Ghost carriers expose weak spots in broker vetting systems

Scammers acquire active authorities, insurance data and contacts to pass standard reviews

Ghost carrier image
Transactions involving "ghost carriers" increasingly surface on online marketplaces and social media. (Transport Topics with AI assistance)

Key Takeaways:Toggle View of Key Takeaways

  • Fraud now plays a role in roughly 45% of cargo theft cases, often involving impersonation of legitimate carriers.
  • Standard broker vetting checks can miss identity takeovers because authority, insurance and contact details still appear valid.
  • Brokers are shifting toward continuous and load-level monitoring to detect suspicious behavior after freight is in transit.

[Stay on top of transportation news: Get TTNews in your inbox.]

Brokers rely on a familiar checklist to vet carriers: active authority, valid insurance, clean safety record and verified contact information. Increasingly, that process is not enough.

In one recent case, a carrier that passed those checks picked up a load of computer equipment, then veered off route. Within hours, $3.5 million worth of cargo was gone.

The credentials were legitimate. The company was not.

For brokers, that kind of shift is becoming harder to detect and faster to unfold.



“You can use a carrier for years,”said Robert Loring, president of brokerage at TGR Logistics. “In six months, they go south and sometimes you’re not going to know about it for days or weeks. Suddenly, they go bad and they go bad quick. It’s a constant struggle.”

Strategic cargo theft tied to fraud and impersonation is evolving to exploit the systems brokers rely on to establish trust, allowing bad actors to assume the identities of legitimate carriers and move freight before anyone realizes something has changed.

At the center of the problem is a mismatch: Vetting systems designed to confirm static information are now being tested by fraud schemes built on rapid identity shifts.

The scam process

One of the fastest-growing threat vectors involves so-called ghost carriers, entities that acquire the identities of legitimate trucking companies. Scammers do not just obtain an MC number; they often take control of associated phone numbers, email addresses and Federal Motor Carrier Safety Administration credentials, giving them everything needed to pass standard verification checks.

In effect, they are not creating new companies. They are inheriting the digital footprint of existing ones.

Those transactions increasingly are surfacing across online marketplaces and social media channels, industry experts say, where brokers and carriers may never see them unless something goes wrong.

RoadSigns

Kevin Clark of Cox Fleet discusses how fleets should rethink their maintenance strategies to stay efficient and resilient. Tune in above or by going to RoadSigns.ttnews.com.  

Criminals often target carriers whose insurance coverage is nearing expiration, typically within 30 to 90 days. At that point, operators already facing weak freight rates and rising costs may opt to exit the business rather than renew coverage.

Instead of shutting down quietly, some accept buyouts, sometimes for just a few thousand dollars, transferring control of their authority and digital assets in the process.

Once the transfer is complete, the new operators can begin impersonating the original company. On paper, nothing appears out of order: The authority remains active, contact information works and third-party verification checks still pass.

To a broker running a standard screening process, the carrier still looks like the same company it was weeks earlier. The underlying reality, however, may be entirely different.

Why brokers miss it

The challenge for brokers is that many traditional warning signs never appear. There are no obvious gaps in authority, no immediate lapses in insurance, no disconnected phone lines or mismatched email domains.

The carrier still looks legitimate until it doesn’t.

Purchased MC authorities have become one of the most concerning fraud trends, said Keith Lewis, vice president of operations at Verisk CargoNet, noting that roughly 45% of the firm’s cargo theft cases involve fraud.

That dynamic has pushed regulators to begin addressing the issue. In March, FMCSAissued a bulletin warning carriers not to buy, sell or lease USDOT or MC numbers. The notice is part of the agency’s broader Registration Modernization initiative, which includes the Motus platform and could eventually phase out MC numbers in favor of USDOT identifiers.

Image
Keith Lewis

Lewis

Even so, enforcement remains uneven, and the distinction between legitimate asset sales and fraudulent identity transfers is not always clear.

In practice, brokers often are left to make real-time decisions based on incomplete or outdated information, a vulnerability that fraud rings have learned to exploit.

A recent case analyzed by GenLogs illustrates how quickly these schemes can escalate.

The incident began when a carrier, Hilder Herd Transport, sold its MC number and digital assets. With those credentials in hand, the new operators were able to present themselves as a legitimate carrier and secure a high-value load of computer equipment.

From the broker’s perspective, the checks cleared. The carrier’s authority was active. Contact information matched. Nothing in the standard vetting process triggered a stop.

From there, the scheme escalated. The load was double-brokered using another MC number under the fraud ring’s control and redirected from Cincinnati to Anaheim, Calif., using an unsuspecting legitimate carrier.

Once in transit, the shipment was transloaded to another truck parked on a public street — a transfer captured unintentionally on video. Within hours, roughly $3.5 million worth of goods disappeared.

The speed of that sequence is part of what makes these cases difficult to prevent. By the time inconsistencies emerge, the freight is often already out of reach.

Looking back, GenLogs’ data showed multiple warning signs in the weeks leading up to the theft. Trucks associated with the MC number were no longer operating, suggesting the business had effectively gone inactive. At the same time, the carrier began bidding on cross-country loads outside its historical footprint, despite previously operating regionally.

Image
Ryan Joyce

Joyce 

Available imagery also indicated the carrier lacked the equipment needed to handle sensitive freight, another signal that the operation on paper did not match real-world capabilities.

Individually, those indicators might not have stopped the load. Together, they pointed to a carrier behaving far outside its normal operating pattern, a shift that traditional vetting processes are not designed to catch consistently.

“The information was there. It was highlighted in red,” said Ryan Joyce, CEO of GenLogs. “This wasn’t a failure of the software. This was a failure of somebody looking at the information and deciding to move forward anyway.”

Staying ahead of the threat

For brokers, staying ahead of that kind of activity increasingly requires more than periodic checks.

Carriers may be re-vetted multiple times a year, particularly around insurance renewals, but those point-in-time reviews offer only a snapshot. In an environment where ownership and control can change quickly, static checks can quickly become outdated.

As a result, brokers are layering multiple systems together to close those gaps.

Platforms such as GenLogs, Highway, RMIS and SaferWatch provide overlapping forms of verification, from compliance monitoring and identity validation to real-time operational data. Yet each additional layer of scrutiny has prompted new workarounds from fraud rings, turning vetting into an ongoing arms race.

Technology alone, however, is not enough.

The effectiveness of these tools ultimately depends on how they are used, and whether the signals they generate are acted upon. As the GenLogs case illustrates, detection and decision-making remain separate steps, and failure at the second stage can be costly.

TGR Logistics, for example, combines multiple compliance platforms with GPS tracking to confirm that loads remain where they are supposed to be. In one recent case, a truck deviated from its expected route immediately after pickup, prompting an immediate call to the driver before the situation escalated.

That kind of intervention reflects a broader shift in how brokers approach risk.

Rather than relying solely on whether a carrier checks out at onboarding, the focus is increasingly on whether a load continues to behave as expected once it is in motion.

The shift, industry executives say, is toward monitoring behavior at the load level, not just validating credentials at the carrier level.

“The days of setting your carrier selection criteria checklist and moving on are over,” said Michael Grace, vice president of customer risk management at Highway. “Now we’re looking at load-level compliance.”

 

Newsletter Signup

Subscribe to Transport Topics

Subscribe  Gift a Subscription

FOLLOW US ON GOOGLE NEWS