Thorsten Neumann, a NATO Civil Expert on cyber threats and a leading voice at TAPA EMEA

Modern technology makes life easier, but not safer. The flip side of logistics digitalization

You can read this article in 19 minutes

In an era where global supply chains are increasingly digitized, many logistics managers operate under the dangerous assumption that expensive IT systems, real-time tracking, and automated algorithms guarantee security. However, as the digital landscape evolves, so do the tactics of organized crime groups (OCGs). Operating with corporate efficiency, today's cargo thieves are just as likely to hack into a Transportation Management System (TMS), use AI to forge authentic-looking documentation, or deploy a €30 GPS jamming device bought online as they are to rely on physical force.

There is a person behind this text – not artificial intelligence. This material was entirely prepared by the editor, using their knowledge and experience.

To understand the hidden vulnerabilities of modern freight networks, we spoke with Thorsten Neumann, a NATO Civil Expert on cyber threats and a leading voice at TAPA EMEA. Neumann warns against the naivety and complacency that currently threaten the transport sector, arguing that technology—while crucial—cannot completely solve the issue of cargo theft in isolation. 

True resilience, he notes, must be backed by robust security protocols and a highly trained, security-minded workforce. In the following interview, Neumann breaks down the sophisticated methods of modern freight criminals, the risks inherent in digital freight exchanges, and how the logistics industry must evolve to protect its assets.

Artur Lysionok, trans.iNFO editor, AI and Business Development Coordinator: You once said that while modern technology makes life easier, it doesn’t necessarily make it more secure. Looking at the transport sector, have we fallen into a trap of naive optimism, blindly believing that GPS, IoT, and automation would completely solve the issue of cargo theft?

In all areas of freight crime prevention and supply chain security, naivety and complacency are two of our greatest enemies. Technology advancements are responsible for many outstanding improvements in protecting goods in supply chains, both in warehouses and distribution facilities and moving onboard all forms of transportation.

Technology definitely makes supply chains more secure if it is used correctly, but it’s important to remember that there is no such thing as 100% guaranteed security. You reference GPS, and it’s a valuable tool, but we see many instances where all this technology can be disrupted by a simple jamming device that can be bought on the internet for as little as €30, which can disrupt a tracking signal long enough for criminals to stop a truck and steal the vehicle and its load or just take the cargo. And, supply chains are increasingly vulnerable to hackers being able to infiltrate TMS systems to easily divert trucks to steal loads.

Also, when we talk about technology, we should remember that crime groups also have access to technology that makes it even easier to identify and target goods. Organised crime groups increasingly engaging in freight crime think and operate like corporations. And if they see a technology that helps them steal loads worth hundreds of thousands or millions of euros, they don’t have to go through lengthy business cases, budget reviews, and procurement processes. They just do it. The CEO of one TAPA EMEA member company stated recently that ‘criminal organisations are evolving faster than supply chains themselves.’ I totally agree.

Technology is a big and important part of supply chain resilience but, in isolation, it does not completely solve the issue of cargo theft. Simply having technology is place should be no excuse for any companies that are victims of freight crime. It needs to be backed up by security processes and protocols, as we set out in our TAPA Standards, and it needs to be implemented and managed by well-trained people with awareness and intelligence on the evolving risks.

Cargo thieves used to rely on a crowbar and an inside tip from a corrupt warehouse worker. What does the profile of a modern-day gang look like now? Who are the people currently dismantling digital supply chain security?

Cargo crime today covers everything from opportunist thefts by employees and individuals who roam around areas like unsecured parking places and motorway services looking for an easy truck to target. They will maybe steal a single smartphone from a pallet or slash a hole in a truck tarpaulin and grab what they can easily carry. This type of crime is never going to change because the opportunities and vulnerabilities are so great. There are currently more than 6.4 million medium and heavy commercial vehicles on EU roads to choose from.

Polizei Emsland/illustrative photo

But the greatest concern is the activities of organised crime groups. They understand that cargo crime offers rich rewards and low risk and, even if their operatives are caught, the penalties compared to other forms of crime are generally modest. So, there is massive incentive to participate in freight crime from their perspective. They see it as easy money.

If you look at it from a crime group’s point-of-view, it is like being offered a job that can pay you a million euros for a few minutes work.

OCGs are often described as a ‘paramilitary’ force and some of the thefts we see very much support this description. Highway robberies of cash-in-transit vehicles, for example, can involve gangs of 15-20 individuals, roadblocks using burning vehicles, automatic weapons, and explosives. And such crimes usually happen on major highways in broad daylight.

And, as I said, technology is now giving OCGs the opportunity to conduct freight crimes in a far less dramatic way. Setting up fake companies and bidding low to win delivery loads, for example, means they literally have to turn up at a warehouse dock and freely take over the collection of a truckload of products.

Hacking into WMS and TMS systems and using AI tools to create very authentic-looking documentation is now taking this risk to another level.

Many logistics managers treat expensive IT systems as an alibi—operating under the assumption that “we have the software, so we’re safe.” Has technology lulled us into a false sense of security and caused people to unlearn basic security habits?

I would go further. I think there are a very high number of companies out there that have little or no security software, systems, or processes, and who just have a ‘it won’t happen to us’ mentality. They are probably thinking they only have 20 trucks in their fleet and there are 6.4m commercial vehicles operating in Europe, so, statistically, they are highly unlikely to suffer a loss. And, that might be true. But, if they do, they have to explain to a customer not only that their goods have been stolen and their supply chain disrupted, but also that there was nothing in place to prevent the crime from happening. How would you feel if you were the customer? You trust would be broken. When SME companies are victims of cargo crime, they can lose major customers as a result and this can threaten their very survival.

Customers are quite realistic. They understand that sometimes it is impossible to stop a freight crime from occurring. But they find it much harder to accept that their service provider did not take the security of their supply chain seriously.

Security systems might lull companies into a false sense of security because some under-estimate the vital role people still play in the security and resilience process. I suspect some companies are quick to penalise employees deemed to be negligent. A better way is to train employees in loss prevention and to find a suitable way to reward them for the resilience of the entire supply chain operation.

Criminals are increasingly using social engineering against dispatchers, submitting fraudulent transport orders that look flawless inside a TMS. How do you train a human employee to question a transaction that the algorithm has already green-lit?

We have to look at layered security. In life, we are becoming conditioned to what technology tells us – and that is a massive risk. First of all, having evidence of the types of fraud taking place, we need to look at the checks and balances used within TMS systems to try to identify these crimes. How can they be improved to manage known risks? It’s also important to make employees understand more about freight crime, the M.O. used by crime groups, and to share examples of actual incidents to make the issue real. It’s about creating a security mindset.

But it is not easy. Changing an email address from a .de to a .com can be all it takes to steal a load worth several hundred thousand euros.

We have to keep learning, sharing intelligence, and raising awareness because preventing cargo crime is a journey that never stops. You may fix one vulnerability, but you can’t then walk aware and think your supply chain operation is secure. Crime groups are always looking for gaps in security – and, often, they don’t have to look very far.

TAPA EMEA/illustrative photo

Real-time visibility is the holy grail of modern logistics—customers want to know everything about their cargo instantly. Where is the line between “convenient tracking” and handing criminals the exact location of high-value goods on a silver platter? How can companies share tracking data safely?

I think we first have to look at the big picture and say that freight transport and logistics, overall, is a professional and reliable way of moving goods from B2B and B2C. Visibility is a big part of this because it is vital to production and inventory. We had a speaker at a TAPA EMEA conference several years ago who talked about the risks we face because we live and work in a ‘connected world’. Every single day, we happily share information personally and in business that makes us extremely vulnerable if this information falls into the wrong hands.

Realistically, we have to acknowledge that crime groups, in particular, will, in any case, find it easy to target high-value loads. This might be through insider information, systems hacking, or something as simple as monitoring media reports where they can see LSPs announcing big contract wins with major brands in specific countries or the opening of a dedicated facility to handle pharma products. This is lead generation for crime groups.

But, also, what are high-value goods these days?

We see cases of shipments stolen-to-order. A very specific type of product with a ready-made buyer lined up to receive the stolen goods. But the old view of cargo crime is no more. When TAPA was founded in 1997, the ‘T’ in our name stood for Technology’ because it was the high-tech industry that saw the value in industry collaboration and intelligence sharing to combat attacks on their supply chains. But, later, the ‘T’ became ‘Transported’ to recognise that virtually all goods moving in supply chains now face the risk of being stolen.

Criminals know a truck carries a lot of units of products. Yes, a truck full of phones, laptops, catalytic converters, cigarettes, or pharmaceuticals will have a considerable value. But, a truckload of cheese, nappies, shoes, bicycles, power tools, or household appliances can also be valued in the high six-figure range. And this is what makes nearly all trucks a target.

Digital freight exchanges and spot platforms have revolutionized the market, but they’ve also become a playground for fictitious pickups and carrier identity theft. How sophisticated have these cargo fraud methods become, and why is traditional document verification no longer enough?

This partly comes back to my comments about our connected world and how this adds risk. But, freight exchanges are a very big and important part of the transport and logistics market and, of course, the large majority of companies offering capacity through them are professional, reliable operators who deliver as promised. But the sheer size of the loads being transacted – alongside the need for companies to move goods quickly and at the lowest cost – opens doors to fake carriers and fraudulent operators if they can find a way onto an exchange.

Technology plays a big part in vetting and advanced risk prevention architecture, alongside comprehensive rating systems, and this can prove extremely successful in preventing infiltration by rogue operators. Given the scale of the big exchanges, traditional document verification is not viable and more open to abuse.

We have recently announced a collaboration with Trans.eu on a new Certified Carrier Exchange, which is powered by TAPA Intelligence & Standards. This exchange only allows transport companies with TAPA Trucking Security Requirements (TSR) Level 1 and Level 2 certifications to offer capacity and bid for loads. This is another layer of security and reassurance for shippers and LSPs, particularly for movements of high-value, theft targeted loads.

TAPA EMEA and Trans.eu launch the first freight exchange built on TAPA’s supply chain security certifications

While the industry is excited about how AI will optimize routing and predict delays, how is artificial intelligence helping criminals? Is the TAPA Intelligence System (TIS) already picking up attacks or anomalies orchestrated by malicious algorithms?

Our TIS system is also leveraging the benefits of AI to help companies use our freight crime intelligence to plan secure routings. I expect to see more companies using AI to optimise routings and to predict delays and we facilitate this. TIS allows them to cross-reference route optimisation to see if the proposed AI solution brings their vehicles into known cargo crime ‘hotspots’. It will also help them to see the types of goods being targeted on specific routings, the numbers and types of incidents, and the modus operandi used in attacks on trucks, other transport modes, and facilities. Additionally, TIS provides access to our secure parking database, which is another important element of secure transportation.

Like all technology, AI will help legitimate businesses and it will also help crime groups. This is why companies can never be complacent and must remain well-informed and vigilant.

As a NATO Civil Expert on cyber threats, you view logistics through the lens of critical infrastructure protection. Is Europe’s fragmented, privately-owned road freight sector anywhere near ready to withstand hybrid or state-sponsored cyberattacks targeting core systems like TMS?

This is such a good question and I would have to say the answer is ‘no’ because the privately-owned freight sector is so fragmented. Individual companies, the big players, will, of course, have security solutions and response mechanisms in place to identify and, hopefully, prevent such an attack. But, often, you can’t tell how resilient your security is until there is an attempt to breach it.

Being a NATO Civil Expert is a great honour and it certainly gives me a broader insight and outlook. What I can say is that NATO very much recognises the importance of resilient supply chains and the need to protect them, as well as the value of listening to, and engaging with, industry leaders to learn more.

For years, TAPA standards (TSR, FSR) were heavily associated with physical security: high-security locks, alarms, surveillance, and concrete barriers. How are these standards evolving to keep pace with cyber threats? Are we going to see mandatory cyber-security requirements for on-board telematics in trucks?

TAPA’s supply chain security Standards are minimum standards that provide a framework for companies to raise and standardise their security levels. What makes them especially effective is that they are developed through industry consultation. They are reviewed every three years to ensure they are fit-for-purpose and to address new and emerging security threats. In fact, the next revisions of our Trucking Security Requirements and Facility Security Requirements are launched on 15 September 2026.

There is also a TAPA Cyber Security Standard and, additionally, we have specific security guidance documents which cover locking systems, CCTV, telematics, and subcontracting. Through discussions with our members and via our Standards & Training team and working groups, we are constantly reviewing the support and solutions we offer to our members to help make their supply chain operations more secure – and we are always open to suggestions for other areas we should be focusing on.

Investing in advanced cybersecurity is expensive. Small and medium-sized carriers—the backbone of transport in Central and Eastern Europe—often lack the budget for it. Are we facing a market split into a “secure digital elite” and an “analog high-risk zone”?

SME carriers are a very important part of European and global supply chains and I do not see this changing any time soon. TAPA’s Cyber Security Standard (CSS) is geared to SME operators because we recognise the big industry players are already advanced in this area in terms of their preparedness. I believe the important thing for SME carriers is to demonstrate that they take security seriously. No one expects them to have the same investment capabilities as a big global LSP, but that doesn’t mean they should do nothing.

Within the TAPA EMEA membership community, we have hundreds of professional SME transport companies that are using our Standards, Training & Intelligence. This places them alongside our global LSP members. Being part of this community give SMEs constant updates, awareness, and solutions to manage risks, and I believe their customers place great value on this.

If you could give one piece of unfiltered, no-nonsense advice to a logistics director who thinks their supply chain is bulletproof because “everything is in the cloud and managed by AI,” what would it be?

If they haven’t already done so, my best advice is to join TAPA EMEA. Supply chains are never ‘bulletproof’ or 100% secure. You don’t always realise this when you are working alone. But as part of a like-minded network – in our case over 1,100 global brands shipping goods, global LSPs, national and regional SME transport and logistics providers, insurers, security service providers, parking operators, and law enforcement professionals – gets you closer to the reality of the risks supply chains are facing, and gives you access to information, intelligence and security solutions that will, ultimately, help to make your supply change more secure. At TAPA EMEA, we truly believe supply chains become more secure when we work together.

Tags:

Also read