Two coordinated cargo thefts in California targeted semitruck shipments carrying high-value AI data center hardware from Silicon Valley to Southern California, with attackers deliberately disabling private security escort vehicles before the trucks vanished with millions of dollars in equipment. Investigators said the tactics included staged vehicle attacks such as rear-ending and PIT-style maneuvers, and they suspect the truck drivers may have been complicit; no injuries were reported.
The hijackings reflect a broader surge in cargo crime focused on enterprise computing, networking gear, and other AI infrastructure components as data center spending accelerates. Security sources said the stolen hardware is attractive to black-market buyers, with some investigators believing shipments are moved overseas, including to China, where U.S. export controls have helped push prices for advanced AI equipment far above domestic retail levels.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Investigators reported one recovery this summer of $550,000 in Celestica-built server switches destined for Meta and another of about $1 million in data center equipment found in a trailer outside Chicago. These recoveries were cited as examples of the broader targeting of enterprise and AI infrastructure cargo.
Following the suspected attacks, U.S. escort operators began reviewing stronger security measures for high-value technology shipments. Personnel were being encouraged to call 911 at the first sign of suspicion.
Verisk CargoNet reported 677 supply-chain theft incidents across the U.S. and Canada in Q2 2026, while losses rose year over year from $135.7 million to $304.6 million and the average reported theft reached $564,009. The firm also identified enterprise computing and networking equipment as a heavily targeted category.
Investigators came to suspect the truck drivers were complicit in both thefts. They also found both incidents involved motor carrier numbers that had recently changed hands, a fraud method used to book freight under a legitimate company's federal registration.
In recent months, two semitruck shipments carrying millions of dollars in AI data center hardware from Silicon Valley to Southern California were stolen after their private security escort vehicles were deliberately disabled. In one case the escort was rear-ended in a hit-and-run, and in the other it was forced into a tailspin with a PIT-style maneuver; the trucks then continued on and disappeared.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.