
For most of my career in freight, cargo theft meant something physical. A hijacked truck. A broken seal. A trailer gone from the yard overnight.
That version of the problem hasn't gone away. But it's not where the real money is being lost anymore.
The freight theft quietly draining this industry today doesn't involve a truck stop, a weapon, or even a physical location. It starts with an email. I call it the $0 Hack, because it costs the attacker almost nothing to pull off. No equipment. No fuel. No physical risk. Just access to the right inbox at the right time.
Here's how it actually plays out.
Someone gets into a legitimate email account, usually through phishing or a credential they bought off a forum. Once they're in, they don't do anything right away. That's the part most people get wrong about these attacks. The attacker isn't smash-and-grab. They sit. They read. They learn how your team books loads, how rate cons get sent, how payment info gets exchanged, who talks to whom and how often.
By the time they make a move, they understand your workflow better than your last three new hires combined.
Then they step into a thread that's already in motion. They reply from the real account. Update a pickup detail. Change a remit-to. Send a "quick correction" on banking info. Nothing looks off because nothing actually is off, technically. The email is real. The sender is real. The history is real.
Then the wrong carrier shows up. Or the payment lands in the wrong account. Or the load just walks away.
Why this hits freight so hard isn't complicated. Our industry runs on three things: speed, volume, and trust. And the connective tissue for all of it is email. Loads are booked over email. Instructions move over email. Payment changes get confirmed over email. Attackers figured out years ago that if you control the inbox, you control the transaction.
The frustrating part is that most companies are still defending against the wrong problem. Firewalls, antivirus, endpoint protection — all of it has its place, and none of it stops this. Because this isn't a system breach. It's an identity and communication attack. Once the attacker is operating from a trusted account, your security stack sees them as a regular employee doing regular work.
The honest question isn't whether the $0 Hack is real. It is, and it's happening to brokers, 3PLs, and carriers every week. The question is whether your operation would catch it before the loss, or after.
If you're not sure, I built something for that.
The Freight Cyber Risk Scorecard is a free assessment I put together specifically for freight operations. It walks you through the gaps attackers are actually using right now — email, identity, payment verification, vendor workflow — and gives you a score plus the specific exposures to close first. Takes about 5 minutes. No sales call attached.
Link in the comments.
If someone got into your email today, how much of your operation could they run before anyone noticed?

