Cybercriminals are targeting trucking and logistics companies by deploying remote monitoring and management (RMM) tools and other malware to gain unauthorized access to corporate networks. Once inside, these actors—often working in concert with organized crime groups—leverage their access to manipulate shipment details, bid on real cargo loads, and ultimately steal physical freight. The stolen goods, which include commodities such as food, beverages, electronics, and energy drinks, are typically resold online or shipped overseas, resulting in significant financial losses and supply chain disruptions for affected companies.
Attackers employ a variety of tactics, including spear-phishing emails, social engineering, and the use of compromised email accounts to hijack legitimate business conversations. They frequently impersonate brokers or carriers, sending malicious links disguised as shipment information to lure victims into installing malware. Proofpoint has observed nearly two dozen distinct campaigns in recent months, with at least three known criminal groups involved. The campaigns exploit the urgency and trust inherent in freight negotiations, making logistics companies particularly vulnerable to these sophisticated cyber-enabled cargo theft operations.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
The FBI issued a public warning that cyber-enabled cargo theft is rapidly increasing in the U.S. transportation and logistics sector, estimating 2025 losses in the U.S. and Canada at nearly $725 million. The bureau said criminals have compromised freight brokers and carriers since at least 2024 using phishing and spoofed communications to divert shipments, and it published mitigation and reporting guidance.
Deception.pro released technical indicators tied to the cargo-theft actor’s decoy-environment intrusion, including domains, URLs, an IP address, and multiple SHA-256 hashes. The publication also included sample Gurucul TDIR detection queries, expanding defender-facing technical detail beyond earlier reporting on the intrusion workflow.
Proofpoint reported that in the load-board intrusion it investigated, attackers searched victim environments for cryptocurrency wallets, PayPal credentials, and transportation-specific tools such as load management and freight brokerage software. Researchers also said a final ScreenConnect instance included a script automating queries to an external certificate-signing service, possibly to adapt to recent ScreenConnect safeguards.
On 2026-02-27, Proofpoint observed a financially motivated actor compromise a load board platform and deliver a malicious VBS payload by email to a decoy environment that remained compromised for more than 30 days. Researchers documented persistent access via multiple RMM tools and a trust-evasion technique in which the attacker re-signed a ScreenConnect installer with a fraudulent but valid code-signing certificate hosted on attacker-controlled Amazon S3 infrastructure.
Proofpoint published research describing a cluster of cybercriminal activity in which attackers work with organized crime groups to compromise logistics firms, access freight systems, and divert or steal physical cargo. The report detailed tactics, affected sector focus, and the use of RMM tools and credential theft to deepen access.
Since August 2025, Proofpoint observed more than or nearly two dozen distinct campaigns targeting North American trucking and logistics organizations. The campaigns involved use of legitimate RMM products such as ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, N-able, and LogMeIn Resolve to support cargo theft.
Proofpoint said the cyber-enabled cargo theft activity has been active since at least June 2025, with attackers targeting trucking and logistics companies to facilitate theft of physical shipments. The operations used phishing, email thread hijacking, compromised load boards, and remote monitoring and management tools to gain access.
Proofpoint said there are indications the cyber-enabled cargo theft activity may have begun as early as January 2025, earlier than its prior public baseline of June 2025. The cluster targeted trucking carriers, freight brokers, and logistics firms to facilitate theft of physical shipments through compromised freight operations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 67 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
25 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourceic3.gov
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.