Data reports
Why Carrier Impersonation Works: Nobody Is Watching the Records You Verify Against
By The Draylo Team · August 1, 2026
The short answer
Highway's Q2 2026 index attributes roughly half of classified freight-fraud vectors to communication-based attacks — impersonation, spoofed email, compromised inboxes. They work because the federal contact layer brokers verify against is soft: 72.5% of active carriers register webmail addresses, about one in eight filings hasn't been updated in two-plus years, and 21,093 aged carriers combine stale filings with takeover-prone inboxes. “Matches the record” is weak proof of identity when nobody is watching the record.
Fraud stopped inventing carriers — it started borrowing them
Freight fraud used to mean fake carriers: invented companies, forged documents, authority minted for a scam. That era is ending, because the industry got better at catching invented identities. Highway's Q2 2026 Freight Fraud Index puts communication-based attacks — compromised inboxes, spoofed email, impersonation calls — at roughly half of classified fraud vectors, up from 42.7% the previous quarter. Ownership-change fraud accounts for another quarter of reported thefts.
A communication-based attack doesn't invent a carrier. It borrows a real one — a company with active authority, filed insurance, and a clean record — and simply answers your email as them. The vetting check comes back green because the carrier IS legitimate. The person you're talking to isn't the carrier.
Which raises the question this report measures: how hard is that to pull off? The answer lives in the federal contact layer — the phone numbers and email addresses on FMCSA's own records that brokers verify against. We counted the whole file.
The verification ritual has a hidden assumption
When a broker verifies a carrier contact, the ritual is: compare what's in front of you to what's on the federal record. That ritual silently assumes two things — that the record is current, and that the inbox it names is still controlled by the carrier. We measured both assumptions against the July 2026 federal files, all 378,583 carriers with active operating authority.
Neither assumption holds as often as the ritual implies.
| The contact layer, measured (July 2026 full file) | Finding |
|---|---|
| Active carriers using webmail contact addresses (gmail, yahoo, etc.) | 274,660 — 72.5% |
| Filings not updated in 2+ years (contact info nobody has touched) | 46,174 — about 1 in 8 |
| Non-webmail domains that serve 100+ carriers each (shared service inboxes) | 24 domains — 4,577 carriers |
| The full stack: 3yr+ authority + stale filing + webmail contact | 21,093 carriers — about 1 in 18 |
The hijack stack: 21,093 unwatched shells
Look at the last row of that table. Those 21,093 carriers hold three properties at once: authority old enough to have a valuable, trusted history; a federal filing nobody has updated in over two years; and a contact inbox on ordinary webmail — the kind taken over with one phished password, no domain spoofing required.
That combination is what an impersonator shops for. An aged clean record means brokers' checks come back green. A stale filing means the listed contact information is old — and that nobody at the carrier is minding the record. A webmail inbox means the cheapest possible takeover. Put together: a company worth impersonating, with nobody watching the identity that would be borrowed.
This is also the population where ownership-change fraud — the bought-shell pattern that now accounts for about a quarter of reported thefts — operates most comfortably: the shell's value is its tenure, and its unwatched record is what lets the handoff pass unnoticed.
One inbox, hundreds of carriers
There's a second, less obvious surface in the data. Not every carrier contact is unique to that carrier: 24 non-webmail domains each serve as the registered contact for a hundred or more carriers — 4,577 carriers in total. These are mostly insurance agencies, permit services, and compliance firms that file paperwork on their clients' behalf, with their own email as the contact of record.
Nothing improper about that — it's how small carriers outsource paperwork. But it concentrates risk: one compromised service inbox is a skeleton key to impersonating hundreds of carriers at once, each of whom would check out clean against the federal record. Blast radius is a property of the contact layer's structure, not of any carrier's behavior.
What these numbers are not
A webmail contact address is not a red flag — at 72.5% of the population, it is the norm. Owner-operators dispatch from the cab on a Gmail address, legitimately, every day. A stale filing is not evidence of wrongdoing; it usually means a busy small carrier hasn't gotten to their biennial paperwork. These are population statistics about a fraud surface, not verdicts about any carrier on it.
The honest conclusion is narrower and more useful: “the email matches the record” is weak proof of identity, because the record is frequently old, usually webmail, and rarely watched. Matching the record proves the fraudster did their homework. Verification has to reach past the record to the carrier itself.
Verifying in a world of unwatched records
Three practical habits close most of the gap. First, check the record's date along with its contents — FMCSA shows when a filing was last updated, and a contact block that hasn't been touched since 2023 deserves less trust than one refreshed this spring. Second, verify out-of-band: call the phone number on the federal record — not one from the email thread — before the first load and before any change in payment details. Third, treat contact changes as events: a carrier whose registered contact information just changed, right before quoting you, is worth one extra phone call.
One methodology note, because this is a data report: every number here is a full count of FMCSA's public July 2026 files — 378,583 carriers with active operating authority. “Webmail” means the 20 largest consumer email providers; “stale” means no MCS-150 update in the two years before the file date; “aged” means authority held three years or longer. No samples, no estimates, no third-party aggregators. The Highway and ownership-change figures are from Highway's published Q2 2026 Freight Fraud Index.
Frequently asked questions
Why do fraudsters impersonate real carriers instead of inventing fake ones?
Because vetting got better at catching invented identities. A real carrier with active authority, filed insurance, and a clean history passes every record check — so borrowing that identity through a spoofed or compromised email beats forging a new one. Industry data now attributes roughly half of classified fraud vectors to these communication-based attacks.
Is a carrier using a Gmail or Yahoo address a red flag?
No. 72.5% of active US carriers — 274,660 companies — register webmail contact addresses with FMCSA. It is the industry norm, especially for owner-operators. The signal worth attention is not which provider a carrier uses, but whether the person emailing you actually controls the address on the federal record — which is why out-of-band verification matters.
How current is FMCSA's carrier contact information?
Carriers are required to update their MCS-150 filing every two years, but about one in eight active carriers — 46,174 as of July 2026 — has a filing more than two years old. Broker records are worse: barely half of active brokers' filings are current. A contact block on the federal record can be years out of date while the carrier operates normally.
How do I verify a carrier email is really from the carrier?
Don't rely on the email thread to verify itself. Call the phone number on the carrier's federal record — not a number from the email signature — and confirm the load and the contact. Check the record's last-update date for how much trust it deserves. And treat any change in contact or payment details mid-relationship as a trigger to verify out-of-band again.
Get the next guide in your inbox
Practical guides like this one — carrier fraud, broker liability, vetting that holds up. One email when a new guide publishes; no list-blasting, unsubscribe with one reply.