Carrier-identity provider Highway published its Q2 2026 Freight Fraud Index on July 28. Its central finding: communication-based attacks — compromised inboxes, spoofed email, account takeover and impersonation calls — reached 50% of all classified fraud vectors in Q2, up from 42.7% in Q1. Read that figure knowing who produced it: Highway sells carrier-identity and fraud-prevention software, the data is its own unaudited network telemetry, and it is measuring a problem it also sells the fix for. We are using the ratio and the direction, and not the absolute counts, for exactly that reason.
What Changed?
Communication-based attacks moved from 42.7% of classified fraud vectors in Q1 to 50% in Q2 — from under half to half.
The finding underneath it is more useful than the headline: ownership-change fraud rose to 25.6% of reported thefts from 23.0%, while ownership-discrepancy alerts fell 40.9%. The loss category grew while the control that is supposed to catch it went quiet.
Highway also reports blocking 784,201 fraudulent inbound emails and intercepting 109,995 spoofed or fraudulent calls in the quarter, and says impersonation of its own brand rose 282% quarter over quarter. Those are counts of Highway’s own blocking activity across its own customer base. They rise when Highway signs customers as well as when attackers get busier, and they are not an industry measurement. We are reporting that they exist, not what they prove.
Highway shipped a control it calls Ownership Attestation during the quarter — relevant context for reading the alert numbers, and another reason to treat this as a vendor document.
Why It Matters
There is a coherent explanation for the shift, and it is regulatory. FMCSA’s Motus registration transition went live May 14, 2026, IDEMIA identity verification raised the cost of establishing a new carrier identity, and 15 ELD providers were decertified in Q2.
When creating a fake carrier gets expensive, the attack moves to taking over a real one. That is the thesis this quarter’s data supports: as identity creation got harder, fraud migrated to identity takeover.
It reframes what protects you. Registration screening was the control that mattered when the threat was fake carriers. It is not the control that matters when the threat is a real, verified, screened carrier whose email account someone else is reading.
The divergence is the tell. A detection control getting quieter while the loss category it governs grows is a detection-gap problem, not a fraud-volume problem — and detection gaps are where losses accumulate silently.
Who Is Affected
- Freight brokers and 3PLs, whose inboxes are the attack surface.
- Motor carriers and owner-operators, whose identities are the thing being taken over.
- Shippers and cargo insurers absorbing the loss.
- Carrier-vetting vendors generally — Highway, Descartes MyCarrierPortal, Truckstop RMIS, DAT, Bluewire — all of whom now have a shared problem to answer for.
What To Watch
- Whether the ownership-alert decline reverses in Q3. If it does not, the detection gap is structural rather than a reporting artifact.
- Whether any independent dataset corroborates the direction. Bluewire publishes a carrier score built on 652,000+ evaluations across 47 consecutive monthly releases and is the obvious cross-check.
- Verisk CargoNet’s quarterly theft data, which has flagged an underreported mechanism: compromise of software-based business phone systems, letting a remote actor place calls from a carrier’s own verified numbers.
Action To Consider
- Treat any mid-transaction change to payment, remit-to, ownership or contact details as hostile until you have verified it out of band. Not by replying to the message. Not by calling the number in the message.
- Call back on a number you already had on file from before the transaction started. Spoofed caller ID and compromised phone systems mean the number showing on your screen is not evidence of anything.
- Turn on email authentication (SPF, DKIM, DMARC) on your own domain, and multi-factor authentication on every mailbox that touches load tendering or payment. Account takeover is the vector; the mailbox is the door.
- If you are a small carrier or owner-operator: your MC/DOT identity is now the asset being stolen, not just your load. Check periodically that your registration contact and payment details still say what you think they say.
Plain English
Freight thieves used to invent fake trucking companies. That got harder, because the government tightened up how you register one.
So they switched. Now they break into the email of a real, legitimate trucking company or broker and steal loads using that company’s good name. Half of all the fraud counted last quarter worked this way.
The company that published these numbers sells software that blocks this kind of attack. That does not make the numbers wrong. It does mean you should read them as a vendor’s view of its own network, not as a measurement of the whole industry.
Meaning For People Moving Freight
This is the one story in this issue with something to do on Monday, and it costs nothing.
The single highest-value habit: when anything about money or ownership changes mid-deal, hang up and call back on a number you had before the deal started. That one habit defeats most of what this report describes.
For an owner-operator, the uncomfortable part is that your clean, verified, screened authority is now the thing worth stealing. The system that made it hard for criminals to be fake carriers made it valuable for them to be you.
What Remains Uncertain
- Every figure is Highway’s own network telemetry, unaudited, measuring its own blocking activity. Highway sells the product that mitigates the problem it measures. Its counts scale with its own customer growth.
- The 282% brand-impersonation figure is self-referential — it measures impersonation of Highway.
- Independent directional corroboration exists in the FBI IC3 public service announcement of April 30, 2026 (approximately $725 million in cyber-enabled cargo theft in 2025, up about 60% year over year), but that PSA falls outside this issue’s research window and is cited here as context only, not as an event of this week.
- Fraud tradecraft is not by itself an artificial-intelligence story. It qualifies here as an AI-enabled threat — synthetic communications and impersonation at scale — not as a report about an AI product.
Sources
- GlobeNewswire — Q2 2026 Freight Fraud Index: Half of All Incidents Now Tied to Communication-Based Attacks
https://www.globenewswire.com/news-release/2026/07/28/3334396/0/en/Q2-2026-Freight-Fraud-Index-Half-of-All-Incidents-Now-Tied-to-Communication-Based-Attacks.html - Highway — Q2 2026 Freight Fraud Index (vendor report)
https://highway.com/reports/q2-2026-freight-fraud-index - FMCSA Motus registration modernization and IDEMIA identity verification (regulatory context, cross-checked)