Are transport exchanges safe? How is crime evolving on freight platforms?
- Instead of spending months taking over established companies, criminals increasingly steal digital identities through phishing and launch rapid attacks.
- Fraudsters using compromised accounts may have only a few hours before the account is detected and blocked.
- Another growing threat comes from legally registered companies that spend months building a credible track record before striking when least expected.
- Most successful fraud still happens outside official platforms, often through fake email addresses containing minor spelling changes in the domain.
- Cyberattacks are increasingly carried out by organised groups with clearly divided roles, using servers or infrastructure in places such as Armenia and companies registered in the United Kingdom, Italy, Romania and Lithuania.
Michał Pakulniewicz: Two years ago, we spoke about fraud in transport, and you described the situation as a kind of cycle. At one point, fake freight forwarders dominated; at another, criminals impersonated carriers. Back then, the main problem was the takeover of existing transport companies. What has changed since then?
Piotr Sobala, International Security Team Leader, Trans.eu Group: I used the word cycle because the nature of transport crime has been changing for years. At some points, we see more fraud involving fake carriers; at others, dishonest freight forwarders pose the greater threat.
Two years ago, criminals were carrying out highly sophisticated schemes. They would legally take over established transport companies and exploit their operating history and the trust those businesses had built over many years. Such a company looked credible to both freight forwarders and carriers, allowing criminals to steal a large number of high-value loads in a short period.
It seemed reasonable to assume that this approach would continue. Instead, criminals changed direction. Taking over an entire company is no longer always necessary. Compromising its digital identity is much easier.
What does that mean in practice?
Phishing has become one of the biggest threats. Criminals trick users into handing over their login details. Compared with buying or taking over an entire company, it is cheaper, easier and, above all, faster. The pattern is usually familiar: a user receives a message that appears to come from the platform.
The message may claim that the user must log in again, update their account details or resolve an issue. The link does not lead to the real Trans.eu website, however, but to a convincing copy. Once the user enters their login and password, the criminal gains access to the account and can impersonate the legitimate company for a limited period.
Many business owners believe they would immediately recognise a fake email. Are these messages really that convincing?
Unfortunately, they are becoming harder to spot. Early phishing campaigns were relatively crude. Today, fake login pages can replicate the original almost perfectly. Often, the only difference is the web address: a single altered letter or a different domain ending. When someone is working under pressure and handling dozens of messages a day, that detail is easy to miss. That is exactly what criminals are counting on.
What happens next? Are stolen credentials used immediately?
Not necessarily. That is one of the elements that surprises many people. A criminal may wait a week, a month or even longer before logging in. We saw a particularly strong wave of phishing campaigns around the turn of 2024 and 2025, while attempts to exploit the stolen credentials for theft and fraud appeared many months later.
The fraudster monitors the company’s activity and waits for the moment that offers the best chance of success. Only then is the compromised account put to use. As a result, the company owner often does not connect the later incident with a message they clicked several weeks earlier.
There is one major difference compared with the situation two years ago. Previously, preparing an attack could take months. Now, speed is the priority. A criminal taking over an existing company account knows that the owner will eventually notice an unauthorised login or a new user. There is no time to spend several days building credibility. The window may be only a few hours.
Does that affect the scale of cargo theft? With a company under their control, criminals could plan a major operation more carefully. Is that harder when they have only stolen an identity?
Yes. A few years ago, criminals invested substantial time in preparing a single large operation. They took over a credible company, established the necessary infrastructure, spent weeks getting ready and then defrauded several freight forwarders, stealing numerous high-value loads in a short period. Taking over a company made sense when the plan was to steal many valuable shipments. The model looks different today.
Someone using a compromised account knows that the time available is extremely limited. The account owner may notice unusual activity, our analysts may identify suspicious behaviour, and the account may be blocked.
Speed is therefore critical. Instead of planning a large-scale theft involving many shipments, a criminal will usually try to divert one or two loads and disappear. This creates an interesting paradox: the number of fraud attempts is rising, while the average value of individual thefts is falling.
Even so, last year was a record year for cargo theft across Europe.
That is true, and it shows that the problem is far from over. Across the European market, the number of incidents reached record levels. Depending on the source, the increase compared with the previous year was estimated at two or even three times the previous year’s figure. That illustrates the scale of the challenge facing the industry.
Data from our platform, however, point to a different pattern. Although we are detecting more fraud attempts, the total value of stolen cargo is decreasing. As I mentioned, someone who takes over an account through phishing knows that they have very little time. The account holder or our security team will often spot irregularities quickly.
That leaves no opportunity to prepare a large-scale operation. The criminal has to act immediately. So there are more attempts, but each individual attack tends to be much smaller.
Interestingly, during the first half of this year we have also seen fewer companies affected. This suggests that criminals continue to develop new methods, but our security controls are helping to limit the resulting losses.
For us, that is a more important measure than the number of incidents alone. Business partners have also become more alert and better informed about fraud, which is another factor helping to reduce cargo theft.
So, based on what you are saying, the major phishing wave around the turn of 2024 and 2025 affected 2025, while the situation began to stabilise in the first half of the year as new safeguards were introduced.
I would like to say that this is the full picture, but it would be too simple. I do not see any sign that cybercriminals are backing off. Quite the opposite: new scenarios continue to appear.
We have seen cases where a compromised account was not used immediately to steal cargo. Instead, the fraudster sent PDF files containing malware through the platform’s messenger. Anyone who opened one of those files could also have had their computer compromised. This shows that criminals are constantly looking for new ways to gain access to more accounts.
You mentioned new tactics. Is phishing still the biggest threat, or are other scenarios emerging?
Phishing is one of the two main scenarios. Before discussing the second, which involves setting up shell companies on the platform, it is important to mention that identity theft also includes the traditional impersonation of companies outside the platform.
Fraudsters create email addresses that closely resemble legitimate business addresses. The difference may be just one letter or a different domain ending.
They then contact carriers or freight forwarders and try to move the conversation off the platform. This technique has been around for years, but it remains highly effective. Based on the cases reported to us, the clear majority of fraud taking place outside transport platforms follows this pattern.
And people still fall for it?
Unfortunately, yes. We sometimes assume that a method is so well known that nobody could still be deceived by it. Reality is different. All it takes is haste, a moment of inattention or a situation that appears urgent. That is the same mechanism behind phishing campaigns: the victim is not given enough time to stop and think carefully.
That is why we constantly remind users to check the sender’s address, verify the website address and avoid moving communication outside the platform unless there is a clear need to do so.
You mentioned another popular method used by fraudsters alongside phishing: shell companies.
Phishing remains one of the most serious problems, but it is not the only one. Companies set up solely to exploit the credibility they build over several months are becoming a growing challenge. This is now the second clear trend we are seeing.
A few years ago, many fraudsters tried to take over established companies with an existing track record. Today, it can be more effective to create a new entity, complete the verification process, spend several months building credibility and only then commit the fraud. It requires patience, but it gives criminals much greater control over the entire operation.
Are we talking about entirely fictitious businesses, or legally registered companies that genuinely operate?
That is the most difficult part. In many cases, these companies are fully and legally registered. They have a licence, insurance, a trading history and an identifiable owner, and they complete the authorisation process. On paper, everything checks out.
There is no obvious reason to reject such a company as suspicious from the outset. In fact, it may look completely normal for many months.
But is it actually carrying out transport operations on the exchange?
Often, yes. This is another shift we are seeing. In the past, fraudsters wanted to move as quickly as possible. Today, they may patiently build a credible profile. They complete individual jobs, collect positive feedback and accumulate references. Everything appears routine.
Only after some time does the moment arrive for which the company was created: one theft, sometimes two, and then the operation ends.
Does that mean document verification alone is no longer enough?
Exactly. Document checks remain essential. We need to know who is registering a company and whether the submitted documents are genuine. But today, that is not enough to provide complete protection.
Someone who plans fraud from the beginning can prepare for the verification process much more thoroughly than a few years ago. That is why it is now equally important to monitor what happens after a company has completed authorisation.
Does the responsibility for greater vigilance and closer scrutiny of potential business partners lie not only with the platform operator, but also with its users? Are users paying more attention to suspicious activity?
Definitely. A few years ago, many people checked little more than whether a company was verified and how long it had been operating. Today, businesses assess a much broader range of information.
They look at the cooperation history, the number of completed jobs, references and activity on the platform. If a company has existed for only a few months but has almost no operating history, users are increasingly likely to ask additional questions. That is a positive development. User awareness has clearly improved.
Even so, criminals still manage to deceive people successfully?
Unfortunately, yes. We have to remember that criminals are learning from the market as well. If they know that recently established companies receive more scrutiny, they will not necessarily act a week after registration. They can wait several months, sometimes even longer. Their objective is to build trust. The more credible they appear, the more likely someone is to skip an additional check.
Can you identify the countries these companies most often come from?
Based on what we observe, they are more often foreign entities. At present, the cases we analyse most frequently involve companies from the United Kingdom, Italy, Romania and Lithuania. That does not mean companies from those countries are less trustworthy. These are simply the locations that appear most often in the cases under review.
And what about the phishing campaigns you mentioned earlier? Where do they originate?
When we analyse technical data, we see that many login attempts and parts of the infrastructure used by criminals can be traced to IP addresses in Armenia. But an important distinction is necessary: an IP address does not tell us who the perpetrator is. It may point to where a criminal group is operating, rented servers or infrastructure used to run an attack. We therefore cannot conclude that the people responsible are from that country.
It sounds as though we are no longer dealing with individual fraudsters, but with well-organised groups.
That is our observation too. We are increasingly seeing a clear division of roles. Some people obtain access to accounts. Others identify the most attractive loads. Another group handles the theft itself or the subsequent sale of the goods.
This shows that crime in the transport sector is becoming more professional. That is precisely why traditional verification methods are no longer enough. We need to analyse not only documents but also user behaviour. In many cases, behaviour is the first sign that something is wrong.
This is the first of two interviews with Piotr Sobala about security in the transport sector. In the second part, we discuss how algorithms, behavioural analysis and artificial intelligence help detect anomalies and limit losses on freight exchanges. Both interviews are available under the #interviewSobala tag.









