A load is late, the delivery address changed unexpectedly, or the carrier says it never booked the shipment. At that point, the broker’s job is not to solve the case from a chat thread. It is to protect people and freight, stop unverified changes, preserve the original record, and give the right responders a coherent packet.
The FBI’s April 30, 2026 public service announcement describes cyber-enabled cargo-theft schemes involving compromised broker or carrier accounts, fake load-board postings, manipulated documents, and rerouted freight. It recommends independent, multi-channel verification before releasing loads and thorough documentation of the parties, vehicles, identifiers, and communications. FMCSA’s fraud and identity-theft page separately directs suspected victims toward law enforcement and official reporting routes and warns that a carrier involved may also be a victim.
This guide turns that public guidance into an original 30-minute broker evidence-packet method. It is not a substitute for emergency services, law enforcement, an insurer, counsel, a shipper’s incident plan, or a cybersecurity professional. If people are in danger, hazardous materials are involved, or authorities give instructions, follow those instructions immediately rather than waiting for this checklist.
First, separate three jobs
Do not let one hurried person investigate, negotiate, alter records, and communicate externally at the same time. Assign three roles when staffing allows:
- Response owner: coordinates the clock and the approved contact list.
- Record custodian: preserves source material without silently editing it.
- Communications owner: sends only approved, factual updates to the shipper, carrier, insurer, load board, and authorities.
One person may cover more than one role in a small brokerage, but the responsibilities should remain separate on the incident log. Record who is acting, the current UTC or time-zone-qualified timestamp, and the next review time.
The 30-minute evidence-packet sequence
Minute 0–5: freeze unverified changes
Pause new destination, contact, payment, release, or pickup instructions until they are independently verified through known-good contact routes. Do not use a phone number, email address, or link supplied only in the suspicious message. Do not promise payment, recovery, immunity, or a particular law-enforcement result.
Preserve the load as it currently appears. Avoid replacing a carrier, overwriting an address, deleting a message, renaming a document, or “cleaning up” notes before the original state is captured. If a system must remain operational, record each necessary change as a new event with the actor, time, source, reason, and prior value.
Minute 5–10: establish the incident spine
Create one incident identifier that is different from the load number. At minimum, record:
- discovery date, time, time zone, and person;
- affected load, customer, broker, carrier, pickup, and delivery identifiers;
- last independently verified location and time;
- what is known, what is reported but unverified, and what is still unknown;
- immediate safety, cargo, credential, financial, or account concerns;
- response owner and next decision time.
Use careful language. “Driver reported a destination change at 14:08 UTC” is evidence. “The driver stole the load” is a conclusion that the brokerage may not be able to establish.
Minute 10–20: build the eight-part packet
Organize copies or stable references under these headings:
- Load identity: internal load number, customer reference, commodity description from the governing source, declared value source if one exists, pickup and delivery details, and appointment windows.
- Contracted parties: legal names, USDOT and MC numbers, authorized contacts, broker-carrier agreement reference, rate confirmation, and the source and time used to verify each identity.
- Driver and equipment: driver name, independently verified contact, tractor and trailer numbers, license plates, cab number, seal number, and photos or ID records only when lawfully collected and handled under policy.
- Timeline: original booking, dispatch, arrival, pickup, check calls, tracking events, instruction changes, missed milestones, last known location, and discovery.
- Documents: original and revised rate confirmations, bill of lading, pickup evidence, proof-of-delivery status, carrier packet, insurance evidence, and any changed destination or release document.
- Communications: original email files or stable exports when available, message threads, call logs, voicemail references, load-board messages, and the visible sender plus actual address or number.
- Account and payment signals: unexpected mailbox rules, password or user changes, changed remittance instructions, factoring notices, payment holds, and which system owns each fact. Do not place passwords, one-time codes, full bank details, or unrelated personal data in the packet.
- External actions: police report number, IC3 complaint reference, FMCSA/NCCDB ticket, insurer claim reference, load-board case, counsel contact, and the exact material sent to each recipient.
The packet should point to evidence, not manufacture it. Mark unavailable items “not available” and untested items “not verified.” A blank is ambiguous; an honest status is useful.
Evidence-handling rules that keep the packet useful
Keep originals read-only where the tool and policy allow. Work from copies, and record where the original lives. Preserve filenames, received timestamps, sender details, and document versions. If your security team uses hashes, legal holds, forensic images, or another custody process, follow that process; this guide does not invent one.
Limit access to people who need it. A cargo-theft packet can contain personal, commercial, security, and financial information. Create recipient-specific copies rather than sending the full internal file to every outside party. Maintain a disclosure log with recipient, reason, time, sender, and the files or fields released.
The packet passes this editorial test only when a second reviewer can answer five questions without searching private inboxes:
- Which load and parties are involved?
- What is verified, alleged, and unknown?
- What changed, when, and from which source?
- Where are the original records?
- Who has been contacted, and what is the next controlled action?
Route the incident through official channels
The FBI’s IC3 advisory says suspected victims of the described cyber-enabled cargo-theft schemes should file a local police report and an IC3 complaint, or contact a local FBI field office. FMCSA’s broker and carrier fraud page lists additional routes including the FMCSA Contact Center, the National Consumer Complaint Database, the DOT Office of Inspector General hotline, insurers, load boards, and factoring companies. The right route depends on the facts and on instructions from your shipper, insurer, counsel, and authorities.
Do not treat a report number as proof that the freight is recovered or the incident is resolved. Record the reference, owner, submission time, scope, and requested follow-up. Continue using independently sourced contact details.
Public facts, editorial method, and ServeOps boundary
The FBI and FMCSA statements above are attributed public guidance. The 30-minute sequence, three-role split, eight-part packet, five-question acceptance test, status labels, and disclosure log are original editorial controls—not federal requirements and not legal or cybersecurity advice.
This guide does not claim that ServeOps detects cargo theft or identity fraud; verifies carriers, drivers, locations, authority, insurance, or documents; monitors load boards, email, GPS, accounts, or payments; preserves forensic evidence; creates an incident packet; reports to any agency; controls access or retention; integrates with insurers or law enforcement; or prevents, investigates, or recovers a loss. Any relevant product behavior must be demonstrated with current product evidence and a synthetic, non-production test.
After the incident path is separately controlled, a brokerage may evaluate its operating TMS on a different track. The verified ServeOps offer language is unchanged: 60-day free trial; card collected upfront; no charge for 60 days; cancel anytime; then $49 per seat/month or $490 per seat/year. Card is required upfront. No charge during the trial. Confirm the complete checkout terms before signup.
Related Broker Guides
- Test carrier records without mistaking storage for verification
- Test whether critical load instructions survive a dispatcher handoff
- Verify a suspicious FMCSA message through an independent path
Confirm each related route is approved and live before inserting it in the CMS.
Sources
- FBI Internet Crime Complaint Center, Cyber-Enabled Strategic Cargo Theft Surging, published April 30, 2026; reviewed August 24, 2026.
- FMCSA, Broker and Carrier Fraud and Identity Theft, current page reviewed August 24, 2026.
- FMCSA, Eligible Complaints, current page reviewed August 24, 2026.
- FMCSA, Fraud Alerts, current page reviewed August 24, 2026.
- ServeOps registration, offer destination; complete terms require publication-day recheck.