{
 "slug": "freight-identity-lifecycle",
 "topic_id": "TOPIC-143",
 "cluster": "Freight, Cargo, Ports & Customs Identity",
 "tier": "Tier A",
 "title": "Proofed once at registration, stolen at the dock: the 2026 cargo theft arithmetic",
 "summary": "FMCSA began requiring photo ID and a live selfie for operating authority in January 2026 and retired MC numbers. In the same period cargo thefts fell 26% while losses more than doubled. Both facts are explained by the same thing.",
 "lede": "Two numbers from 2026 sit awkwardly together. Cargo theft incidents fell twenty-six percent year over year. Losses more than doubled, to $304.6 million in a single quarter. Fewer thefts, bigger losses — and the explanation is that the industry hardened the front door while the money walks out of the loading dock.",
 "date": "2026-02-23",
 "category": "Vertical",
 "author_id": "constance-ibe-whitmore",
 "tags": [
  "cargo theft",
  "strategic theft",
  "FMCSA",
  "carrier identity",
  "fictitious pickup",
  "freight fraud"
 ],
 "image_title": "Freight Identity Lifecycle",
 "schema": "Article",
 "key_takeaways": [
  "FMCSA identity proofing took effect in January 2026: government photo ID and a live facial selfie to obtain operating authority. It addresses registration, which is not where the losses occur.",
  "The FBI's IC3 reported 2025 cargo theft losses of approximately $725 million, a 60% increase, driven by cyber-enabled strategic theft.",
  "Across eleven lifecycle moments from registration to delivery, nine inherit identity rather than establish it. Three deserve a cryptographic re-proof."
 ],
 "body": [
  {
   "type": "h2",
   "text": "What changed in registration, and when"
  },
  {
   "type": "diagram",
   "kind": "chain",
   "alt": "Proofed once, stolen later",
   "caption": "Registration hardened. Nothing re-establishes identity at the moment freight changes hands.",
   "nodes": [
    {
     "label": "Operating authority granted",
     "sub": "photo ID, live selfie",
     "note": "hardened",
     "good": true
    },
    {
     "label": "Months pass",
     "sub": "identity not re-checked",
     "note": "gap",
     "bad": true
    },
    {
     "label": "Carrier identity assumed",
     "sub": "or account compromised",
     "note": "",
     "bad": true
    },
    {
     "label": "Load collected",
     "sub": "at the dock",
     "note": "no re-proofing",
     "bad": true
    }
   ]
  },
  {
   "type": "p",
   "html": "In January 2026 the Federal Motor Carrier Safety Administration implemented identity proofing for new carrier and broker applications, requiring a government-issued photo identification and a live facial selfie. MC numbers were retired in the same period, consolidating identification on the USDOT number. In May 2026 a modernised registration system launched, described by the Department as improving fraud detection and data quality."
  },
  {
   "type": "p",
   "html": "These are substantive changes and they were correctly motivated. Registration fraud — obtaining authority under a fabricated or stolen identity — was a real and growing problem, and the controls address it directly."
  },
  {
   "type": "h2",
   "text": "What the loss data did in the same period"
  },
  {
   "type": "p",
   "html": "The FBI's Internet Crime Complaint Center issued a public service announcement on 30 April 2026 on cyber-enabled strategic cargo theft, reporting that estimated 2025 losses in the United States and Canada reached approximately $725 million — roughly a 60% increase over 2024."
  },
  {
   "type": "p",
   "html": "Industry data through 2026 continued the pattern. Reported incidents in the second quarter fell about 26% year over year, while estimated losses in that quarter reached $304.6 million against $135.7 million a year earlier. Earlier in the year, more than 1,120 incidents with roughly $121 million in losses were recorded across the first five months."
  },
  {
   "type": "table",
   "caption": "The divergence. Incident counts and loss totals moving in opposite directions is the signature of a shift in method, not in volume.",
   "head": [
    "Metric",
    "Direction in 2026",
    "Implication"
   ],
   "rows": [
    [
     "Incident count",
     "Down ~26% year over year",
     "Fewer, more selective operations"
    ],
    [
     "Loss total",
     "More than doubled",
     "Higher value per incident"
    ],
    [
     "Implied value per incident",
     "Up sharply",
     "Targets are being selected, not encountered"
    ],
    [
     "Method",
     "Shift toward strategic and cyber-enabled theft",
     "Identity, not force"
    ]
   ]
  },
  {
   "type": "h2",
   "text": "Why hardening registration does not move those numbers"
  },
  {
   "type": "p",
   "html": "Strategic cargo theft does not begin with obtaining authority. It begins with impersonating authority that already exists — a legitimate carrier's USDOT number, a real insurance certificate, a plausible email domain, a dispatcher who answers the phone."
  },
  {
   "type": "p",
   "html": "Identity proofing at registration raises the cost of creating a new fraudulent carrier. It does nothing about presenting the credentials of an existing legitimate one, which is both cheaper and more effective because the attributes survive every downstream check."
  },
  {
   "type": "blockquote",
   "text": "A check performed once, years ago, against a person who is not the one standing at your dock, is not a check."
  },
  {
   "type": "h2",
   "text": "The Freight Identity Lifecycle Map"
  },
  {
   "type": "p",
   "html": "Eleven moments between registration and delivery. For each, whether identity is <em>established</em> (proven at that moment), <em>inherited</em> (carried forward from an earlier proof), or <em>asserted</em> (claimed with no verification)."
  },
  {
   "type": "table",
   "head": [
    "#",
    "Moment",
    "Identity state",
    "Loss concentration"
   ],
   "rows": [
    [
     "1",
     "Operating authority registration",
     "Established",
     "Low"
    ],
    [
     "2",
     "Load board posting and search",
     "Asserted",
     "Low"
    ],
    [
     "3",
     "Carrier onboarding by broker",
     "Inherited (attributes checked)",
     "Moderate"
    ],
    [
     "4",
     "Rate confirmation issued",
     "Asserted",
     "Moderate"
    ],
    [
     "5",
     "Re-tender to another carrier",
     "Asserted",
     "<strong style=\"font-weight:600\">High</strong>"
    ],
    [
     "6",
     "Driver assignment",
     "Asserted",
     "Moderate"
    ],
    [
     "7",
     "Arrival and gate check-in",
     "Asserted",
     "<strong style=\"font-weight:600\">High</strong>"
    ],
    [
     "8",
     "Dock release of freight",
     "Asserted",
     "<strong style=\"font-weight:600\">Highest</strong>"
    ],
    [
     "9",
     "In-transit status updates",
     "Asserted",
     "Low"
    ],
    [
     "10",
     "Delivery and proof of delivery",
     "Asserted",
     "Moderate"
    ],
    [
     "11",
     "Settlement and payment",
     "Inherited",
     "Moderate"
    ]
   ]
  },
  {
   "type": "p",
   "html": "Nine of eleven inherit or assert. The three carrying the highest loss concentration — re-tender, gate check-in and dock release — are all pure assertion, verified by document inspection."
  },
  {
   "type": "h2",
   "text": "The three moments worth a cryptographic re-proof"
  },
  {
   "type": "ol",
   "items": [
    "<strong style=\"font-weight:600\">Re-tender (moment 5).</strong> Express permitted co-brokerage as a delegation with an explicit depth limit, so an unauthorised re-tender is detectable rather than discoverable at claim time.",
    "<strong style=\"font-weight:600\">Gate check-in (moment 7).</strong> The driver presents a signed assertion under a load-bound delegation, not a rate confirmation PDF.",
    "<strong style=\"font-weight:600\">Dock release (moment 8).</strong> The shipper verifies the assertion offline against a published key before releasing freight."
   ]
  },
  {
   "type": "p",
   "html": "Each is a single point in an existing workflow. None requires a new system in the freight path, and all three verify without connectivity — which matters at a dock in an industrial park."
  },
  {
   "type": "h2",
   "text": "Reading the numbers carefully"
  },
  {
   "type": "p",
   "html": "Incident counts and loss totals differ between IC3, industry databases and insurer datasets because inclusion criteria differ — some count attempts, some count only confirmed thefts, some include in-transit pilferage. This article cites each source with its own figure rather than selecting the largest, and the per-incident implied value used above derives from the quarterly industry data cited, not from a national average."
  },
  {
   "type": "p",
   "html": "What none of the datasets disagrees about is the direction: value per incident is rising sharply, and the method producing that rise is identity-based."
  },
  {
   "type": "h2",
   "text": "What the two numbers together mean"
  },
  {
   "type": "p",
   "html": "A falling count with rising losses is the signature of a control that raised the cost of entry. Casual thieves were priced out; the ones who remain target fewer, larger loads and invest more per attempt. That is a real improvement in one dimension and a worsening in another, and reporting either number alone misleads."
  },
  {
   "type": "table",
   "caption": "Where the lifecycle has gates",
   "head": [
    "Stage",
    "Gate today"
   ],
   "rows": [
    [
     "Registration",
     "<strong style=\"font-weight:600\">Strong, since January 2026</strong>"
    ],
    [
     "Account access",
     "Password and sometimes MFA"
    ],
    [
     "Load acceptance",
     "None — a tender in a system"
    ],
    [
     "<strong style=\"font-weight:600\">Pickup</strong>",
     "<strong style=\"font-weight:600\">Paperwork</strong>"
    ]
   ]
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“So registration hardening failed.”</strong> It did not. It removed a class of attacker, which is what the falling count shows. It simply cannot reach the dock, which is where the remaining loss concentrates."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Identity re-proofing at every pickup is impractical.”</strong> It is. Re-proofing is not the same as re-authorising — a signature bound to this tender takes seconds and does not re-run identity verification."
  }
 ],
 "faq": [
  {
   "q": "Did FMCSA's changes make things worse?",
   "a": "No. They addressed registration fraud, which was a genuine problem. The point is that the losses concentrate elsewhere in the lifecycle, so improvement at registration was never going to move the loss numbers."
  },
  {
   "q": "Is this just fictitious pickup?",
   "a": "Fictitious pickup is the dominant technique at moment 8. Moments 5 and 7 involve related but distinct methods — unauthorised re-tender and driver impersonation — which is why they are separated."
  },
  {
   "q": "What does a dock actually do differently?",
   "a": "It stops evaluating documents and starts verifying a signature against a published key. The verification is offline and takes under a second."
  },
  {
   "q": "Does this require every carrier to adopt something?",
   "a": "For a given lane, it requires the broker and the shipper to agree and the carrier's driver to hold a credential. It works bilaterally before it works industry-wide."
  },
  {
   "q": "Why did losses rise while thefts fell?",
   "a": "Registration hardening priced out casual thieves. Those remaining target fewer, higher-value loads and invest more per attempt."
  },
  {
   "q": "Is re-proofing needed at every pickup?",
   "a": "No. Re-authorising is not re-proofing. A signature bound to this tender takes seconds and does not repeat identity verification."
  },
  {
   "q": "Where is the remaining gap?",
   "a": "Between load acceptance and pickup, where nothing re-establishes that the collector is the carrier that accepted."
  }
 ],
 "sources": [
  {
   "t": "FBI IC3 2025 Internet Crime Report",
   "u": "https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf"
  },
  {
   "t": "FMCSA registration and rulemaking",
   "u": "https://www.fmcsa.dot.gov/registration"
  },
  {
   "t": "CargoNet / FMCSA freight fraud resources",
   "u": "https://www.fmcsa.dot.gov/protect-your-move/fraud"
  }
 ],
 "related": [
  {
   "slug": "dock-release-gate",
   "title": "Fictitious pickup: designing a dock release gate",
   "category": "Vertical"
  },
  {
   "slug": "retender-authority-chain",
   "title": "Double brokering: making the re-tender signed",
   "category": "Vertical"
  },
  {
   "slug": "assignment-change-receipt",
   "title": "The rate confirmation that changed bank accounts",
   "category": "Vertical"
  }
 ],
 "image": "https://cdn.twc.sh/images/igcache/Freight%20Identity%20Lifecycle/1200_630/blog.jpg",
 "wordcount": 1090,
 "url": "/blog/freight-identity-lifecycle.html",
 "reading_time": "5 min read",
 "seo_title": "The 2026 cargo theft arithmetic and carrier identity",
 "meta_description": "FMCSA began requiring photo ID and a live selfie for operating authority in January 2026 and retired MC numbers.",
 "hub": {
  "slug": "topics/freight-identity",
  "title": "Freight, cargo and customs identity"
 },
 "answer": "Because the control moved to registration and the attack moved to the dock. FMCSA began requiring photo ID and a live selfie for operating authority in January 2026 and retired MC numbers. Fewer, better-targeted thefts of higher-value loads is what you get when you proof once and never again.",
 "answer_q": "Why did cargo thefts fall while losses more than doubled?",
 "glossary": [
  {
   "term": "Operating authority",
   "def": "The federal grant permitting a carrier to operate, now subject to photo ID and live selfie proofing."
  },
  {
   "term": "Double brokering",
   "def": "Re-tendering a load to another carrier without authority, which breaks the chain of custody and insurance."
  },
  {
   "term": "Strategic theft",
   "def": "Theft using assumed identity and documentation rather than force — the category that grew."
  }
 ],
 "checklist": {
  "title": "Closing the lifecycle gap",
  "id": "lifecycle",
  "desc": "Four steps.",
  "steps": [
   {
    "name": "Treat registration and pickup as separate gates.",
    "text": "They answer different questions."
   },
   {
    "name": "Bind the tender to a credential at acceptance.",
    "text": "When the carrier takes the load, not at the dock."
   },
   {
    "name": "Verify that binding at pickup.",
    "text": "Seconds, fail closed."
   },
   {
    "name": "Re-affirm carrier identity periodically.",
    "text": "Not per load — per quarter is enough to catch account takeover."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav binds the authorising person to the exact release, tender or instruction, and produces a receipt a shipper, a terminal or a broker can verify at the gate without a phone call.",
  "href": "../docs.html",
  "label": "See release receipts"
 }
}