The truck arrived, the paperwork matched, and the freight was never seen again
Estimated cargo theft losses in the United States and Canada reached nearly $725 million in 2025, up roughly 60 percent in a single year, and the fastest growing share of it is not people cutting locks. It is people who are handed the freight. Every document in the chain can be forged. A signature from an enrolled dispatcher cannot.
The load tenders at 06:40 on a Tuesday. A shipper in Ontario, California has forty-two pallets of consumer electronics going to a distribution center outside Dallas, and the broker has it covered by 09:00 with a carrier whose MC number checks out, whose authority has been active for six years, and whose certificate of insurance arrived by email inside four minutes of the request.
The truck shows up at 13:10, inside the window. The driver has a printed rate confirmation with the correct load number, the correct pickup and delivery appointments, and the correct broker logo in the header. He gives a name. The name matches the one on the dispatch email thread. The dock supervisor checks the bill of lading against the pick list, watches the pallets go on, gets a signature, and waves the truck out at 14:25.
Nobody at that facility did anything wrong. They followed the process exactly as written. The carrier on that rate confirmation is a real company in Illinois with six trucks and a clean safety record, and right now its owner is asleep, because he has never heard of this load, this shipper, or this driver. Somebody registered a domain that differs from his by one character, answered the broker's calls on a number they controlled, and sent a copy of a certificate of insurance they pulled off a public filing. The forty-two pallets are on their way to a cross-dock in a different state where they will be broken down and sold inside seventy-two hours.
The first anyone will know is when the receiver in Dallas calls to ask where the delivery is.
What actually failed in that story?
Read the sequence again and mark every point where somebody checked an identity.
The broker checked the MC number against the Federal Motor Carrier Safety Administration register, and it was a real MC number belonging to a real carrier. The broker checked the certificate of insurance, and it was a real certificate, because it was a real carrier's real certificate, copied. The broker called the phone number, and somebody answered professionally. The dock checked the rate confirmation against the load in their system, and it matched, because the fraudster had booked the load and therefore had the real document. The dock checked the driver's name against the dispatch email, and it matched, because the fraudster wrote both.
Six checks. All passed. Every one of them was a check on a document or a channel, and every document and channel in that list was either genuine and stolen, or forged and never compared against anything that would have caught it.
Here is the sentence worth sitting with. At no point in that entire chain did anyone verify that the human at the dock had been authorized by the company whose name was on the paperwork. Not because anybody was careless. Because there is currently no way to do it.
That is not a vetting failure. Vetting worked. The carrier was real and the carrier was vetted. That is a delegation failure, and it is a different kind of problem with a different kind of fix.
What is a fictitious pickup, and how is it different from double brokering?
These two get used interchangeably in coverage and they are not the same thing. The distinction matters because they break at different points in the chain, and a control that stops one may not touch the other.
Fictitious pickup
An impostor physically takes possession of freight at the shipper's dock using stolen or fabricated carrier credentials. The load is gone at the moment of release. There is no legitimate party downstream, no chain of custody to unwind, and typically no recovery. The freight is converted to cash within days.
The identity failure is precise: the person who took the goods was not authorized by the party the broker contracted with. Everything upstream can be perfectly legitimate. The break happens in the last thirty seconds, at the gate.
Double brokering
A party that presents as a broker accepts a load and then re-brokers it to another carrier, usually without disclosure and usually without authority to do so. Often the freight is actually delivered, by a real carrier doing real work. The damage is financial rather than physical: the intermediary collects the payment and disappears, and the carrier that hauled the load is left unpaid, sometimes placing a lien on freight that the original shipper already paid for.
The identity failure here is upstream. The party that accepted the load was not who they represented themselves to be, or held authority they did not have. The delivering carrier is an innocent party who took a load from a load board in good faith.
Why the difference changes the control
A dock-level control stops fictitious pickup outright, because the fraud is consummated at the dock. It does not by itself stop double brokering, because in the double brokering case a legitimate driver from a legitimate carrier arrives and everything at the dock is genuine. What a dock-level control does to double brokering is make it visible: if the delegation presented at the dock traces to a carrier that is not the carrier the shipper contracted with, the discrepancy surfaces at the moment of pickup rather than sixty days later in a payment dispute.
That is a useful property and it is worth being precise about it. The control eliminates one class and converts the other from an invisible problem into a detected one at the earliest possible moment.
How big is strategic cargo theft in 2026?
In April 2026 the FBI's Internet Crime Complaint Center issued a public service announcement on cyber-enabled strategic cargo theft, reporting that estimated cargo theft losses across the United States and Canada surged to nearly $725 million in 2025, an increase of roughly 60 percent over 2024, while confirmed incidents rose about 18 percent (FBI IC3 public service announcement, April 2026).
Read those two numbers next to each other, because the relationship between them is the whole story. Incidents up 18 percent. Losses up 60 percent. The average theft got substantially more valuable. That is what happens when a crime shifts from opportunistic to selected: a thief cutting a trailer seal in a truck stop takes whatever is inside, while a thief who books the load chooses the commodity, the lane, and the value before making a single phone call.
Industry reporting through 2025 and into 2026 describes strategic theft, meaning fictitious pickups, carrier identity fraud and double brokering, growing from a small fraction of incidents to a large one, with some analyses putting it near 40 percent of cases against roughly 5 percent a few years earlier. Quarterly reporting from Overhaul in early 2026, as summarised in freight trade coverage, described deceptive pickup schemes up around 31 percent year over year. Treat the precise shares carefully, because different firms count differently and each publishes from its own book of business, but the direction is not in dispute and it is corroborated by the federal advisory.
One more figure worth holding: a single truckload of electronics, pharmaceuticals, or non-ferrous metals routinely carries a cargo value above $250,000. This is not a category where the expected loss per event is small enough to absorb.
Why does carrier vetting not stop this?
The freight industry has spent heavily on vetting, and the vendors in that space do genuinely useful work. Highway, Carrier Assure, MyCarrierPortal and others check authority status, insurance, operating history, safety scores, and increasingly behavioural signals across booking patterns. Load boards including DAT and Truckstop have run identity programs since 2024 and 2025. None of this is theatre and none of it should be dismissed.
It fails against this specific attack for a structural reason, and the reason is worth stating in one line: vetting answers a question about an entity, and the fraud happens to a human.
What each control actually establishes
| Control | What it proves | What it cannot establish | Stops fictitious pickup? |
|---|---|---|---|
| FMCSA authority lookup | An MC number exists and its authority is active | Whether the party using it today is the registrant | No |
| Certificate of insurance check | A policy existed on a date for a named insured | Whether the sender is the insured, since certificates are copyable | No |
| Carrier vetting platform | Entity history, safety record, risk indicators | Who is driving today, and whether they were dispatched | Rarely |
| Phone call to number on file | Somebody answered a number | Whether the number belongs to the carrier or the impostor | No |
| Load board identity program | The account holder was verified at signup | Who is operating the account on this load | No |
| Driver licence photo at the dock | A document was presented and photographed | Any link between that person and the booking | No |
| GPS and geofencing | Where the trailer went after it left | Anything at all before the freight is already gone | No, it is forensic |
| Signed pickup delegation | This carrier's enrolled dispatcher authorized this driver for this load | Whether the carrier itself is a bad actor | Yes |
The document problem, stated plainly
Think about what a certificate of insurance is. It is a PDF that asserts something true about a company. It has no cryptographic binding to the person emailing it, no expiry that a recipient can check independently, and no mechanism by which the recipient can distinguish the original from a copy. It is, functionally, a photograph of a fact.
Every artifact in a freight booking has that property. The MC number is a public identifier, which means it is also a public target. The rate confirmation is generated after the fraudster already has the load. The bill of lading is created at the dock by the dock. There is no artifact anywhere in this chain that a thief cannot obtain, copy, or generate.
Compare that to how the same industry handles a different problem. Nobody accepts a driver's hours of service on a handwritten note any more, because the electronic logging device mandate forced a shift from a claim on paper to a record from a device. The freight industry has already done this once. It has simply not done it for identity.
What is actually missing at the dock?
Strip the problem to its smallest form. The dock supervisor is being asked one question, and it is not the question anyone thinks it is.
The question is not "is this driver a real person", because he obviously is, he is standing there. It is not "does this paperwork look right", because it does, the fraudster booked the load and therefore holds real paperwork. The question is: did the company we contracted with send this specific human to collect this specific load?
Right now there is no way to answer that question at a gate in ninety seconds. Not a hard way, not an expensive way. No way. The information required to answer it exists only inside the carrier's dispatch system, and the dock has no channel to that system that a fraudster could not also fake, because every channel available is email or a phone number, both of which the fraudster supplied.
This is what we call the Enrollment Binding Gap in the Identity Failure Map: an entity is verified once, at registration, and nothing binds that verified entity to the human who later acts in its name. It compounds with Trust Islands, because each broker, shipper, load board and vetting service holds its own verification result that no other party can check.
It is the same failure that shows up in vendor email compromise, where a real supplier's real invoice arrives with fourteen changed digits, and in e-signature workflows, where the artifact binds a mailbox rather than a person. Different industries, identical shape. Somebody is trusted because a document about them was correct.
How would a signed pickup work?
The control is a delegation. The carrier of record signs a statement authorizing one specific driver to collect one specific load inside one specific window, the driver presents that statement at the dock, and the dock verifies it. Three steps, each of which needs to be practical or none of it matters.
Step one: the dispatcher signs the assignment
When the carrier assigns the load in its transportation management system, the dispatcher signs a small object on their enrolled device. This is a per-action signature bound to the exact content of the assignment, not a login and not a session. The payload looks like this:
{
"type": "pickup_delegation",
"load_id": "BRK-8842190",
"carrier_mc": "MC-724118",
"shipper_site": "ONT-DC-04",
"driver_key": "z6Mkf3n...9qTb",
"tractor": "4471",
"pickup_window": ["2026-09-17T12:00Z", "2026-09-17T18:00Z"],
"scope": { "actions": ["collect_freight"] },
"maxChainDepth": 1,
"revocationId": "rv_8842190_a"
}
The dispatcher's signature covers the hash of that whole object. Change the load number, the driver key, the tractor, or a single minute of the window, and the signature fails. This matters more than it might appear: it means the delegation is not a credential that can be reused, forwarded, or repurposed for a different load. It authorizes one collection.
Step two: the driver carries it
The delegation lands in the driver's wallet on their phone. The driver does not need to understand any of this, and should not have to. From their side it is one more line in the app they already open for the load, alongside the appointment time and the dock number.
The important design property is that the driver holds the delegation. It is not fetched from a server at the gate, because the gate is exactly where connectivity is worst.
Step three: the dock verifies, offline
At the gate the driver's device presents the delegation and a fresh proof of presence, which in the Manav flow is a Beam pattern displayed on the dock screen and claimed by the driver's phone, binding the person holding the enrolled device to this moment rather than to a token copied last week. The dock software verifies the chain:
function verifyPickup(presented, expected, publishedKeys) {
const d = presented.delegation;
// 1. The dispatcher's signature is genuine and the payload is unaltered
if (!verifyEd25519(d.payload, d.signature, publishedKeys[d.carrier_mc])) return DENY;
// 2. It is for this load, at this site, right now
if (d.payload.load_id !== expected.load_id) return DENY;
if (d.payload.shipper_site !== expected.site) return DENY;
if (!withinWindow(now(), d.payload.pickup_window)) return DENY;
// 3. The carrier that signed is the carrier we contracted with
if (d.payload.carrier_mc !== expected.booked_carrier) return FLAG_DOUBLE_BROKER;
// 4. The human at the gate holds the delegated key
if (!verifyPresence(presented.presence, d.payload.driver_key)) return DENY;
return RELEASE; // and write the receipt
}
Note what is absent from that function. There is no network call. Verification is a signature check against the carrier's published key, which the dock software can cache and refresh on any schedule it likes. A dock with no bars of signal, in a metal building, at a facility whose guest wifi has been broken since March, can still complete this check. That is not an accident of the design, it is the reason the design uses offline verifiable receipts at all. We wrote about why that property matters in general in verifying a credential without phoning the issuer.
Line three is where double brokering surfaces. The delegation is cryptographically valid, the driver genuinely holds the key, everything is real, and the carrier that signed it is not the carrier on the shipper's contract. That is not a theft in progress. It is a disclosure failure, and now it is visible at 13:10 on Tuesday rather than in a payment dispute in November.
Will this survive a real dock?
This is the question that separates a control somebody will actually run from a slide in a vendor deck, and it deserves a direct answer rather than optimism.
The operating environment is genuinely hostile to software. A driver may have been on the road for nine hours. It may be raining. He may be wearing gloves. His phone may have a spidered screen and 6 percent battery and an operating system three versions behind. The facility may have no reliable data connection inside the building. The dock supervisor is managing a queue, and every second added to a gate transaction multiplies across every truck behind this one. Any control that takes two minutes will be worked around within a week, and the workaround will be worse than the original problem, because it will be a habit of skipping the check.
So the budget is roughly this: under thirty seconds at the gate, works with gloves on, works with no signal, works on a cheap Android phone, and fails in a way that gives the supervisor a clear next action rather than a mystery. Those constraints are demanding but they are not unusual, and they are the same constraints that shaped how the presence check works: a pattern on a screen, a phone that claims it, no typing, no URL, no scanning of a document, no upload.
There are cases this design has to handle rather than wish away. A driver whose phone is dead needs a path, which means the dock needs a supervisor override that is itself signed and logged rather than a verbal exception, otherwise the override becomes the new attack. Team drivers mean two keys on one load. A driver reassigned at 05:00 because someone called in sick means the dispatcher signs a replacement delegation and revokes the first, which takes about as long as sending the text message they would have sent anyway. Owner-operators are their own dispatcher and sign their own delegation, which is a smaller ceremony, not a larger one.
Who pays for this, and why would anyone adopt it?
Being honest about adoption is more useful than pretending the technology settles it. Nothing here works unless carriers enroll, and carriers will not enroll because a technology vendor asks nicely.
There are three forces that plausibly move this, and they are not equal.
The first is the shipper with concentrated exposure. A company moving high-value electronics or pharmaceuticals on repeat lanes has a small number of carriers and a large expected loss, and can simply require signed pickups on those lanes. That is a contractual change, not an industry change, and it is where anything like this starts.
The second is the load board and the transportation management system, which is the natural distribution channel, because the dispatcher is already in that software when they assign the driver. A signature is a button in a screen they were already using. This is the only path by which enrollment becomes cheap rather than a project.
The third, and probably the strongest over time, is the cargo insurer. Insurers price controls. If signed release produces a receipt that is offline verifiable and unforgeable, then loss experience on lanes with the control can be compared against lanes without it, and the premium difference does what no amount of advocacy will. This is the same mechanism that made telematics normal in fleet insurance.
To be clear about where this stands: Manav ships the primitives described above, which is to say per-action signatures, delegation chains with scope and expiry and revocation, Beam presence on a companion device, and offline verifiable receipts. Manav has shipped no logistics integrations, no TMS connector, and no load board partnership. The flow in this post is a reference design, not a product you can buy this afternoon, and anyone telling you otherwise about any vendor in this space deserves a hard question about what exactly is deployed.
Honest limits
A control is only worth adopting if you know precisely what it does not do.
- It does not stop a dishonest carrier. If the carrier of record is itself the fraudster, they will sign a perfectly valid delegation to their own driver and take the freight. This control binds the human at the dock to the contracted entity. Deciding whether that entity deserves the contract is what vetting is for, and vetting remains necessary. The two controls address different halves of the problem, and neither replaces the other.
- It does not stop physical theft. Straight cargo theft, meaning trailers taken from yards and truck stops, is unaffected. That class needs locks, yard security and telematics, and those remain worth funding.
- It does not stop coercion. A driver forced to sign under duress produces a valid signature. No cryptography addresses this and any vendor claiming otherwise is selling something.
- It does not fix double brokering by itself. As described above, it detects the discrepancy at pickup. Detecting it early is worth a great deal, and it is not the same as prevention.
- It requires enrollment on both sides. A shipper who requires signed pickups from a carrier who has not enrolled has a load that cannot be collected, which is a commercial problem before it is a security one. Rollout has to start where the value density justifies the friction.
- Key loss is a real operational cost. A dispatcher who changes phones needs a recovery path, and a bad recovery path re-opens everything the control closed. This is a genuinely hard problem and we treat it separately in the piece on recovery.
What to do this week
None of the following requires buying anything, and all of it is useful whether or not you ever adopt a signed pickup flow.
- Write down your release rule. Ask your dock supervisors what would have to be true before they refuse to load a truck. If the honest answer is "the paperwork looks wrong", you have a document-shaped control against a human-shaped fraud, and you now know it.
- Rank your lanes by cargo value. Strategic theft selects for value. Your top decile of loads by value is where any control belongs first, and it is usually a surprisingly short list.
- Test the callback. Take one recent booking and try to reach the carrier using a phone number you found independently, from FMCSA records, rather than one supplied in the booking thread. Count how long it takes. That gap is your exposure.
- Separate your fraud categories in reporting. If your loss data does not distinguish fictitious pickup from double brokering from physical theft, you cannot tell which control is working. Most reporting collapses all three.
- Ask your vetting vendor one specific question. Not whether they verify carriers, they do. Ask what their product establishes about the individual human who arrives at the dock on a given load. The answer is clarifying.
- Instrument the exception path. Count how often a load is released despite a failed or skipped check, and who authorized it. That number is the real strength of your current control.
- Talk to your cargo insurer about controls-based pricing. Ask what evidence of a release control would change your premium. Their answer tells you what they actually believe about this risk.
If you want to see what an offline verifiable delegation looks like in practice rather than in a diagram, the signing demo shows the payload, the signature and the verification, and the developer documentation covers delegation scope, expiry and revocation.
Frequently asked questions
How do you prevent fictitious pickup cargo theft? Require the carrier of record's signed delegation to the specific driver for the specific load, and verify it at the dock before releasing the freight. Documents such as MC numbers, insurance certificates and rate confirmations can all be copied or generated by an impostor. A signature from the dispatcher's enrolled device, bound to the load and the driver's key, cannot be produced by anyone who does not hold that device.
What is the difference between fictitious pickup and double brokering? A fictitious pickup is an impostor physically collecting freight using stolen or fabricated carrier credentials, and the load is gone at the moment of release. Double brokering is a party accepting a load and re-brokering it without authority, usually collecting the payment and disappearing while a legitimate carrier hauls the freight unpaid. The first is a theft at the dock, the second is a financial fraud upstream.
Does carrier vetting stop strategic cargo theft? Vetting reduces exposure to carriers that are themselves bad actors, and it is worth doing. It does not stop fictitious pickup, because vetting establishes facts about an entity while the fraud is committed by a human whose connection to that entity was never checked. A vetted, legitimate carrier's identity is exactly what gets stolen in these schemes.
How much is cargo theft costing in 2026? The FBI's Internet Crime Complaint Center reported in April 2026 that estimated cargo theft losses in the United States and Canada reached nearly $725 million in 2025, roughly 60 percent higher than 2024, with confirmed incidents up about 18 percent. Losses growing more than three times faster than incidents indicates a shift toward higher value, targeted theft.
Can a signed pickup check work without a data connection at the dock? Yes, and that is a deliberate design requirement. Verification is a signature check against the carrier's published key, which the dock software caches, so no call to any server is needed at the moment of release. Docks are frequently inside metal buildings with poor connectivity, and any control requiring live connectivity would be bypassed within days.
What happens if the driver's phone is dead? There must be a supervisor override, and the override must itself be signed and recorded rather than granted verbally, otherwise the exception path becomes the attack path. Measuring how often the override is used is one of the more informative metrics a facility can collect about its own controls.
Does this require every carrier in the country to enroll? No, and any rollout that assumes it will fail. The practical starting point is high-value lanes with a concentrated carrier base, where a shipper can make signed release a contract term. Broader adoption depends on distribution through transportation management systems and load boards, and on cargo insurers pricing the control.
Sources
- FBI Internet Crime Complaint Center, public service announcement on cyber-enabled strategic cargo theft, April 2026, reporting nearly $725 million in estimated 2025 losses, up about 60 percent, with incidents up about 18 percent. ic3.gov
- Federal Motor Carrier Safety Administration, carrier registration and operating authority records. fmcsa.dot.gov
- CargoNet, cargo theft incident reporting and analysis. cargonet.com
- Overhaul, quarterly cargo theft reporting, including 2026 analysis of deceptive pickup growth as summarised in freight trade coverage. overhaul.com
- Transportation Intermediaries Association, broker fraud guidance and framework materials. tianet.org
- DAT Freight and Analytics, load board identity and fraud prevention program materials. dat.com
- Truckstop, carrier identity verification program materials. truckstop.com
You cannot verify a human with a document about a company. The freight leaves the dock in the hands of a person, so that is where the proof has to be.