top of page

Email Threats and Cargo Theft

Writer: Dominick Zangaro
Dominick Zangaro
Sep 29
2 min read

For most of the trucking industry, cyber security sounds like something for the IT department. With the rise in cyber-enabled cargo theft, it’s more than just IT. Every employee is a cyber security employee.  


Email's Role in Cargo Theft

In April 2026, the Federal Bureau of Investigation (FBI) warned that hackers are breaking into broker and dispatcher email accounts, and then using them to post fake loads, grab real ones, and reroute deliveries.


It usually plays out one of three ways:


  • The lookalike address. Your dispatcher gets an email from dispatch@smithfreightllc.com. The real email is smithfreight.com.

  • The fake document. Phishing links can be embedded in documents to bypass traditional email security systems, and forged documents might go unnoticed in typical dispatching. 

  • The hijacked account. Someone clicked a bad link, and now a criminal is sitting inside a real carrier’s inbox. Everything about the email appears normal, but the person sending it has bad intentions. 


Simple Email Security

Three email settings, known by their initials, make it much harder for anyone to send email that looks like it came from your company. 


  • Sender Policy Framework (SPF) is your approved carrier list for email. It tells everyone which email servers are allowed to send on behalf of your company’s web address (domain).

  • DomainKeys Identified Mail (DKIM) is the seal on the trailer. It puts a digital signature on every email you send, so the other side can tell it really came from you and wasn’t tampered with on the way.

  • Domain-based Message Authentication, Reporting and Conformance (DMARC) is the instruction for a broken seal. It tells your email servers to block or quarantine email that comes with a ‘broken seal’, and it sends you reports when someone tries to use your name.


How Miti can Help

Miti is a cybersecurity platform specializing in cyber-enable cargo theft reduction solutions for logistics firms to reduce fraud and transact business confidently. Our protection doesn't stop when the load is delivered because between loads, Miti watches transactions across the ecosystem that can signal an account takeover, like suspicious logins, new contacts, or changes to insurance or operating authority. 


Not sure where your company stands? Miti will run a free analysis of your email setup. We'll confirm that SPF, DKIM and DMARC are enforced and actually blocking fake email, and give you plain guidance on tightening up the rest.


For your free assessment, email consulting@mitirisk.io.


Follow Miti for more on emerging cybersecurity risks in freight.


 
 
 

Comments


bottom of page