How Transportation Leaders Are Fighting Back Against Enterprise Cyber Risks

How Transportation Leaders Are Fighting Back Against Enterprise Cyber Risks

October 2, 2026 | By Amy Roach 

In freight transportation today, cybersecurity has become everyone’s job. That’s one of the key takeaways from this week’s National Motor Freight Traffic Association (NMFTA) 2026 Cybersecurity Conference in Long Beach, Calif. 

Traditionally, physical security and digital IT in the freight world lived in two entirely different universes. Freight theft meant stolen trailers at yards, truck stops, on the road, or at warehouse docks, while cybersecurity was an in-the-office IT concern. Industry executives, technology leaders, and security experts gathered at the conference agree that protecting moving cargo today requires a strategy that promotes alignment from the C-suite down to the loading  dock.

Everyone has a role to play.

 

The Blurred Line Between Freight Fraud and Cybercrime

Traditional cargo theft is rapidly giving way to digital manipulation. Criminal rings frequently rely on compromised carrier portals, hijacked credentials, forged electronic paperwork, and AI trickery to lure companies into handing over valuable freight. 

“Where does traditional freight fraud end and cyber-enabled freight fraud begin? I think [that line] is disappearing,” explained Erica Brigance, vice president of technology enablement at ArcBest, during a panel discussion on the state of the industry. “We are so digitally connected with our customers and partner carriers that it’s one and the same. The way freight fraud is showing up is by people getting into systems and doing things that they shouldn’t.”

Digital platforms like public load boards, carrier onboarding systems, and even routine email threads have become primary entry points for bad actors posing as legitimate operators. Once inside, attackers claim high-value shipments and alter drop-off locations, or send malware masked as routine PDF attachments like insurance certificates or bills of lading.

Data visibility can also be turned into a tool for theft, noted Todd Florence, CIO of Estes Express Lines. Shippers and brokers often ask for constant tracking updates, but broadcasting live locations introduces security risks if those data streams aren’t carefully managed.

“We have customers who want to know where every trailer is with five seconds of accuracy on the GPS pane,” said Florence. “Do I want everybody to know where all of our equipment is with five seconds of accuracy? Maybe not. How do you fuzz those things up to meet customer demand while managing theft implications? That’s where you see a lot of friction.”

NMFTA Cybersecurity Conference 2026

Weaponized AI: Deepfakes and Shadow Risks

A central point woven into several presentations was the growing risk from AI exposure. Generative artificial intelligence has given fraudsters a way to launch convincing social engineering campaigns on a much larger scale, noted panelists.

Voice cloning and video deepfakes are already making their way into places like dispatch operations and call centers. With as little as three seconds of audio pulled from a public webinar or podcast, a cybercriminal can replicate an executive’s or dispatcher’s voice to authorize a fraudulent wire transfer or reroute a load, explained James McQuiggin, a former CISO and founder of risk advisory firm Apparent Security, who demonstrated generating a complete deepfake video in just four minutes using easily available online tools. 

“The question isn’t, is it a deepfake? The question is, how long do you think it took to make that video?” McQuiggin said. “Attackers aren’t hacking any systems. They’re calling. They are doing the deepfakes. They are calling staff to gain access, pretending to be somebody else.”

Along with external AI threats, internal operational vulnerabilities are growing through “shadow AI”—employees putting company data into unmonitored consumer AI apps.

“What concerns me more is what our employees choose to do with our data,” Brigance noted, echoing the concerns of several panelists. “Educating employees to make sure they understand what they can and can’t do with our data, and what they can share, is crucial.”

Supply Chain Blind Spots and Third-Party Exposure

As fleets add technology like telematics, dash cams, and IoT sensors to their trucks, the attack surface expands exponentially. As a result, security concerns extend into third-party connections including repair shops, software access points, and onboard hardware.

Recent research presented at the conference and conducted by Anne Zachos, cybersecurity research engineer with NMFTA and Jaime Lightfoot, cybersecurity researcher, Lightfoot Labs, revealed eye-opening vulnerabilities in the Electronic Logging Device (ELD) ecosystem. Their findings show that 50% of registered ELDs use white-labeled hardware sourced from a tiny pool of manufacturers and 75% of analyzed ELD mobile apps share the same underlying white-labeled codebase.

When a vulnerability surfaces in a shared hardware component or cloud library, they explained, the breach isn’t isolated to one fleet but instead can ripple across hundreds of reseller brands and thousands of trucks on the road simultaneously.

Vendor oversight has consequently become a core risk-management discipline. “Having someone manage your technology is not the same as having someone defend it,” cautioned Estes’ Florence, who highlighted a case where a former software vendor retained a copy of a carrier’s code repository years after a project ended, leaving it exposed when the vendor was later breached. “The amount of contracts I have to review now compared to before… we’re evaluating how we interconnect,” he added.

Industry Collaboration as the Ultimate Defense

Historically, companies kept quiet about cyber incidents out of fear of brand damage or legal fallout. That’s changing. 

Resources like the NMFTA Threat Report Portal—a centralized industry platform for reporting incidents, sharing intelligence, and gaining visibility into emerging risks—give fleets of all sizes a way to report threats anonymously and receive near-real-time warnings before bad actors reuse the same tactics elsewhere.

“We are very interconnected,” Florence stressed. “Anything that impacts one of us impacts all of us. The more of that information we can share as an industry, the stronger we all are.”

Brigance agreed, adding, “Finding out that someone is having a problem and how they’re thinking about it helps all of us.”

Moving From Compliance to True Resilience

NMFTA Cybersecurity Conference 2026

Another problem the industry spends time thinking about is ransomware attacks. While much public focus centers on the ransom note, security expert Melanie Padron, vice president of strategic growth at IT Architeks, warned that a ransom note isn’t the start of an attack—it’s the middle. Threat actors often lurk inside networks for months, studying operations and exfiltrating data before locking files, she explained.

Padron contrasted a 95-year-old carrier that went out of business after an unmonitored breach with a fuel hauler that recovered from an attack in 18 hours without paying a dime—simply because they had practiced their response plan and tested their backups under clock pressure.

When a breach hits, Padron said, survival comes down to muscle memory, not annual compliance checkmarks. Fleets must assign clear crisis roles, use out-of-band comms like Signal, and routinely run full system restores.

“An incident response plan isn’t a door that criminals compromise per se, but it is the key to closing one that’s already been compromised,” Padron stressed. “A backup that has never been tested under real conditions is not a safety net. That’s a hope.”


Executive Action Plan: Key Steps to Strengthen Resilience

Security expert Melanie Padron provided an actionable roadmap for logistics leaders to “move from assumed security to verified resilience.” Her cyber battle plan includes these steps: 

  • Designate a clear executive owner for cybersecurity risk and response, keeping risk oversight distinct from routine IT uptime management.
  • Conduct thorough reviews of external vendor credentials, revoke stale access points, and enforce strict contractual rules regarding data privacy and AI usage.
  • Schedule semi-annual crisis simulations involving executive, legal, IT, and operational teams to build muscle memory under pressure.
  • Routinely practice full system recovery from off-site, immutable backups to ensure recovery timeframes hold up when every minute counts.

Padron also shared these five questions every company should ask when reviewing their security stance:

  1. Who owns your cyber risk?
  2. When was your last independent audit?
  3. When did you last practice your incident response plan?
  4. Who has admin privileges to your network?
  5. Can you prove your backups work?