{"id":16526,"date":"2026-07-29T10:06:22","date_gmt":"2026-07-29T10:06:22","guid":{"rendered":"https:\/\/newestek.com\/?p=16526"},"modified":"2026-07-29T10:06:22","modified_gmt":"2026-07-29T10:06:22","slug":"its-easier-to-steal-cargo-than-toothpaste","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16526","title":{"rendered":"It\u2019s easier to steal cargo than toothpaste"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Our cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it\u2019s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as \u201cOcean\u2019s Eleven\u201d or \u201cMission: Impossible\u201d. Real-world equivalent scenarios like these are happening in front of your eyes and you might not even know when it\u2019s happening. <a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260430\">Cyber-enabled cargo theft<\/a> is growing at a shocking pace.<\/p>\n<p class=\"wp-block-paragraph\">Most cybersecurity professionals do not spend much time focusing on transportation and logistics and it makes sense why. Traditionally, these industries were heavily manual in nature with little tech innovation or connected systems. However, that has changed drastically in the last few years. Autonomous vehicles, connected systems and devices, robotics \u2013 the list goes on, are just a few examples of how logistics and specifically freight logistics has changed in recent years to innovate to ultimately keep transportation costs low. While shiny tech companies are still the attack beacon on the hill, there has been something brewing in the shadows and the bad guys have been paying attention.<\/p>\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/www.trucknews.com\/transportation\/fbi-issues-public-warning-over-strategic-cargo-theft\/1003214303\/\">TruckNews.com<\/a>, \u201ccargo theft incidents are up more than 90% since 2021, with high-tech strategic cargo thefts soaring by 1,500%\u201d. That\u2019s not a typo. I lead the cybersecurity function for a company that specializes in vehicle logistics, and we also see reports of cyber-enabled vehicle thefts increase around 1,400% during transport. Again, that\u2019s not a typo. It has gotten so bad that the FBI has noticed it and is deploying dedicated resources to combat the increase.<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-did-we-get-here\">How did we get here?<\/h2>\n<p class=\"wp-block-paragraph\">Freight logistics is quite a fragmented industry. From the production line all the way to consumers or customers, there are generally multiple parties in the mix to get goods from point A to point B. At a high level, transportation of goods does not seem overly complex. Maybe it\u2019s a warehouse or the production facility; a truck shows up, loads the goods and transports them to the store. However, the reality is, complexity is quite high. \u00a0This includes inventory systems, brokers and their systems, bills of lading, payment systems, vehicle telematics and of course a ton of data and the goods themselves. Freight logistics, and logistics more broadly, have been heavily paper-based but had to innovate and move operations and their data online. However, controls, governance and security gates have traditionally been de-prioritized. Shipping goods is a cost center, and the goal is to keep costs low. Well, the bad guys have noticed.<\/p>\n<p class=\"wp-block-paragraph\">Think about it this way: I could try to walk into a store with mounted security cameras, security guards standing at the doors, locked shelves and try to steal whatever is behind that locked shelf and risk being caught \u2014 or I can exploit a transportation management system, divert an entire truckload and completely cover my tracks for a much bigger payday with arguably less immediate risk. Or even better, pin it on someone else. Just to prove how lucrative this scheme is, instead of breaking into a car to steal it, thieves went after a transporter to steal NBA legend <a href=\"https:\/\/www.cbsnews.com\/atlanta\/news\/shaquille-oneals-custom-range-rover-stolen-during-transport-from-georgia-to-louisiana-police-say\/\">Shaquille O\u2019Neal\u2019s Range Rover during transport<\/a>. It takes coordination and planning to get that done, and apparently a compromised transporter.<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-hackers-get-the-goods\">How hackers get the goods<\/h2>\n<p class=\"wp-block-paragraph\">Generally, just like with every compromise, attackers look for the easiest way in. However, certain patterns are emerging of how the perpetrators are accomplishing these heists, which include business email compromise (BEC), identity theft\/carrier impersonation, load board hacks and freight redirection and Electronic Bill of Lading (eBOL) tampering. As previously mentioned, there are many handoffs and parties involved in the logistics process. Each handoff, or trust boundary if you\u2019re thinking in terms of a threat model, carries risks and has potential vulnerabilities that a threat actor could exploit. What we also see is that carriers (transporters) have large, varying degrees of cybersecurity maturity, generally no requirements for standardization and often not sufficient resources to defend against increasingly complex cyberattacks.<\/p>\n<p class=\"wp-block-paragraph\">At this point, you might wonder if freight logistics is completely defenseless and the answer is \u201cno\u201d. Vehicle telematics and GPS tracking have been in place for a while, but they were often used to prevent traditional theft. Attackers know this and they have pivoted as well. One of the movie-worthy heists that made the news was the cyber-enabled cargo theft of <a href=\"https:\/\/www.cbsnews.com\/news\/how-thieves-stole-24000-bottles-of-guy-fieris-tequila-highway-heist-60-minutes-transcript\/\">24,000 bottles of Guy Fieri\u2019s tequila<\/a>. Not only did the bad guys infiltrate systems, but they also spoofed GPS tracking to make it look like the goods were en route to the correct destination when they weren\u2019t.<\/p>\n<p class=\"wp-block-paragraph\">Also, think about the planning and infrastructure these crime rings have invested in, and I am calling them crime rings because these are major operations with attacks often coming from overseas. In a \u201ctraditional\u201d compromise, you get in, get the data, cover your tracks and get out. In these examples, the attackers do that and need real infrastructure to move physical goods. It\u2019s one thing to infiltrate a system or spoof a carrier online, but it\u2019s a whole different story to operate actual trucks, clear goods through customs and ship them overseas \u2014 which is what they often do.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-industry-is-noticing-but-we-need-more-of-the-good-guys\">The industry is noticing, but we need more of the \u201cgood guys\u201d<\/h2>\n<p class=\"wp-block-paragraph\">Industry sharing forums and conferences around cyber-enabled cargo theft have started to emerge, but we still have a long way to go. Given the industry\u2019s fragmented systems, operators and entities, it can be challenging to perform incident response and forensics.\u00a0 We need cybersecurity professionals who understand logistics as well. There is phishing and then there is showing up with an actual truck with a forged USDOT number and a spoofed eBOL. The US Department of Transportation estimates that \u201cin 2023, the U.S. transportation system moved a daily average of about 55.5 million tons of freight valued at more than $51.2 billion\u201d \u2014 yup, daily. You can see what the potential for these attackers is, and they are currently only handicapped by their own capacity to move the loot. Maybe AI-enabled TSOCs (Transportation Security Operations Center), which combine the movement of the goods with cyber operations, are an avenue to explore. We ourselves are investing heavily in advanced detection and prevention mechanisms. While I am hopeful this industry will attract more talent, especially as thefts become more widely reported, finding talent can be challenging. A recent CSO article mentions that there is a \u201cgap between existing and needed skills\u201d to fill many of the cyber roles, but now we are also adding specific industry knowledge and while unicorns exist, there are no specific trainings or certifications geared toward cyber-enabled cargo theft to help close the knowledge gap. It is learning by doing (most of the time).<\/p>\n<p class=\"wp-block-paragraph\">It seems the perpetrators have an agenda, although clear patterns of strategic thefts vs. opportunistic ones have not emerged yet or been publicly disclosed. \u00a0According to recent reported thefts, they are targeting raw materials, data center equipment, high-value vehicles, and yes, even adult protection products. \u00a0I suspect we will also see them scaling their operations to divert more freight. So, is it easier to steal cargo than toothpaste? In a way, yes and no, but it is a perfect storm of a fragmented industry catching up, low levels of regulation, limited controls and detection capabilities and until now, a relatively low risk of punishment. The next time you see a car hauler or semi-truck on the road, there could be a chance you are watching a cyber-enabled cargo heist unfold in front of your eyes.<\/p>\n<p class=\"wp-block-paragraph\"><strong>This article is published as part of the Foundry Expert Contributor Network.<\/strong><br \/><a href=\"https:\/\/www.cio.com\/expert-contributor-network\/\"><strong>Want to join?<\/strong><\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Our cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it\u2019s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as \u201cOcean\u2019s Eleven\u201d or \u201cMission: Impossible\u201d. Real-world equivalent scenarios like these are happening in front of your eyes and you might not even know when it\u2019s happening. Cyber-enabled cargo theft is growing at a&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16526\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16526","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16526","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16526"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16526\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16526"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}