Freight Fraud

Real Documents. Wrong Hands. Is Freight’s Verification Enough?

What the Revolut breach teaches freight about fake requests and real credentials.

Aleksander Frelas · September 17, 2026 · 11 min read

Real Documents. Wrong Hands. Is Freight’s Verification Enough?

Revolut, the financial technology company whose app provides banking, payments and international money transfers, confirmed on September 12 that it had disclosed sensitive customer information after receiving fraudulent requests from a legitimate government-agency email domain. The company said its own systems and customer funds were unaffected. [1] [2]

Customer notifications described potentially exposed records including copies of passports and driver’s licenses, verification selfies, contact details, account statements and transaction histories, including Bitcoin transactions. [3] The Financial Times subsequently reported that 680 customers had been notified. [4]

The immediate lesson is about checking who is entitled to receive sensitive information. But there is another lesson for freight: what happens when information collected during a legitimate verification process becomes available to someone trying to pass another one?

A scan of a real driver’s license can still contain accurate information after it reaches the wrong person. So can a carrier’s insurance records, tax documents and banking details. The information does not announce that its custody has changed. That should make us more skeptical of any verification process that treats possession of genuine documents as sufficient reason to trust the person presenting them.

When the stolen packet checks out

Consider the evidence freight companies collect during onboarding and pickup: operating authority information, a certificate of insurance, a W-9, a broker-carrier agreement, payment instructions and, depending on the process, identification belonging to a driver. Those records answer legitimate business questions. They can also supply an impostor with accurate information about the business they intend to impersonate.

Carrier identity theft is not a new concern. The Federal Motor Carrier Safety Administration, or FMCSA, warns about unauthorized use of another carrier’s identity and fraudulent insurance certificates. Its guidance calls for independent checks of contact information and comparisons between the booked carrier and the equipment arriving to collect the load. [5]

Now imagine a fraudster obtaining a complete, genuine carrier packet. The company exists. The authority is active. The address matches. The insurance information belongs to the carrier. Checking those details against other records produces reassuring results because the information really is correct.

Those checks still have value. They establish facts about the carrier. What they do not necessarily establish is that the person submitting the packet represents it. A process can correctly validate the information and still make the wrong decision about the person holding it.

That is where counting checks can become misleading. Five matching documents are not five independent reasons to trust someone if all five came from the same stolen packet. Even checking the information against separate databases does not automatically connect the presenter to the business described in those databases.

Some carrier information is already public or routinely shared. It should not be treated as a secret that only an authorized representative would know. And where a process relies on possession of more sensitive records, the availability of genuine copies to criminals directly weakens that assumption. The records have not necessarily become less accurate. Possession has become less meaningful.

How genuine records reach the wrong hands

Picture a packet moving from a carrier into a broker’s inbox, a transportation management system, a shared folder and a third-party service. A criminal who gains access to one of those locations may obtain records originally supplied for an entirely legitimate purpose. Another possibility is that someone persuades an employee to send the records out.

That second route was documented well before Revolut. In November 2024, the FBI warned about criminals using compromised government email accounts to submit fraudulent emergency requests for customer information. The warning described online advertisements for government-account credentials and guidance on abusing them to obtain private records. [6]

This is why the email domain in the Revolut case matters. Email systems use safeguards called SPF, DKIM, and DMARC. In simplified terms, they check whether a sending server is permitted to use a domain, whether digitally signed parts of a message were changed, and whether the authenticated domain matches the one shown to the recipient. They help detect forged sender addresses. They do not determine whether the request inside the message should be honored. [7]

Someone using an unauthorized or compromised account on a genuine domain may therefore pass the technical email checks. The DMARC standard explicitly distinguishes authenticating a domain’s use from deciding whether a message is safe. A real address is not a permission slip to receive somebody else’s records. [7]

For freight, the connection is direct. Imagine a carrier packet released in response to a bogus compliance review or claims inquiry, then presented to another broker during onboarding. The first company’s failure is an improper disclosure. The second company’s potential failure is assuming that possession of the packet establishes a legitimate relationship with the carrier.

One company’s disclosure problem can become another company’s verification problem.

AI makes the material more useful, not every check worthless

Genuine records can also provide a foundation for more elaborate impersonation. The U.S. Treasury’s Financial Crimes Enforcement Network, known as FinCEN, helps combat money laundering and other financial crime. In November 2024, it warned about increased suspicious-activity reporting involving suspected use of AI-generated or manipulated media, particularly fraudulent identity documents intended to circumvent verification controls. [8]

Consider what an attacker could assemble from a real packet, an employee’s public profile and old correspondence. Names, addresses, business relationships and the language used in previous transactions could all be accurate before any fabricated element is added. The attacker does not have to invent an entire company. They can build the impersonation around one that exists.

That does not mean possession of a stolen license and photograph guarantees a successful identity check. Live capture, facial comparison and liveness detection, which looks for signs that a real person rather than a photograph or recording is present, can create additional obstacles. The U.S. National Institute of Standards and Technology, or NIST, also addresses protections against fabricated media being substituted into a verification session. These controls have limits, but they are not interchangeable with simply accepting an uploaded image. [9]

The AI concern here is a possible downstream use of exposed information, not a claim that AI was involved in the Revolut incident. Nor does that incident establish that any freight-verification service was defeated. The question is whether the process you actually use can distinguish an authorized participant from someone equipped with convincing material about one.

Don’t count checks. Ask what the stolen packet cannot answer.

Revolut does not prove that verification technology is useless. It is a reason to examine the decisions a successful check does not settle. A genuine identity does not make every instruction legitimate, and an authenticated email does not establish a right to receive sensitive information. Nor does successful verification end the responsibility to protect the information collected along the way.

Proper identity verification already recognizes part of this distinction. NIST separates validating the authenticity and accuracy of evidence from establishing that the applicant is the person to whom the evidence belongs. Checking the document and checking its presenter are different steps. [10]

That makes the criticism here specific: a document-heavy process deserves scrutiny when it treats the first step as if it completed the second. Carrier vetting, driver verification and pickup controls are valuable precisely when they establish something beyond facts a stranger could copy from a file.

A useful test is to assume an attacker already has a complete packet, accurate public records and old correspondence. Which step would still stop them? What would they have to demonstrate that cannot be learned from those files? That is a more revealing question than how many fields your onboarding form contains.

Start with independently established sources. Confirm operating authority through official records and relevant insurance coverage through the insurer or authorized agent. FMCSA recommends confirming carrier and broker contact numbers through its records rather than relying solely on the details supplied by the person contacting you. But remember what the lookup establishes: information about the company, not automatic authority for the person making the request. [5]

The next step needs to connect the person to the business and the transaction. Does an established carrier contact confirm the assignment now? Was that contact independently verified, or supplied in the same questionable message? Is the approval tied to this shipment, or is everyone relying on a previous onboarding result? A fresh confirmation through an established channel asks more of an attacker than another copy of a document already in their possession.

At pickup, this means checking more than whether the driver has genuine identification. Consider a real driver acting on fraudulent dispatch instructions. That person could pass an identity check correctly because their identity is not the deception. The remaining question is whether the booked carrier authorized that driver to collect this particular load.

This is where stronger pickup processes belong in the solution. They can connect the driver, carrier, equipment and shipment instead of allowing one successful identity check to stand in for the whole relationship. A driver change, payment change or new destination should trigger verification of the relevant authorization, not automatically inherit trust from an earlier approval.

The exception process deserves the same scrutiny. Test what happens when the normal check fails, when someone claims the equipment is not working, or when urgency is used to request an override. A strong verification step offers less protection if a convincing caller can simply persuade someone to bypass it.

Don’t supply the next fraud attempt

The same skepticism should apply after verification. Every identity image or carrier document retained is information that still needs protection. The question is not only whether it entered the business securely, but who can retrieve it, export it or send it to someone else.

Before releasing sensitive records, establish the recipient, the purpose and the authority for the request. Legal and government demands should reach the people responsible for validating them. A familiar domain or urgent explanation should not replace that decision. Otherwise, the evidence collected to prevent one fraud attempt can become material for the next.

Retention needs similar discipline. U.S. property brokers must preserve the transaction records specified in 49 CFR § 371.3 for three years. That is not a blanket requirement to retain every identity document or duplicate attachment collected during onboarding. Other applicable obligations, including contractual requirements and legal holds, also need to inform the retention schedule. [11]

Preserve the evidence needed to explain what was checked, which source was used, what the result was and who approved the transaction. Retain underlying documents where necessary and protect them accordingly. That is different from keeping the same driver’s license indefinitely in several inboxes and shared folders because nobody decided what should happen to it.

There is also a useful direction in digital identity: proving a necessary fact without distributing the entire document behind it. The European Union’s Digital Identity Wallet initiative incorporates “selective disclosure,” which allows users to share required attributes without revealing unrelated information. [12]

The freight application is worth considering. A driver could demonstrate the required license status without every facility collecting another full copy. A carrier could provide verifiable confirmation of relevant insurance coverage rather than treating a forwarded PDF as the final answer. Those examples would require suitable issuers, current information and reliable checks connecting the evidence to its user. They are not capabilities a European initiative automatically delivers to U.S. freight.

The objective should be fewer reusable copies, not less accountability. And even a well-protected digital credential would still need to be connected to the action being authorized.

The harder test is genuine evidence

The lesson is not that freight should stop verifying. It is that verification deserves scrutiny when its confidence comes mainly from information an unauthorized person could obtain elsewhere.

A process that catches altered documents may perform very differently when the documents are genuine. A process that verifies a real person may still miss fraudulent instructions. And a process that makes the right decision today can create tomorrow’s exposure if it mishandles the records collected.

Revolut should prompt a harder question than whether the paperwork looks legitimate: what would your process establish if the person presenting it had obtained every document improperly? Until you can answer that, a completed checklist may say more about the accuracy of the packet than the legitimacy of the counterparty.

A forged packet should fail verification. The harder test is whether the process rejects a fraudster carrying a real one.

SOURCES

Numbered references correspond to the sources below. Source links checked September 16, 2026.

[1] Revolut. Banking & Beyond.

https://www.revolut.com/

[2] Reuters. Revolut confirms sensitive customer data breach after fake government requests. September 12, 2026; updated September 14, 2026.

https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/

[3] The Block. Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov’t domain. September 12, 2026.

https://www.theblock.co/news/business/2026-09-12-revolut-says-customer-kyc-bitcoin-transaction-data-exposed-after-fake-request-from-govt-domain-414516

[4] Financial Times. Revolut handed nearly 700 customers’ data to scammers. September 14, 2026. Subscription may be required.

https://www.ft.com/content/e0fe28a8-bc8c-460d-a7f2-972f725c0d46

[5] Federal Motor Carrier Safety Administration. Broker and Carrier Fraud and Identity Theft. Updated April 7, 2025.

https://www.fmcsa.dot.gov/mission/help/broker-and-carrier-fraud-and-identity-theft

[6] Federal Bureau of Investigation. Easy Access to Information for Conducting Fraudulent Emergency Data Requests Impacts US-Based Companies and Law Enforcement Agencies. November 4, 2024. Private Industry Notification 20241104-001.

https://www.ic3.gov/CSA/2024/241104.pdf

[7] Internet Engineering Task Force / RFC Editor. RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC). See Section 1, Introduction.

https://www.rfc-editor.org/rfc/rfc9989.html

[8] Financial Crimes Enforcement Network. FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions. November 2024.

https://www.fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial

[9] National Institute of Standards and Technology. Digital Identity Guidelines, SP 800-63A-4: Identity Proofing Requirements. See requirements for physical evidence validation and digital injection prevention.

https://pages.nist.gov/800-63-4/sp800-63a/ial-general/

[10] National Institute of Standards and Technology. Digital Identity Guidelines, SP 800-63A-4: Identity Proofing Overview. See identity validation and identity verification.

https://pages.nist.gov/800-63-4/sp800-63a/proofing/

[11] Electronic Code of Federal Regulations, reproduced by Cornell Law School’s Legal Information Institute. 49 CFR § 371.3: Records to be kept by brokers. See paragraph (b) for the three-year retention requirement.

https://www.law.cornell.edu/cfr/text/49/371.3

[12] European Commission. EU Digital Identity Wallet: Security and Privacy. See selective disclosure.

https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/712508927/Security+and+Privacy

Get the next one in your inbox.

Free, 3× a week, the brief 15,000+ freight pros read.