Forget shoplifting — hackers are hijacking entire truckloads by exploiting logistics systems, and the trend is accelerating fast.
Our cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalent scenarios like these are happening in front of your eyes and you might not even know when it’s happening. Cyber-enabled cargo theft is growing at a shocking pace.
Most cybersecurity professionals do not spend much time focusing on transportation and logistics and it makes sense why. Traditionally, these industries were heavily manual in nature with little tech innovation or connected systems. However, that has changed drastically in the last few years. Autonomous vehicles, connected systems and devices, robotics – the list goes on, are just a few examples of how logistics and specifically freight logistics has changed in recent years to innovate to ultimately keep transportation costs low. While shiny tech companies are still the attack beacon on the hill, there has been something brewing in the shadows and the bad guys have been paying attention.
According to TruckNews.com, “cargo theft incidents are up more than 90% since 2021, with high-tech strategic cargo thefts soaring by 1,500%”. That’s not a typo. I lead the cybersecurity function for a company that specializes in vehicle logistics, and we also see reports of cyber-enabled vehicle thefts increase around 1,400% during transport. Again, that’s not a typo. It has gotten so bad that the FBI has noticed it and is deploying dedicated resources to combat the increase.
How did we get here?
Freight logistics is quite a fragmented industry. From the production line all the way to consumers or customers, there are generally multiple parties in the mix to get goods from point A to point B. At a high level, transportation of goods does not seem overly complex. Maybe it’s a warehouse or the production facility; a truck shows up, loads the goods and transports them to the store. However, the reality is, complexity is quite high. This includes inventory systems, brokers and their systems, bills of lading, payment systems, vehicle telematics and of course a ton of data and the goods themselves. Freight logistics, and logistics more broadly, have been heavily paper-based but had to innovate and move operations and their data online. However, controls, governance and security gates have traditionally been de-prioritized. Shipping goods is a cost center, and the goal is to keep costs low. Well, the bad guys have noticed.
Think about it this way: I could try to walk into a store with mounted security cameras, security guards standing at the doors, locked shelves and try to steal whatever is behind that locked shelf and risk being caught — or I can exploit a transportation management system, divert an entire truckload and completely cover my tracks for a much bigger payday with arguably less immediate risk. Or even better, pin it on someone else. Just to prove how lucrative this scheme is, instead of breaking into a car to steal it, thieves went after a transporter to steal NBA legend Shaquille O’Neal’s Range Rover during transport. It takes coordination and planning to get that done, and apparently a compromised transporter.
How hackers get the goods
Generally, just like with every compromise, attackers look for the easiest way in. However, certain patterns are emerging of how the perpetrators are accomplishing these heists, which include business email compromise (BEC), identity theft/carrier impersonation, load board hacks and freight redirection and Electronic Bill of Lading (eBOL) tampering. As previously mentioned, there are many handoffs and parties involved in the logistics process. Each handoff, or trust boundary if you’re thinking in terms of a threat model, carries risks and has potential vulnerabilities that a threat actor could exploit. What we also see is that carriers (transporters) have large, varying degrees of cybersecurity maturity, generally no requirements for standardization and often not sufficient resources to defend against increasingly complex cyberattacks.
At this point, you might wonder if freight logistics is completely defenseless and the answer is “no”. Vehicle telematics and GPS tracking have been in place for a while, but they were often used to prevent traditional theft. Attackers know this and they have pivoted as well. One of the movie-worthy heists that made the news was the cyber-enabled cargo theft of 24,000 bottles of Guy Fieri’s tequila. Not only did the bad guys infiltrate systems, but they also spoofed GPS tracking to make it look like the goods were en route to the correct destination when they weren’t.
Also, think about the planning and infrastructure these crime rings have invested in, and I am calling them crime rings because these are major operations with attacks often coming from overseas. In a “traditional” compromise, you get in, get the data, cover your tracks and get out. In these examples, the attackers do that and need real infrastructure to move physical goods. It’s one thing to infiltrate a system or spoof a carrier online, but it’s a whole different story to operate actual trucks, clear goods through customs and ship them overseas — which is what they often do.
The industry is noticing, but we need more of the “good guys”
Industry sharing forums and conferences around cyber-enabled cargo theft have started to emerge, but we still have a long way to go. Given the industry’s fragmented systems, operators and entities, it can be challenging to perform incident response and forensics. We need cybersecurity professionals who understand logistics as well. There is phishing and then there is showing up with an actual truck with a forged USDOT number and a spoofed eBOL. The US Department of Transportation estimates that “in 2023, the U.S. transportation system moved a daily average of about 55.5 million tons of freight valued at more than $51.2 billion” — yup, daily. You can see what the potential for these attackers is, and they are currently only handicapped by their own capacity to move the loot. Maybe AI-enabled TSOCs (Transportation Security Operations Center), which combine the movement of the goods with cyber operations, are an avenue to explore. We ourselves are investing heavily in advanced detection and prevention mechanisms. While I am hopeful this industry will attract more talent, especially as thefts become more widely reported, finding talent can be challenging. A recent CSO article mentions that there is a “gap between existing and needed skills” to fill many of the cyber roles, but now we are also adding specific industry knowledge and while unicorns exist, there are no specific trainings or certifications geared toward cyber-enabled cargo theft to help close the knowledge gap. It is learning by doing (most of the time).
It seems the perpetrators have an agenda, although clear patterns of strategic thefts vs. opportunistic ones have not emerged yet or been publicly disclosed. According to recent reported thefts, they are targeting raw materials, data center equipment, high-value vehicles, and yes, even adult protection products. I suspect we will also see them scaling their operations to divert more freight. So, is it easier to steal cargo than toothpaste? In a way, yes and no, but it is a perfect storm of a fragmented industry catching up, low levels of regulation, limited controls and detection capabilities and until now, a relatively low risk of punishment. The next time you see a car hauler or semi-truck on the road, there could be a chance you are watching a cyber-enabled cargo heist unfold in front of your eyes.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?










