The FBI's $725 Million Warning: Cargo Theft Is Now a Cybercrime

The FBI just released a public service announcement on a fast-growing scam, and the numbers are hard to ignore. In 2025, cyber-enabled cargo theft cost American businesses around $725 million. That is a 60% jump over 2024, with the average single theft now north of $273,000. The advisory focuses on trucking and logistics, but the playbook is the part that should worry every business owner.

How the Scheme Works
The scam is built on a chain of small steps, none of which look like "theft" until the last one.
First, the criminals get into a legitimate inbox. Usually it is a phishing email dressed up as a broker agreement, a service review request, or a routine vendor message. Click the link, install the helper application, and an attacker now has a foothold in a real corporate email account.
Second, they post fake loads on freight boards using that compromised account. Brokers and carriers see thousands of these listings, and they look exactly like everything else on the board because they come from a verified company.
Third, the attackers bid on real shipments, manipulate the bills of lading, and reroute the cargo in transit.
Fourth, the load gets handed off to a complicit driver and the goods are gone, sold downstream before anyone realizes they were taken.
Each step uses a small piece of trust the company built up legitimately, and each step looks like normal business until the next one.
The Pattern Is Bigger Than Cargo
If you read past the trucking-specific details, the four phases are identical to almost every modern business email compromise:
- Get into a real inbox.
- Use that inbox's reputation to issue fraudulent instructions.
- Move money or goods before anyone notices the request didn't actually come from the legitimate party.
- Disappear.
Swap "freight board" for "wire transfer," "bill of lading" for "vendor invoice," "complicit driver" for "money mule," and you have the same scheme that has been hitting law firms, real estate brokers, manufacturers, and city governments for years.
The FBI's advisory focuses on transportation because that sector is having its turn at the front of the line. The mechanics are universal.

We Are at an All-Time High, and It Will Get Worse
The $725 million in cargo theft is one slice of a much bigger picture. The FBI's 2025 Internet Crime Report logged $20.877 billion in reported losses across more than one million complaints, both records, and a 26% jump from 2024. The average loss per complaint with actual financial harm came in at $20,699. Investment fraud was the largest single category, followed by business email compromise. Total losses have grown roughly fivefold in five years, from $4.2 billion in 2020 to $20.9 billion in 2025.
Those numbers come from a year the FBI publicly disrupted scam call centers, dismantled fraud and laundering syndicates, and ran Operation Level Up to claw back more than $500 million from crypto investment scams. Even with the wins, losses still climbed by a quarter.
A few honest reasons it will keep climbing:
- Generative AI lets criminals scale spear-phishing the same way it lets businesses scale marketing. Convincing emails that used to take a small team to write now take one person and a free tool.
- Deepfake voice and video make impersonation calls plausible at a price point any criminal group can afford.
- Stolen credentials are a commodity. Past breaches feed every new attack.
- Reporting still lags. The actual numbers are higher than the FBI sees.
This is the environment business owners are operating in now, and it does not look like it is rolling back.
Practical Things You Can Do This Week
You do not need an enterprise security budget to make most of these scams much harder. The list below comes from how these attacks actually unfold and where they break down when defenses are in place.
1. Verify with a phone call. Any change to a payment instruction, a shipping address, a vendor banking detail, or a routing decision gets a callback to a known phone number. Not the number in the email. The one already on file.
2. Turn on multi-factor authentication on every business email account. The first move in the FBI's scenario was inbox compromise. MFA is the single highest-leverage thing you can do to stop it.
3. Audit mailbox rules. Attackers commonly add quiet forwarding rules so they can read your conversations without you ever seeing the alert. Check your own rules. Train your team to check theirs.
4. Watch for lookalike domains. The scams use extra punctuation, swapped letters, a different top-level domain. If "[email protected]" suddenly becomes "[email protected]" or "[email protected]," that is the attack.
5. Document everything. The FBI advisory specifically calls out the importance of detailed records of all parties and communications. When the dispute starts, the side with the paper trail wins.
6. Train on the pattern, not the slogan. "Don't click suspicious links" is not training. Walking through how a real BEC unfolds, with the actual emails, is.
A Word on Where This Is Going
If your defense plan was built around the idea that the criminals are unsophisticated, that plan is no longer accurate. The groups doing this are organized, patient, and operating at scale. They will study your business the same way a serious competitor would, and they will find the seam.
The good news is that the basics still work. Multi-factor authentication, a callback policy, alert employees, and a willingness to slow down a transaction when something feels off will defeat the majority of these schemes. The companies that take a hit in 2026 are mostly going to be the ones who skipped the basics.
The FBI's cargo theft advisory is one warning. There will be more. The question for any business owner is whether the next advisory is something to read about, or something to live through.
Sources: FBI Internet Crime Complaint Center, PSA I-043026-PSA: Cyber-Enabled Strategic Cargo Theft Surging, April 30, 2026; FBI Internet Crime Complaint Center, 2025 Internet Crime Report. Inline graphic: FBI/IC3, public domain (U.S. Government work, 17 U.S.C. § 105).

