← All guides

Carrier fraud

Anatomy of a Double-Brokering Attempt: How a "Clean" Carrier Steals a Load

By The Draylo Team · July 17, 2026

A carrier record card that looks complete and green on the surface, with a red thread pulled loose from one corner revealing a second, mismatched identity beneath it.

The short answer

A modern double-brokering attempt doesn't fail the obvious checks — that's the point. The scammer uses a real, active MC (often a hijacked or purchased one), sends a professional carrier packet, and gives you a working phone number. The load is re-brokered to an unwitting real carrier or simply stolen. What catches it isn't checking harder on the surface — it's verifying the pieces cohere: does the contact match the FMCSA record, is the insurance actually in force, and is the entity behind the number the one actually hauling.

The short version

A modern double-brokering attempt is engineered to pass the checks most brokers run. The carrier's authority is active, the MC is real, the packet looks professional, and the phone number they give you rings. Everything "checks out" — and a few hours after pickup, the freight is gone. This isn't a failure of vetting effort; it's a failure of vetting the right things. The scam is built to survive a surface check, so the defense is verifying that the identity holds together underneath.

This post walks the attack the way it actually unfolds, then maps each step to the check that stops it. None of these checks are exotic. They're the difference between confirming a record exists and confirming the party in front of you is the one the record describes.

Step 1 — The scammer starts with a real, active MC

The old mental model — "a scam carrier will have no authority or a revoked one" — is exactly what modern fraud exploits. Today's operation starts with a legitimate-looking MC. Sometimes it's purchased: authorities with clean histories are bought precisely so the paperwork checks out. Sometimes it's hijacked — a real carrier's identity is taken over, its FMCSA-registered contact info quietly changed so verification emails and calls route to the scammer instead of the real company.

The tell isn't in the authority status, because the authority status is fine. The tell is in whether the entity's details are internally consistent and recently altered: a carrier whose registered contact information was updated days before it contacted you, or whose email domain was registered weeks ago despite a years-old authority, is wearing an identity that may not be its own.

Step 2 — The packet looks perfect (because it's built to)

The carrier packet arrives complete and professional: signed agreement, W-9, a certificate of insurance showing healthy coverage. Brokers reasonably treat a clean packet as reassurance. It isn't. A certificate of insurance is a snapshot of coverage as of its issue date — it proves nothing about coverage today, and a polished COI can be fabricated outright. The FMCSA is explicit that "even insurance certificates can be fraudulent."

The check that catches this is verifying insurance against the federal filing rather than the certificate: the carrier's liability status on record with FMCSA (which insurers update when a policy is cancelled) is the stronger signal, and a COI claiming more coverage than the federal BIPD filing on record is a classic forged-certificate flag. Coverage that a broker has actually seen lapse — active on the certificate, pending cancellation on the filing — is exactly the mismatch a surface read misses. Our insurance-lapse check covers why the COI date isn't proof.

Step 3 — The contact info routes to the scammer, not the carrier

The phone number and email on the rate confirmation ring and reply — but they belong to the scammer, not the carrier whose MC is on the load. This is the pivot the whole scam turns on, and it's why calling the number you were given proves nothing: you're just confirming you can reach the fraudster.

The single most-recommended defense among working brokers is an out-of-band check: pull the carrier's phone number from the FMCSA record (SAFER) and call that, not the number on the offer. If the number you were given doesn't match the federal record, you're talking to someone other than the carrier. A mismatch between the contact on the offer and the contact on the federal record is one of the clearest fraud signals there is — and it's the one a scammer usually can't fake, because they don't control the real carrier's FMCSA-listed line.

Step 4 — The load is re-brokered or disappears

With the tender accepted, the scammer either re-brokers the load to an unwitting legitimate carrier (pocketing the difference and leaving a payment mess and liability confusion behind) or arranges for it to be picked up and simply stolen. By the time the freight is missing, the trail runs through a contact that was never the carrier, an insurance policy that was never in force, and an identity that was never really theirs.

Recovery is unlikely, and the enforcement backstop is thin — brokers routinely report that law enforcement lacks the resources to pursue these cases even when handed evidence. Which means the practical truth is blunt: prevention at the point of tender is the defense. There isn't a meaningful cure.

The pattern under all four steps: verify coherence, not existence

Notice what connects every step. In each one, a single fact "checks out" in isolation — real authority, complete packet, working phone — while the pieces don't cohere with each other or with the federal record. Surface vetting checks each fact alone and passes. Fraud lives in the gaps between the facts.

So the defensible version of vetting asks a different question than "does this carrier exist and have authority?" It asks: does the domain match the registered business name, is the contact the one FMCSA lists, is the insurance in force on the federal filing and not just on the certificate, and was this identity recently altered in a way that suggests takeover? Those are the seams a clean-looking scam splits open. Checking them is what separates a green light you can defend from one that just looked green.

Doing this fast enough to actually do it

The honest objection every busy broker raises: "I move 80 loads a week — I can't run a forensic investigation on each one." Fair. But the answer working brokers give each other is that the coherence checks aren't slow once they're a process rather than a scramble — and the alternative is a stolen load. The goal isn't more vetting; it's vetting fast enough that thoroughness stops being a tradeoff against volume.

That's the entire reason a tool exists for this: an always-on base read — authority, insurance status, and double-brokering signals against the live federal record — that clears every load in seconds, plus deeper layers you add on the loads that warrant them, like verifying the carrier's contact out-of-band or running an identity-coherence check on a brand-new authority. The base keeps up with the load board; the extra layers are your call, load by load. Start with the free read — enter a USDOT or MC and get a red/yellow/green verdict in seconds. For the full vetting sequence these steps fit into, see the new freight broker carrier vetting checklist and how to check if a carrier is legit.

Frequently asked questions

How does a double-brokering scam pass carrier vetting?

It's engineered to. The scammer uses a real, active MC number — often purchased for its clean history or hijacked from a legitimate carrier — sends a complete, professional carrier packet, and provides a working phone number. Each fact checks out in isolation, so a surface vetting pass gives a green light. The fraud lives in the gaps: the contact routes to the scammer instead of the carrier, the insurance certificate doesn't match the federal filing, and the identity may have been recently altered.

Why isn't checking the carrier's phone number enough?

Because the number on the rate confirmation belongs to the scammer, not the carrier whose MC is on the load. Calling it just confirms you can reach the fraudster. The defense is an out-of-band check: pull the carrier's phone number from the FMCSA record (SAFER) and call that instead. If the number you were given doesn't match the federal record, you're not talking to the real carrier.

Can a certificate of insurance be faked?

Yes. FMCSA states plainly that even insurance certificates can be fraudulent. A COI is also only a snapshot of coverage as of its issue date — a policy can be cancelled mid-term with no new certificate issued. Verify coverage against the carrier's federal insurance filing (which insurers update on cancellation), not the certificate alone; a COI claiming more coverage than the federal BIPD filing on record is a red flag.

What is a 'chameleon' carrier?

A chameleon carrier is a fraudulent operation running behind an existing carrier's identity — often an MC with a real load history that was purchased or hijacked so the operation looks established. Because the paperwork belongs to a legitimate (or formerly legitimate) carrier, surface checks pass. Signs include registered contact details changed just before the carrier reached out, or a business profile that no longer matches the carrier's actual current operation.

Will law enforcement help recover a stolen load?

Usually not in time to matter. Brokers widely report that law enforcement lacks the resources to pursue individual freight-fraud cases, even when handed evidence. Recovery after the fact is unlikely. That makes prevention at the point of tender — verifying identity coherence before the load moves — the real defense rather than the cure.

Get the next guide in your inbox

Practical guides like this one — carrier fraud, broker liability, vetting that holds up. One email when a new guide publishes; no list-blasting, unsubscribe with one reply.

Check a carrier now

Catch the mismatch before the load moves. Run a free USDOT or MC check against live FMCSA data — verdict, insurance status, and double-brokering signals in seconds, no signup.

Run a free carrier check →

Want every check documented automatically? Start a 30-day free trial — no card required.

Keep reading