Carrier identity fraud
Carrier impersonation: when the carrier is real and the person emailing you isn't
Most carrier vetting is built to answer one question: is this a real, authorized, insured motor carrier? That question is still worth asking, and it is no longer the question that loses freight. The faster-growing attack uses a carrier that passes every check you can run — active authority, insurance on file, clean safety rating, years of history — because the fraud is not in the carrier. It is in the channel. A spoofed email domain, a hijacked dispatch inbox, a phone number that was never the carrier's, a login to a load board that changed hands. In the second quarter of 2026, communication-based attacks accounted for half of all classified fraud vectors tracked by Highway's Freight Fraud Index, up from 42.7% the quarter before. This page explains how carrier impersonation works, why a clean vetting file does nothing to stop it, and what you can actually check before each load moves.
Check a carrier now
Start with the federal record. Run an MC or DOT number free, no account, and see the carrier's authority, insurance and safety status — the baseline you compare every later contact against.
Just the number works — with or without the MC/DOT prefix, and spaces are fine. Tip: prefix an MC number with “MC” (e.g. MC123456) so it isn't read as a DOT number.
The shift: from fake carriers to compromised trust
For years the archetypal freight fraud was a fabricated identity. Someone registered authority under a new name, or reused a lapsed one, built a shell that looked like a carrier, took a load and disappeared. The whole vetting industry grew up around catching that: check the authority, check the insurance, check whether the entity is who it claims to be, and check it again if anything looks new.
That defense works, which is exactly why the attack moved. It is far cheaper to borrow an established carrier's identity than to manufacture a new one, and far more effective, because the borrowed identity passes every check on your onboarding form. Highway's Q2 2026 Freight Fraud Index put numbers on the shift: communication-based attacks — compromised inboxes, spoofed email, account takeover, impersonation calls — reached 50% of classified fraud vectors, up from 42.7% in Q1. The same report counted 784,201 fraudulent inbound emails blocked in the quarter, up 48.5% from Q1, and 109,995 spoofed or fraudulent phone calls, up 159.3% year over year.
The practical consequence for a broker is uncomfortable: your vetting file can be complete, current and correct, and still describe a company that has nothing to do with the person you are emailing.
The four ways carrier impersonation actually happens
These are variations on one idea — insert yourself into a conversation the carrier's reputation has already earned.
- Lookalike domain. Someone registers a domain one character off the carrier's real one, or the same name under a different ending, and emails you from it. Transposed letters are the classic: the eye reads what it expects. The signature block, the logo and the MC number are all copied from real correspondence, so nothing in the message body helps you.
- Compromised inbox. The email really does come from the carrier's real domain, because someone has the password. This is the hardest version to catch, because every technical signal — sender domain, mail authentication, message history — is genuine. What changes is behavior: new remit-to details, urgency, a request to move the conversation somewhere else.
- Spoofed phone number. Caller ID is trivially forged. A number that displays as the carrier's filed number proves nothing about who is on the line, which is why calling a number back — one you looked up yourself — is worth more than answering the one that called you.
- Account takeover. A load board or portal login changes hands, sometimes along with an update to the FMCSA record itself. Once the contact details on the federal record have been changed, a broker who dutifully verifies against that record is verifying against the fraudster's own data.
Why onboarding-time vetting cannot catch this
A carrier packet is a snapshot. It records that on the day you onboarded them, this carrier held authority, carried insurance, and gave you a phone number and an email address. Every one of those facts can be true and unchanged today while the conversation you are having right now belongs to someone else.
The gap is structural, not procedural. Vetting establishes that a company is legitimate. It does not, and cannot, establish that the message in your inbox came from that company. Nothing about checking authority more carefully closes that gap, which is why brokers who have tightened onboarding are still losing loads.
The fix is to treat verification as continuous rather than a gate you pass once. Two things have to happen after onboarding: the federal record has to be watched for changes, and each new contact has to be reconciled against it.
What to check before each tender
- Compare the sending domain to the record. FMCSA's carrier census carries an email address for most registered carriers. If the message came from a different domain, that is not proof of anything on its own — small fleets legitimately dispatch from webmail — but it is the single fastest way to catch a lookalike domain, which is otherwise invisible.
- Check when the sending domain was registered. A domain created weeks ago, used to move freight for a carrier that has been operating for fifteen years, is one of the strongest signals available. Domain registration dates are public.
- Call a number you looked up, not one you were given. Caller ID and email signatures are both attacker-controlled. The filed number on the federal record is not.
- Watch the record for contact changes. A phone number or physical address that changes on a carrier's FMCSA record, on a carrier you are actively hauling with, deserves a phone call before the next load. Legitimate carriers move and change numbers; the point is to know that it happened rather than to find out afterward.
- Treat new remit-to details as hostile until confirmed. Payment redirection is the endgame of most inbox compromises. A banking change that arrives by email is confirmed by phone, on a number from the record, or it is not confirmed.
- Keep a dated record of what you checked. When a load does go wrong, the difference between a defensible file and an argument is a timestamped record of what you verified and when.
What a mismatch does and doesn't mean
This is worth saying plainly, because the failure mode of any fraud signal is crying wolf until people stop reading it. A great many honest carriers run dispatch out of a Gmail account, use a cell phone that was never filed with FMCSA, and have never updated their MCS-150 contact details. A mismatch between the email in front of you and the record is a reason to make one phone call. It is not evidence of fraud.
What deserves a hard stop is narrower: a domain that is a near-copy of the carrier's real one, a domain registered in the last few months, or a change to payment details that arrived through the same channel you are being asked to trust.
Common questions
- What is carrier impersonation?
- Carrier impersonation is when someone poses as a real, legitimate motor carrier in order to be given freight. Unlike a fabricated or chameleon carrier, the identity being used belongs to a genuine company with real authority, real insurance and a real safety record — which is why it survives standard vetting. The impersonation happens in the communication channel: a lookalike email domain, a compromised inbox, a spoofed phone number, or a hijacked load-board or FMCSA account.
- How is this different from a chameleon or ghost carrier?
- A chameleon carrier is a bad operator reappearing under a new registration, and a ghost carrier is a shell with authority but no real fleet. Both are frauds about the entity, and both can be caught by examining the carrier record. Impersonation is a fraud about the channel — the entity is entirely genuine and someone else is speaking for it — so examining the carrier record alone will not surface it.
- Can email authentication like SPF, DKIM or DMARC stop this?
- They help against outright domain spoofing, and they do nothing against the two most common versions. A lookalike domain passes authentication perfectly, because the attacker owns that domain and configured it correctly. A compromised inbox also passes, because the mail genuinely originates from the carrier's real domain. Authentication is worth having and is not a substitute for comparing who is contacting you against the federal record.
- How much of freight fraud is this now?
- Highway's Q2 2026 Freight Fraud Index reported that communication-based attacks — compromised inboxes, spoofed emails, account takeovers and impersonation calls — made up 50% of all classified fraud vectors in the quarter, up from 42.7% in Q1 2026.
- Does CarrierClear check whether the person contacting me is really the carrier?
- Yes, on paid plans. You can paste the email address and phone number from a load offer or rate confirmation and compare them against the carrier's contact details on the FMCSA record, including a check on how recently the sending domain was registered. Monitoring also alerts you when the phone number or physical address on a saved carrier's federal record changes. CarrierClear is an information tool built on public federal records — it gives you the facts and the flags, and the decision about a carrier stays yours.
Sources
- 1.Q2 2026 Freight Fraud Index: half of all incidents now tied to communication-based attacks (50% of classified fraud vectors, up from 42.7% in Q1; 784,201 fraudulent emails and 109,995 spoofed calls blocked) — Highway, via GlobeNewswire, 2026-07-28
- 2.FMCSA Motor Carrier Census — public carrier registration records, including filed contact details — U.S. Department of Transportation
- 3.FBI Internet Crime Complaint Center — business email compromise guidance — Federal Bureau of Investigation
Chameleon carriers and identity reuse →Ghost carriers (phantom carriers) →Freight fraud prevention playbook →Continuous carrier monitoring →
CarrierClear displays public FMCSA records and records your own verification. It is not legal advice and not a certification of any carrier’s fitness, legitimacy, or insurance. Verify independently before relying on any record. Comparisons reflect our understanding of publicly available information as of the date shown and may change; CarrierClear is not affiliated with, endorsed by, or sponsored by any other company named here, and all trademarks belong to their respective owners.