Cargo theft prevention is most effective before shipment details are widely released. Using FMCSA records, verified callback procedures, controlled pickup release, and stricter holiday-weekend rules can reduce exposure to strategic theft and impersonation schemes.

  • Estimated cargo theft losses in the U.S. and Canada reached nearly $725 million in 2025, according to Verisk CargoNet, with organized groups increasingly targeting higher-value shipments.
  • SAFER and FMCSA Licensing & Insurance checks are necessary for verifying authority, identity, and insurance status, but they do not confirm that the current dispatch contact or pickup request is genuine.
  • High-risk loads should use staged tendering, limited information release, known-good callback verification, and management approval for exceptions such as same-day onboarding or after-hours pickups.
  • Documentation of every verification step, including timestamps, screenshots, dispatch contacts, and pickup records, is critical for claims support and internal accountability.
  • Long holiday weekends and reduced-staffing periods warrant stricter controls because theft activity tends to rise when freight dwells longer and teams are rushed.

High-value freight is often most exposed before it ever leaves the dock. As cargo theft losses climbed and law enforcement warned of rising strategic theft and impersonation schemes, the most effective control point for many shipments is not in-transit tracking after dispatch, but the tender and pickup-authorization process that determines who sees the load, who is allowed to accept it, and what information gets released when. Recent FMCSA fraud guidance, FBI warnings, and 2025 theft data from Verisk CargoNet all point in the same direction: identity checks and release controls need to happen before pickup, not after a shipment disappears.

Why tender-stage discipline matters more now

Verisk CargoNet said estimated cargo theft losses in the U.S. and Canada reached nearly $725 million in 2025, up 60% from 2024, while confirmed cargo theft incidents rose 18% to 2,646. Average theft value rose to $273,990, reflecting a shift toward more selective, higher-value targeting by organized groups. Food and beverage thefts jumped 47%, metals thefts rose 77%, and enterprise computing hardware and cryptocurrency mining equipment emerged as top-tier targets. California remained the most impacted state, while New Jersey, Indiana, and Pennsylvania posted notable increases in activity. Those numbers matter because they show thieves are not just stealing more loads; they are targeting loads worth more and often using better intelligence to do it. Verisk CargoNet, Jan. 21, 2026.

The FBI now distinguishes between straight theft and strategic cargo theft, the latter involving deception used to trick a shipper, broker, or carrier into releasing freight to criminals. In an April 30, 2026 IC3 public service announcement, the bureau warned that cyber-enabled strategic cargo theft was surging, and in a June 8, 2026 FBI Philadelphia notice, the agency said criminal organizations were increasingly using account compromise, phishing, spoofed identities, and other tactics to target high-value shipments.

That is why compliance-level vetting is no longer enough. A carrier may look legitimate in a broad sense and still present theft risk if dispatch contacts, email domains, driver substitutions, pickup numbers, or facility instructions are released to an impersonator.

Which loads need enhanced tender protection

Not every shipment needs the same gatekeeping. Enhanced pre-pickup controls make the most sense for loads that combine one or more of these characteristics:

  • high invoice value or concentrated value in a single trailer
  • easy resale through gray or secondary markets
  • consumer-recognizable goods with liquid demand
  • repeat lane patterns that are easy to study
  • long dwell windows, weekend staging, or after-hours pickup
  • loads moving just ahead of major U.S. holiday closures

Current loss data supports prioritizing food and beverage, metals, electronics, vehicle accessories and parts, appliances, apparel, footwear, alcoholic beverages, power tools, and other goods with strong resale value. CargoNet’s holiday analyses also identified repeated targeting of tires, auto parts, motor oils, televisions and displays, computers and accessories, and major appliances during vulnerable closure periods. See CargoNet’s winter holiday 2025 advisory and July 4, 2025 advisory.

For industrial shippers, copper and other metals deserve special attention. Verisk CargoNet reported metals theft up 77% in 2025, driven largely by demand for copper products. That makes project cargo, electrical materials, fabricated metal products, and maintenance inventory more attractive than many teams may assume.

What FMCSA and SAFER can verify — and what they cannot

Public federal records remain a necessary first gate. FMCSA says its free SAFER Company Snapshot provides a concise record of a company’s identification, size, commodity information, safety record, roadside out-of-service inspection summary, crash information, and safety rating if one exists. FMCSA also says the Company Snapshot is a free service, while deeper Company Safety Profile information is not publicly available in the same way.

FMCSA’s current guidance also clarifies how SAFER displays authority status. Under the agency’s FAQ on operating authority status, an entity shown as AUTHORIZED FOR will list the specific operating authorities it may use; NOT AUTHORIZED means the entity does not have operating authority and-or is not authorized to engage in interstate for-hire operations; and OUT-OF-SERVICE means the carrier is under an out-of-service order and is not authorized to operate.

FMCSA’s separate public Licensing & Insurance carrier search can also be used to search by USDOT number, docket number, legal name, DBA name, or state, and the page notes that new applications may not appear for 24 hours after filing. FMCSA further notes that companies are required to keep registration details current and to complete biennial updates every two years, with current information viewable through the SAFER System’s Company Snapshot.

That makes SAFER and FMCSA L&I useful for checking:

  • legal business name and DBA name
  • USDOT and MC identifiers
  • whether authority appears active and for what type of operation
  • address and phone information on record
  • basic safety and out-of-service history
  • whether insurance filings appear in place

But those tools do not tell a shipper whether the person emailing today is truly the authorized dispatcher, whether a last-minute contact change is legitimate, whether a driver substitution is approved, or whether a pickup number has already been compromised. FMCSA itself warns that broker and carrier fraud can involve unauthorized use of another company’s USDOT number or an unregistered party acting as a broker. See FMCSA’s Broker and Carrier Fraud and Identity Theft alert.

Build anti-theft rules into the tender itself

The cleanest way to reduce exposure is to structure the tender so sensitive details are not released all at once.

1. Limit who receives the first tender invitation

For high-risk loads, do not send broad invitations with full shipment detail to a wide pool. Restrict invitations to approved carriers or tightly controlled broker partners, and use commodity- and lane-based eligibility rules. If a load requires specialized equipment or a narrow timing window, that should narrow the invitation list further, not widen it.

A practical approach is to separate the process into stages:

  1. initial interest request with general lane and equipment requirements
  2. carrier identity and authority verification
  3. award confirmation
  4. controlled release of exact pickup address, pickup number, and appointment specifics

That sequencing matters because once exact location and timing details are distributed, the exposure has already increased.

2. Treat contact-path verification as a control, not an administrative step

For high-value freight, the awarded party should be verified through a known-good callback path before any exact pickup instructions are sent. That means using phone numbers and contact information independently sourced from prior onboarding files, FMCSA records, or previously validated company contacts, not just the number in the latest email signature.

This is especially important when any of the following appear:

  • sudden changes in dispatch contact
  • a new email domain or misspelled domain
  • a request to move the conversation off established channels
  • urgent pressure to release pickup numbers immediately
  • last-minute equipment or driver substitutions
  • newly supplied certificates or documents that do not align with known records

NMFTA’s Freight Fraud Prevention Hub now includes a carrier vetting verification workflow and cargo theft prevention checklist focused specifically on closing verification gaps before freight is released.

3. No same-day onboarding for high-risk loads without management approval

Holiday windows, Friday afternoon tenders, and after-hours pickups are exactly when rushed onboarding creates openings. A defensible operating rule is simple: no new carrier setup and no same-day onboarding for high-value or commonly targeted freight unless a designated manager signs off after documented verification.

That rule may feel restrictive, but it directly addresses the conditions cargo thieves exploit: thin staffing, compressed handoffs, and casual exceptions.

Pickup authorization should be controlled like access to inventory

The award is not the final checkpoint. The pickup release process should require a second layer of validation.

Match the pickup party to the party that won the load

Before releasing freight, teams should confirm that the carrier showing up matches the entity that was verified and awarded the shipment. At minimum, that means matching:

  • legal carrier name
  • MC and USDOT identifiers
  • tractor and trailer numbers, if provided in advance
  • driver name and mobile contact, if policy permits collection
  • dispatch contact name and phone number
  • SCAC or internal carrier code, where used

If a different carrier appears at pickup, that should trigger escalation, not improvisation. Unapproved substitutions and rebrokering are exactly the type of breaks in chain-of-custody that create fraud openings.

Control the release of exact instructions and pickup numbers

Pickup numbers, appointment references, dock instructions, gate codes, and exact facility locations should be treated as controlled information. Release them only after award confirmation and identity verification, and only to the validated contact path. If details change after award, require a second documented approval.

This is particularly important for sites with multiple entrances, remote yards, drop trailers, or low-visibility staging areas where a convincing impersonator can look operationally plausible.

Tighten after-hours and pre-holiday pickups

CargoNet’s holiday analyses repeatedly tie elevated risk to extended closures, reduced staffing, and increased dwell time. In its December 19, 2025 year-end advisory, the company said reported events in the Dec. 23 to Jan. 2 holiday window rose from 49 in 2020 to 89 in 2024, an increase of about 82%. In its June 30, 2025 July 4 advisory, it said the days immediately around the holiday represented one of the highest-risk windows and that daily theft reports had climbed from four per day in 2013-2022 to 11 per day in 2025 during the measured period.

Operationally, that supports a stricter holiday-weekend playbook:

  • cutoff time for onboarding new carriers before a holiday weekend
  • management approval for Friday afternoon or after-hours pickups on high-risk loads
  • mandatory callback verification using known numbers
  • no release of pickup numbers until the approved dispatch contact is reconfirmed
  • extra review of any contact, bank, or dispatch changes within 24 hours of pickup
  • no unattended dwell if a shipment can move before closure instead

Documentation is part of the control, not a post-loss chore

A theft-prevention process is only as strong as the record it leaves behind. If a shipment is diverted or stolen, the difference between “we checked them” and a provable verification file can determine internal accountability, insurance handling, and recovery support.

For high-value shipments, the tender and pickup record should preserve:

  • who approved the tender and when
  • which records were checked in SAFER and FMCSA L&I
  • screenshots or saved PDFs of authority and insurance checks
  • timestamps for callbacks and the phone numbers used
  • email addresses and domains used during tendering
  • any discrepancies found and how they were resolved
  • names of dispatch contacts and approving supervisors
  • tractor and trailer identifiers communicated before pickup
  • driver ID and signature records where company policy and local law allow
  • seal numbers and who applied or verified them
  • surveillance retention instructions for pickup footage
  • any post-award change in pickup instruction, contact path, or equipment

This recordkeeping discipline also matters because FMCSA data can change over time as companies update registrations, addresses, or other details. The contemporaneous record is what will matter later.

Compliance checks are necessary, but theft-prevention checks are different

One of the most common operating mistakes is assuming that a legitimate carrier identity on paper answers the fraud question. It does not.

A compliance check asks whether a carrier exists, has relevant authority, and appears active in public records. A theft-prevention check asks whether the person receiving this load release is the right person, through the right channel, under the same identity that was vetted.

That distinction is increasingly important as cargo theft evolves. TT Club and BSI said in their 2025 Cargo Theft Report release that criminal networks are adapting faster, targeting road, rail, warehouse, and digital channels, and exploiting subcontracting and other supply chain vulnerabilities. The report highlighted food and beverage, electronics, automotive parts, construction materials, and metals among the most targeted categories globally.

In practice, that means public database verification should be the beginning of the process, not the end of it.

A practical pre-pickup checklist

For high-value or commonly targeted loads, a workable pre-exposure checklist looks like this:

Before tender release

  • classify the shipment by theft attractiveness and value concentration
  • determine whether enhanced controls are required
  • limit tender visibility to approved parties
  • remove exact pickup details from the initial tender if risk justifies it

Before load award

  • verify legal name, DBA, MC, and USDOT identifiers
  • confirm authority status in SAFER
  • check insurance filings in FMCSA L&I
  • confirm address and phone consistency across records
  • review whether the carrier is newly onboarded or outside normal lane history
  • escalate any mismatch in names, contact details, or operating profile

Before pickup details are released

  • call a known-good contact, not just the latest inbound number
  • validate email domain and dispatch identity
  • document who authorized release of pickup information
  • prohibit unapproved substitutions or rebrokering for the shipment class

At pickup

  • match the arriving party to the awarded entity
  • verify tractor, trailer, and driver details against dispatch information
  • record seal number, timestamp, and pickup signature
  • preserve surveillance and gate records
  • escalate any mismatch before freight is loaded

The tradeoff is real, but the economics are one-sided

Extra verification adds friction. It can slow award, reduce after-hours flexibility, and require management intervention on loads that might otherwise move routinely. But the economics are still clear. When the average theft value is approaching $274,000 and total annual losses are measured in the hundreds of millions, the cost of one more callback, one tighter release rule, or one delayed pickup-number email is typically far lower than the cost of a stolen shipment, a plant outage, a missed project milestone, emergency replacement freight, or a disputed claim file.

For CAP Logistics readers managing high-value industrial freight, the practical takeaway is straightforward: the strongest anti-theft controls usually sit upstream of pickup. Tight tender visibility, disciplined identity verification, controlled release of shipment details, and documented pickup authorization can reduce exposure before a load becomes a recovery problem.

Tracked surfaces

FAQ

What can a shipper verify in SAFER before awarding a load?

SAFER's Company Snapshot can help verify a carrier's identification details, size, commodity information, safety record, out-of-service summary, crash information, and safety rating if one exists. It can also display operating authority status, such as Authorized, Not Authorized, or Out-of-Service. That is useful for screening, but it does not prove the current dispatch contact or pickup request is authentic.

Why are holiday weekends higher risk for cargo theft?

Extended closures, reduced staffing, and longer freight dwell times create more opportunities for theft and fraud. Verisk CargoNet's holiday analyses found elevated activity around year-end and July 4 periods, with incidents clustering immediately before and after holiday closures.

What is the difference between a compliance check and a theft-prevention check?

A compliance check confirms that a carrier exists and appears properly registered or authorized. A theft-prevention check goes further by confirming that the person receiving pickup details is the same verified party, using trusted contact paths and controlled release of shipment information.

Should exact pickup details be included in the first tender?

Not always. For high-value or commonly targeted freight, it is often safer to delay release of the exact pickup address, pickup number, and detailed facility instructions until the awarded party has been verified through authoritative records and a known-good callback process.