White paper · Part 1 of 4
How freight diversion actually works: the main modus operandi
Cargo theft has moved from force to deception. This first part maps the modus operandi observed in practice, and the two structural features of today’s freight market that make every one of them easier to run.
From force to deception
For many years, verifying a carrier meant confirming a handful of core documents — a Community Licence, proof of insurance, a company registration extract. In an environment where cargo theft was primarily opportunistic, those checks gave reasonable assurance that a transport provider was legitimate.
The risk landscape has changed considerably. Cargo theft increasingly relies on deception rather than force. Instead of stealing a loaded vehicle or hijacking a shipment, criminals impersonate legitimate transport companies, manipulate identities, compromise communications, or create convincing fictitious businesses to obtain freight assignments. The truck arrives, the documents appear authentic, the transaction looks legitimate — until the cargo disappears.
A sustained increase in this type of fraud has been observed, and these schemes are increasingly run by organised criminal networks that combine digital deception with a detailed understanding of transport operations. Beyond the immediate loss of a stolen shipment, a successful fraud can damage customer relationships, generate insurance disputes, and expose freight forwarders to legal scrutiny where due diligence is found to be inadequate.
Three things that are true of almost every case
Before the typologies themselves, three cross-cutting traits:
- Targeted. Reconnaissance on a specific shipper or lane precedes the attempt, rather than opportunistic contact.
- Digital. The point of attack has shifted toward email, identity and documents — alongside, not instead of, the physical layer.
- Industrialised. Organised groups run fraud as a repeatable, tooled, AI-assisted operation rather than a one-off act.
The four modus operandi below are presented separately, but in practice they are rarely used in isolation — a single operation often combines several. The categorisation is an analytical tool.
1. Corporate spoofing
Impersonation of a legitimate, credible transport company. Four techniques recur:
- DNS and email spoofing, typosquatting. Registration of a domain almost identical to the legitimate company’s — for example @logistix-transp0rt.com instead of @logistix-transport.com — used to contact shippers or forwarders while exploiting limited scrutiny of email details.
- Website cloning. A near-identical site replicates the targeted company’s legal notices and logos, but with typosquatted contact details, creating an illusion of authenticity under a quick check.
- Document falsification. Company registration extracts, Community Licences and insurance certificates are reproduced from authentic originals that have been obtained or intercepted, then altered with standard desktop-publishing software and AI tools and reassembled into forged PDFs.
- Social engineering and urgency. Tight deadlines and unusually attractive pricing are used to compress the time available for document and human verification.
2. Account compromise
Gaining access to a legitimate user’s account in order to infiltrate an existing, trusted logistics chain from the inside — or to take over a genuine carrier’s account on a freight exchange platform.
- Targeted phishing. Emails impersonating the platform itself prompt a password reset through a malicious look-alike site, capturing the victim’s credentials.
- Credential stuffing. Automated testing of username and password combinations sourced from leaked databases against the platform’s login.
- Takeover of a genuine freight exchange account. The criminal inherits the trust and verified status already attached to that account, and communicates through the platform’s own secure channel.
- Bidding on live loads. Once inside — mailbox or platform — the criminal bids on current freight orders and identifies the account’s existing clients from its trusted history.
An observed pattern. Criminals monitored a compromised mailbox before acting, to identify the target’s upcoming leave. Once the person left for holiday, they registered a typosquatted domain and began diverting a significant volume of freight in his name — exploiting the fact that the victim was not checking email and not answering his mobile. The dwell time between initial compromise and active exploitation is a deliberate tactic, not a delay: the criminals wait for the window in which detection and reaction times are lowest, to maximise the volume diverted.
The same logic explains why, once a load has been diverted, criminals typically supply plausible explanations for delivery delays — vehicle breakdowns and the like — rather than abruptly going silent. Those responses buy time to divert further shipments before the scheme is discovered, and to ensure previously diverted freight has already been dispatched onward before recovery efforts can start.
3. Corporate capture
This scheme is not built on impersonating or compromising a legitimate carrier, but on creating or acquiring a fully genuine company.
A criminal group either incorporates a new transport company or buys a controlling stake in an established one, and places a nominee — an homme de paille — as registered shareholder or director, obscuring who actually controls the entity.
Every document such a company presents is authentic, and cross-document consistency holds, because everything genuinely matches. That makes it one of the hardest typologies to catch through document-based controls alone.
4. Physical misappropriation
The execution phase — the physical diversion itself, typically the final stage of a booking secured through one of the typologies above. Two scenarios are commonly observed.
A. The criminal acts as the freight forwarder
The criminal poses as a freight forwarder and charters a presumed good-faith carrier. The diversion is engineered through the instructions given to that carrier, rather than through any falsified vehicle or driver identity.
This often involves mid-transport redirection: once the vehicle is en route, new delivery instructions redirect the cargo. The scenario should immediately raise questions — the scheme is well known and the delivery address on the CMR always prevails — yet in practice the carrier often proceeds as instructed.
Other methods have been observed, including false confidentiality claims: the criminal states that because of the sensitivity of the cargo the destination is confidential, which is offered as the reason the loading site itself does not know the final destination. This commonly involves multiple CMRs issued with different delivery addresses for the same shipment.
B. The criminal sends a complicit carrier
The criminal supplies their own driver and vehicle into the transport chain directly. The driver who presents for loading is complicit in the scheme, and the vehicle plates are false or stolen.
What happens downstream, in both cases
The cargo is rerouted toward a clandestine warehouse before being re-dispatched onward — a stage that is itself industrialised and run by organised, often transnational networks that coordinate storage, re-dispatch and disposal as a standing operational capability rather than a one-off arrangement.
The goods are typically absorbed into secondary markets or dedicated resale channels — pharmaceuticals among them — including abroad. Some cases have also been observed where the diverted cargo was held for ransom, with payment demanded in cryptocurrency.
Two structural amplifiers
Beyond the specific techniques, two features of today’s freight market ease the conditions that enable diversion — regardless of how sophisticated any individual attack is.
Freight exchanges: marketplace and attack surface
Digital freight exchanges have strengthened onboarding, identity verification and platform security, making fraudulent registrations increasingly difficult. They have implemented two-factor authentication, issued regular security guidelines, and introduced further measures against misuse. Nevertheless, they continue to be widely exploited in practice, for three reasons:
- They serve as an intelligence and sourcing platform, letting criminals identify high-value and sensitive cargoes to target.
- They enable direct contact with shippers and forwarders at precisely the moment additional capacity is needed. Using a platform usually follows from being unable to rely on an internal fleet or pre-approved carriers, so the buyer must engage with previously unknown providers — exactly the access model criminals exploit.
- They provide a trusted communication channel — the platform’s secure chat. Compromised or fraudulently controlled accounts let attackers approach counterparties while benefiting from the platform’s established credibility.
Cascading subcontracting
Cascading subcontracting significantly weakens cargo security, and diversion schemes are frequently orchestrated inside multi-layered subcontracting chains. Every additional layer reduces visibility over who will ultimately perform the transport and progressively weakens identity assurance across the chain.
A shipper contracts a freight forwarder, who subcontracts the load to another forwarder or carrier, who may subcontract it again. At each handover, the party awarding the next contract is responsible for verifying the identity and legitimacy of its subcontractor — but the original principal no longer has direct oversight of those checks. By the time the shipment is collected, the carrier physically executing the transport may be several contractual layers removed from, and entirely unknown to, the cargo owner.
Adapted from the Vectys white paper “Preventing freight diversion”, August 2026.
Provided for informational and guidance purposes only. It outlines general principles, best practices and potential risk mitigation approaches, and does not constitute legal advice, compliance advice, or a guarantee of fraud prevention, regulatory compliance or operational risk elimination.
