alone — a 48.5% increase from Q1 and 58.3% higher than a year earlier. That same network intercepted 109,995 fraudulent and spoofed phone calls, up 53.2% from the prior quarter and 159.3% year over year. Meanwhile, Verisk CargoNet estimates cargo theft losses across the United States surpassed $359 million in the first six months of 2026, with the average stolen commodity value climbing to approximately $341,518 per incident.

These aren't incremental changes. They're a structural shift in how freight fraud operates — and most carrier vetting processes haven't caught up.

What This Means for How Fraud Actually Works Now

For years, the carrier fraud playbook centered on fabricated identities: ghost companies registered with the FMCSA, stolen DOT numbers, shell LLCs with disposable officers. The defense was clear — run a company snapshot, check authority age, verify the SOS filing, look for shared phone numbers or emails across multiple MC numbers. Those signals still matter. But Q2 2026 makes plain that fraudsters are no longer relying primarily on invented carriers.

They're compromising real ones.

Verisk CargoNet has documented a specific tactic driving this shift in 2026: the compromise and misuse of software-based business phone systems. These systems — VoIP platforms widely used by small carriers — can allow a remote actor to make and receive calls from a motor carrier's verified phone numbers. In some cases, they can monitor active calls. When that happens, the carrier passes every onboarding check. The DOT number is real. The MC number is active. The phone number matches the FMCSA record. The email domain looks right. Everything a broker verified at onboarding is technically accurate — and none of it protects the load.

This is the post-onboarding fraud problem. The identity was legitimate when you checked it. It stopped being legitimate sometime after.

The FMCSA has recognized the registration-level piece of this: its transition to Motus tightened identity verification at the point of carrier registration, raising the bar for new entrants. That matters. But Motus addresses who gets an MC number — not what happens to a real carrier's communication infrastructure six months after they're onboarded and approved.

Why One-Time Vetting Creates a False Sense of Security

The standard onboarding workflow at most brokerages runs a carrier through authority checks, insurance verification, and a confirmation call to the number on the FMCSA record. At that moment in time, the process works. The problem is that moment in time isn't the moment a load gets tendered.

Fraud rings understand carrier vetting workflows better than most compliance teams. They know which data points get checked and when. Compromising a carrier's inbox or phone system after onboarding bypasses the entire check — because the check already happened. The broker's system shows a green carrier. The contact comes from a verified number. The rate confirmation looks normal. The load moves to the wrong truck.

This dynamic is why the Q2 2026 data matters operationally, not just statistically. The majority of freight fraud no longer lives in the registration gap. It lives in the communication gap — the space between when you verified a carrier and when you're actually tendering freight to them.

For brokers relying on Operating Authority & Insurance checks at onboarding, these signals remain the essential baseline. But the Q2 data is an unambiguous signal that baseline verification alone doesn't close today's exposure.

Red Flags to Check Before Every Tender

The shift to communication-based attacks changes which signals deserve real-time scrutiny. Before tendering any load — especially to a carrier you haven't moved freight with recently — run through this checklist:

  • Callback to the number on file, not the number that contacted you. If a carrier or dispatcher reaches out through a new number, call the FMCSA-registered number independently to confirm the contact is legitimate.
  • Check the email domain carefully. One-character substitutions (rn for m, cl for d) are common in spoofed domains. Compare it character-by-character against what's on the SAFER record.
  • Look for contact-detail changes since your last tender. A phone number or email that differs from what you onboarded — even slightly — warrants a direct verification call before the load moves.
  • Cross-reference MC number against shared contact signals. The same phone number or email address appearing across multiple MC numbers is a registration-era fraud signal that still catches shell companies and chameleon carriers.
  • Verify the carrier's authority status in real time, not from your onboarding record. Authority can be revoked between when you credentialed a carrier and when you're tendering today.
  • Scrutinize any load where the dispatch contact differs from the onboarded contact. Third-party dispatchers operating from foreign locations are a confirmed vector for communication-based fraud.
  • Flag unusual rate-acceptance speed or pressure. Urgency to lock a load without standard confirmation steps is a behavioral signal that fraud rings use deliberately to compress your verification window.

How to Protect Your Operation Going Forward

The Q2 2026 data isn't a reason to abandon your onboarding workflow — it's a reason to extend it forward in time. Carrier verification has to be treated as a continuous process, not a one-time credentialing event.

That means the identity signals that matter at onboarding — authority age, SOS officer records, shared contact data across MC numbers, prior-revoke DOT links — need to be checked again at tender, and again at dispatch. A carrier that looked clean in January can be compromised by March. A phone number that matched the FMCSA record at onboarding may be ringing in a fraud operation's call center by the time you're assigning a load.

The $359 million lost in just the first half of 2026 didn't all walk out of unlocked trailers. A significant and growing share of it moved through legitimate-looking communications from carriers that brokers had already vetted. That's the gap the Q2 2026 numbers expose — and closing it requires verification that doesn't stop at onboarding.

Frequently asked questions

What is communication-based freight fraud and how does it differ from carrier identity theft?

Communication-based freight fraud involves compromising a real, legitimately registered carrier's inbox, phone system, or email account to redirect loads. Unlike traditional carrier identity theft — where fraudsters fabricate a fake DOT or MC number — this method abuses a genuine carrier identity that already passed vetting, making it undetectable through standard onboarding checks alone.

How do freight fraudsters spoof a carrier's verified phone number?

Fraud rings increasingly exploit software-based VoIP phone systems used by small carriers. By compromising these systems, they can make and receive calls from the carrier's FMCSA-registered number. The number matches every onboarding record, so it passes a standard callback verification — the call just goes to a fraud operation instead of the real carrier.

Is checking a carrier's MC number and authority status at onboarding enough to prevent fraud?

No. Onboarding checks confirm a carrier's status at a single point in time. Authority can be revoked, phone systems compromised, and email accounts hijacked well after onboarding. The Q2 2026 industry data shows 50% of freight fraud now flows through communication channels, meaning real-time verification at tender — not just at credentialing — is required.

What red flags indicate a carrier's contact information may have been compromised?

Key signals include a phone number or email that differs from your onboarding record, a dispatch contact you haven't interacted with before, a spoofed email domain with subtle character substitutions, and unusual pressure to accept a rate confirmation quickly. Cross-referencing the current contact against FMCSA-registered data before every tender is the baseline defense.

How much cargo has been stolen through freight fraud in 2026?

Verisk CargoNet estimates U.S. cargo theft losses exceeded $359 million in the first six months of 2026, with the average stolen shipment valued at approximately $341,518. Industry fraud-detection networks intercepted nearly 110,000 spoofed freight calls in Q2 2026 alone, a 159% increase year over year.

Spotted fraud, or vetting a carrier?

Sign up free to report freight fraud — once filed, the whole industry sees it — and to check any carrier's reports, identity, and authority in seconds.

Get fraud-prevention insights in your inbox

New carrier-vetting and freight-fraud guides. No spam.