Quick answer: Cargo theft prevention in 2026 means defending against fraud, not force. Incidents are falling while losses per theft have roughly doubled, because criminals are making fewer attempts against far more valuable targets. Effective programs map each control to the specific threat it stops and name who owns it.

Controls fail most often because nobody was assigned. The broadest-coverage controls sit upstream of the truck.
Cargo theft prevention is the set of controls that reduce the probability of freight being stolen and the size of the loss when it happens. It covers physical security, carrier and identity verification, communication discipline, facility design, and post-incident response. What separates a working program from a checklist is that each control is tied to a specific threat and assigned to a specific party.
Most published guidance on this topic is running a story that stopped being true. This playbook starts with what the 2026 data actually shows, because the wrong threat model produces the wrong controls.
What changed in 2026
The dominant narrative in cargo security is that theft is exploding. Through 2023 and 2024 that was accurate. It is no longer what the numbers say.
Verisk CargoNet recorded 677 cargo theft incidents in the second quarter of 2026, down 26% year over year. Over the same quarter, losses reached $304.6 million against $135.7 million a year earlier, with average loss per theft at $564,009 (Verisk CargoNet, August 2026). Across the first half of 2026 the same source reported losses above $359 million with an average stolen commodity value near $341,518.
Set that against the 2025 baseline of an estimated $725 million in losses on 2,646 confirmed incidents, averaging $273,990 per theft (Verisk CargoNet, January 2026). The average loss roughly doubled in eighteen months while incident counts fell.
The method changed alongside the numbers. In the second quarter of 2026, straight theft, meaning cargo taken by force or stealth from a parked trailer, fell from 488 incidents to 378. Fictitious pickups moved only from 165 to 158. Force is declining; fraud is holding. BSI attributed 17% of US cargo theft incidents in 2025 to fictitious pickups, against roughly 5% for strategic theft globally, which makes the United States a clear outlier (BSI, April 2026).
Three consequences for how a prevention program should be built:
- Locks are necessary and no longer sufficient. A control set weighted toward physical hardware is defending against the shrinking half of the problem.
- The highest-value control is verification, not deterrence. Most 2026 losses are complete on paper before a truck reaches a gate.
- Severity planning matters more than frequency planning. Fewer, larger events change the arithmetic on excess insurance and on which loads deserve exception handling.
The threats you are actually defending against
Six distinct attacks account for most current loss. They require different controls, which is why an undifferentiated list of best practices underperforms.
- Straight theft. Cargo taken from an unattended trailer or yard. Still the largest single category by count, and the one physical security addresses.
- Fictitious pickup. An impostor presents as the assigned carrier and is handed the freight voluntarily. Covered in depth in our guide to gate verification and fictitious pickups.
- Carrier identity theft. Criminals use a real carrier's credentials, including modified registration records and insurance certificates, to win legitimate loads.
- Undisclosed re-tendering. A load is passed to an unvetted party, breaking both custody and the liability chain. See what double brokering does to your liability chain.
- Cyber-enabled compromise. Credential phishing and business email compromise against broker and carrier accounts, which is the entry point for most of the above.
- Ownership-change fraud. Rather than registering new entities, criminals acquire dormant motor carrier businesses with clean safety histories. Highway's Freight Fraud Index found this in 25.6% of reported thefts in the second quarter of 2026, up from 23.0% in the first.
The FBI's Internet Crime Complaint Center documented how these chain together in an April 2026 public service announcement (FBI IC3, alert I-043026-PSA): phish credentials, post fraudulent loads under stolen identities to harvest carrier data, bid on legitimate shipments while impersonating clean carriers, then reroute freight through a cross-dock. A single compromise produces multiple losses.
The control matrix
Published prevention advice almost universally does two things wrong. It lists controls without saying which attack each one stops, and it addresses an undifferentiated "you" without saying who is responsible. The result is a program where everyone assumes someone else owns the control.
The matrix below fixes both. Read down the owner column to build a responsibility assignment; read across a threat row to see whether you have coverage.
Control | Threats it stops | Owner |
|---|---|---|
Operating authority and authority-type verification before booking | Identity theft, undisclosed re-tendering, ownership-change fraud | Shipper or broker |
Continuous carrier monitoring after onboarding, not one-time vetting | Identity theft, ownership-change fraud | Broker or shipper |
Driver screening at onboarding plus ongoing motor vehicle record monitoring | Internal theft, driver-facilitated loss | Carrier |
Outbound-only confirmation using independently sourced contact details | Fictitious pickup, identity theft, cyber-enabled compromise | Shipper |
Pre-issued pickup authorization codes tied to a named driver | Fictitious pickup | Shipper and facility |
Physical CDL inspection and equipment number match at the gate | Fictitious pickup | Facility |
Stop condition on same-day carrier substitution | Fictitious pickup, undisclosed re-tendering | Shipper and facility |
Photographic record of driver, licence, tractor, trailer, door markings | All theft types, and claim substantiation | Facility |
Written no-re-tender terms in the carrier agreement | Undisclosed re-tendering | Shipper or broker |
Rate confirmation matched against bill of lading at pickup | Undisclosed re-tendering, identity theft | Facility |
High-security rear door locks, kingpin locks, air cuff locks, ISO 17712 seals | Straight theft, pilferage | Carrier |
No-stop window for the first leg after pickup | Straight theft, targeted following | Carrier |
Secured fenced staging rather than open lots between legs | Straight theft | Facility or carrier |
Perimeter control, lighting, camera coverage at the release point | Straight theft, fictitious pickup | Facility |
Walk-around inspection and seal check after every stop | Pilferage | Carrier |
Credential hygiene, enforced password rotation, phishing training | Cyber-enabled compromise | Shipper, broker and carrier |
Restricted circulation of insurance certificates and load details | Identity theft, cyber-enabled compromise | Broker and shipper |
Documented chain of custody at every transfer | All types, and claim recovery | All parties |
Two patterns are worth reading out of that table. First, the controls with the broadest threat coverage are procedural rather than physical. Second, the majority of high-coverage controls sit with the shipper and broker, not the carrier, which is the inverse of how prevention advice is usually addressed.
Controls by owner
If you take one thing operationally from this playbook, make it an explicit assignment of the controls below. Unassigned controls are the ones that fail.
Shipper
Owns counterparty verification and the release decision. Verify authority and authority type before booking. Capture expected driver and equipment details in advance through a channel you initiated. Issue pickup authorization codes. Put no-re-tender terms in writing. Decide which loads get exception handling based on value, not volume.
Broker
Owns carrier selection and ongoing monitoring. Verify at onboarding and re-verify continuously, since authority, insurance, and ownership all change between loads. Control who receives insurance certificates and load details. Maintain the written record that 49 CFR ยง 371.3 requires.
Carrier
Owns the freight in motion. Driver screening and ongoing record monitoring, securement hardware, stop discipline, seal integrity, and the no-stop window on the first leg. See DOT compliance for automotive carriers for what a carrier's record does and does not establish.
Facility and yard
Owns the release point, which is where fictitious pickups succeed or fail. Gate procedure, identity inspection, equipment matching, photographic records, perimeter control, and secured staging. See yard and compound management and secure vehicle storage.
Where and when exposure concentrates
Controls are easier to justify and easier to staff when they are pointed at the right moments. Three patterns hold consistently in the current data.

Labor Day period cargo theft events, 2021 to 2025. Friday is the peak day.
The first leg after pickup
Freight is most exposed in the hours immediately after it is loaded, before it has cleared the area where it was observed being loaded. This is the reasoning behind the widely used practice of running a no-stop window on the first leg, commonly set at 200 miles. It is a scheduling and dispatch decision rather than a security purchase, which makes it one of the cheapest controls available.
Stationary periods, especially weekends and holidays
Verisk CargoNet's analysis of Labor Day periods from 2021 through 2025 recorded 273 theft events across the five years, with annual incidents rising from 33 in 2021 to 56 in 2025 and a five-year high of 70 in 2024. California, Texas and Illinois accounted for roughly half of the total, and Friday was the peak day at 55 incidents (Verisk CargoNet, September 2026). Any load that will sit unattended across a long weekend deserves a different plan than the same load moving midweek.
Geographic concentration, with a source caveat
California leads every dataset. Verisk CargoNet recorded 1,218 incidents in California across 2025, the highest of any state, with New Jersey up 50%, Indiana up 30% and Pennsylvania up 24%. Overhaul's US-only Q2 2026 distribution puts California at 34%, Texas at 18%, Tennessee at 13%, Pennsylvania at 10% and Illinois at 8%. Note that Tennessee does not appear in CargoNet's top tier at all, which is a useful reminder that state rankings are sensitive to which dataset you use. Plan around your own lane history rather than a national ranking.
What to put in the carrier agreement
Several of the highest-coverage controls in the matrix only work if they are contractual. Verbal expectations do not survive a dispute, and they give you nothing to enforce against.
- An explicit prohibition on re-tendering without written consent, with the consequence stated. This is the single most useful clause for protecting the liability chain.
- A requirement to disclose the actual driver and equipment before arrival, and to obtain approval for any substitution.
- Stated minimum cargo coverage and a requirement to notify you if it lapses or changes. Coverage that was valid at onboarding is not necessarily valid at pickup.
- Stop, parking and routing conditions for loads above a defined value, with the value threshold written in rather than left to judgment.
- A condition reporting standard at every custody transfer, specifying format and timing rather than just requiring "documentation."
- A notification window for any incident, deviation or delay, expressed in hours. Most disputes about response time are really disputes about when the clock started.
- Authority to audit compliance, without which every clause above is unverifiable.
What prevention costs against what a loss costs
Nobody in this category prices the tradeoff, which leaves the spending decision to intuition. The available data supports a straightforward argument.

Direct industry cost and the indirect multiplier. ATRI analysed 2023 incident data, so read it as cost structure rather than current volume.
The American Transportation Research Institute put direct industry cost at more than $18 million per day, roughly $6.6 billion annualized, with average annual losses above $521,000 per motor carrier and above $1.84 million per logistics service provider. The finding that matters most for budgeting is this one: indirect expenses can reach three to six times the value of the stolen cargo (ATRI, October 2025). Note that ATRI's report analyses 2023 incident data, so treat it as a cost-structure finding rather than a current-volume one.
Apply the multiplier to current severity. At a $564,009 average loss, indirect costs of three to six times imply total exposure between roughly $1.7 million and $3.4 million per event, covering replacement, expedited re-shipment, customer remediation, investigation time, administrative burden, and premium consequences.
Against that, the controls carrying the widest threat coverage in the matrix above are procedural. Verifying authority before booking, sourcing contact details independently, issuing authorization codes, and matching equipment at the gate cost staff time and process discipline rather than capital. The expensive controls, meaning dedicated secured facilities and specialized equipment, are worth targeting at the loads whose value justifies them, which is the argument for value-tiering your freight. See how high-value freight is tiered.
The honest caveat: no published dataset isolates loss reduction attributable to individual controls, so anyone quoting a percentage reduction from a specific device is guessing. Build the case on exposure and control coverage rather than on invented efficacy figures.
The first 60 minutes
Recovery odds fall sharply with time, and almost no published prevention guidance includes a response protocol. Work this in order.
- Minutes 0 to 10. Confirm the loss is real. Call the consignee and the carrier of record using verified numbers. Rule out an appointment or paperwork error before escalating.
- Minutes 10 to 20. Report to law enforcement and get a report number. Report to the agency with jurisdiction where the freight was released, which is not necessarily where it was going. Nothing downstream proceeds without that number.
- Minutes 20 to 30. File with a cargo theft recovery network. This circulates load details, equipment descriptions, and commodity information to law enforcement and member companies while the freight is still moving. For vehicles, report VINs to the National Insurance Crime Bureau so units are flagged at titling and export.
- Minutes 30 to 40. Notify your insurer and broker in writing. Most policies carry prompt-notice conditions, and delay itself becomes a coverage argument. Email creates the timestamp.
- Minutes 40 to 50. Preserve evidence before it expires. Gate photographs, the signed bill of lading, the rate confirmation, all email and phone records with the party claiming to be the carrier, and gate or yard camera footage. Camera retention windows are frequently short; export the footage rather than relying on the system to hold it.
- Minutes 50 to 60. Contain the wider exposure. Notify the legitimate carrier whose identity was used, since they are also a victim and may have other loads at risk. Freeze related tenders booked through the same channel. Reset credentials if compromise is suspected.
Two things to know about the claim clock. The Carmack Amendment sets minimum periods of at least nine months to file a claim against a carrier and two years to bring suit after a formal denial. Your policy's notice condition is usually far shorter than either. The binding deadline is almost always the insurer's, not the statute's.
Where a vehicle is later recovered damaged or non-running, moving it is its own problem. See damage recovery logistics and, for the documentation that determines whether the claim is paid or argued, insurance-grade condition reporting.
The regulatory layer
Two 2026 federal developments strengthen prevention, and one widely repeated claim is wrong.
The Broker and Freight Forwarder Financial Responsibility Rule took effect January 16, 2026. Brokers must maintain $75,000 in security, trust assets are restricted to cash, irrevocable letters of credit, and Treasury bonds liquidable within seven calendar days, and FMCSA may suspend authority within seven business days of notice if security is not restored. This makes financial security status a more meaningful vetting signal than it used to be.
FMCSA's Motus registration system adds mandatory identity verification for new applicants and for existing registrants on first access (Federal Register, April 2026). Phase I released in December 2025 to supporting companies, with broader availability planned for the second quarter of 2026. The agency cites a significant increase in presumed fraudulent activity using erroneous registrant information to commit cargo and monetary theft. Verification at the registration layer is the most direct structural answer to impersonation attempted so far.
No federal freight fraud legislation has passed. S. 337 sits on the Senate calendar without a floor vote, the SAFER Transport Act bills remain in committee, and broker transparency is still a proposal. Treat vendor claims that any of these are now law as incorrect.
Where prevention programs usually fail
Four failure patterns account for most of the gap between a documented program and an effective one.
- Verification that runs once. Onboarding checks test whether a carrier was legitimate when you signed them. Authority lapses, insurance cancels, and ownership changes between loads, which is the entire premise of ownership-change fraud. A control that does not repeat is a control that expires.
- Controls assigned to nobody. The commonest structural failure. Everyone assumes the gate, the broker, or the carrier owns a check, and nobody does. This is what the ownership column in the matrix above is for.
- Procedure that yields to schedule pressure. Every gate control fails the same way: the truck is there, the dock is backed up, the driver has the paperwork, and someone waves it through. A stop condition that can be overridden by whoever is on shift is not a stop condition. Name who is allowed to authorize an exception, and require it in writing.
- Security treated as the carrier's job. Most published guidance is addressed to carriers, which leaves shippers and brokers assuming their exposure is covered by someone else's program. The controls with the broadest threat coverage sit upstream of the truck.
A note on the numbers you will see quoted
Two data-hygiene points, because this category is full of figures that do not survive checking.
Do not blend sources. Verisk CargoNet covers the United States and Canada; Overhaul covers the United States only. For the second quarter of 2026 they disagreed on direction, with CargoNet reporting a 26% year-over-year decline and Overhaul a 5% quarterly increase (FreightWaves, August 2026). Averaging them produces a number describing nothing.
Treat the $35 billion figure with care. It circulates widely as an annual US cargo theft total. The underlying citation gives a range of $15 billion to $35 billion, and no primary publication supporting the upper figure alone is readily locatable. Use the range or use a sourced figure instead.
Frequently asked questions
What is cargo theft?
Cargo theft is the criminal taking of freight in transit or in storage. It includes straight theft from unattended trailers, fictitious pickups in which an impostor is handed the freight, carrier identity theft, undisclosed re-tendering, and pilferage of partial loads.
Is cargo theft actually increasing in 2026?
Incident counts are falling and losses are rising. Verisk CargoNet recorded 677 incidents in the second quarter of 2026, down 26% year over year, alongside $304.6 million in losses against $135.7 million a year earlier and an average loss of $564,009 per theft. Most published guidance still describes a rising-volume trend that the current data does not support.
Who is responsible for preventing cargo theft, the shipper, the carrier, or the broker?
All three, over different controls. Shippers own counterparty verification and the release decision. Brokers own carrier selection and continuous monitoring. Carriers own the freight in motion, including driver screening, securement, and stop discipline. Facilities own the gate. The controls with the broadest threat coverage sit with the shipper and broker rather than the carrier.
When is cargo theft most likely to occur?
Exposure concentrates when freight is stationary and unattended, which means weekends, holiday periods, and the first stop after pickup. Verisk CargoNet's analysis of Labor Day periods from 2021 through 2025 found annual incidents rising from 33 to 56, with California, Texas, and Illinois accounting for roughly half.
What should I do in the first hour after a load is stolen?
Confirm the loss is real, report to law enforcement where the freight was released and obtain a report number, file with a cargo theft recovery network and report VINs for vehicles, notify your insurer in writing, preserve gate photographs and camera footage before retention windows expire, then notify the carrier whose identity was used and freeze related tenders.
Does cargo insurance cover every kind of cargo theft?
No. Freight released voluntarily to an impostor is frequently treated under a voluntary parting exclusion rather than as theft, and whether the claim is paid depends on the specific policy form and any fraud endorsement. Carrier liability is also separate from cargo insurance and may be capped by a released rate expressed per pound.
How much does cargo theft cost beyond the value of the freight?
ATRI found that indirect expenses can reach three to six times the value of the stolen cargo, covering replacement, expedited re-shipment, customer remediation, investigation, and administrative burden. Average annual losses exceed $521,000 per motor carrier.
What is the most effective single cargo theft prevention measure?
Verifying a counterparty through a channel you sourced independently rather than one they supplied. Most 2026 losses are complete on paper before a truck reaches a gate, and inbound contact details are the part of the transaction a criminal controls.
How do you verify a carrier before releasing freight?
Confirm operating authority status and authority type, check financial security filings, capture expected driver and equipment details in advance through a channel you initiated, issue a pickup authorization code tied to a named driver, and at the gate inspect the physical licence and match equipment numbers and the DOT number on the door against the carrier of record.
Building prevention into the transport program
RPM Logistics moves finished vehicles across all 50 states and Canada through a contracted carrier network rather than open load boards, with motor vehicle record screening at onboarding and continuous monitoring thereafter, documented custody at every transfer, and more than 70 secured storage locations rather than open staging. If you want to test your current program against the control matrix above, talk to our team.
