How technology and AI are protecting freight marketplaces
- Checking company registration documents is no longer enough. Trans.eu builds a picture of each company’s normal behaviour and responds when user activity changes unexpectedly.
- When the system detects at least two anomalies at the same time, it launches a new verification process.
- The platform identifies most threats on its own, often before a customer reports a problem.
- AI does not replace security analysts. Instead, it can process thousands of events at once, revealing connections and patterns that may be impossible to spot manually.
Michał Pakulniewicz: You said that checking documents alone is no longer enough. If a company can appear completely legitimate, how do you recognise that something is wrong?
Piotr Sobala, International Security Team Leader at Trans.eu: The biggest change is that we pay less attention to a company’s claimed identity and much more attention to how it behaves. A few years ago, security was based mainly on checks carried out during registration. We reviewed documents, registration data and the company’s operating history. Today, that is only the starting point. What matters much more is whether the way a company uses the platform changes in a way that cannot be reasonably explained.
Michał Pakulniewicz: So the platform monitors user activity?
Yes, although it is important to stress that we are not looking at isolated actions. As the platform administrator, we monitor several signals that may point to unusual behaviour. We pay particular attention when at least two of those signals appear at the same time.
Michał Pakulniewicz: Are you effectively building a profile of each company’s normal behaviour?
In a sense, yes. Every company operates slightly differently. After a few weeks of activity, its usual pattern becomes fairly clear. If everything changes from one day to the next, the obvious question is: what has happened? We do not immediately assume that fraud has taken place, but we do consider the situation worth investigating.
Michał Pakulniewicz: What happens next?
When our analysis points to an elevated risk, we start a reauthorisation process. We contact the company and ask it to confirm specific details or provide additional documents. For a legitimate business, this is generally straightforward. Someone using a stolen account or operating under a false identity often cannot complete the process.
Michał Pakulniewicz: Do companies ever refuse to cooperate?
Yes. Since introducing this solution, we have reauthorised many entities. Several dozen companies did not respond to our requests at all. That does not automatically mean they were connected to criminal groups. However, each had previously displayed behaviour that we considered unusual and serious enough to warrant further checks. In such circumstances, a refusal to cooperate is itself a significant warning sign.
Michał Pakulniewicz: Are most cases identified through customer reports or your own analysis?
That is one of the biggest changes in recent years. In the past, we were much more likely to hear about a problem from customers. Today, our tools and analysis now identify around 55% of cases independently, while users report the rest.
This tells us two things. First, our security systems are becoming more effective. With every new case, we gain a better understanding of how criminals operate and can recognise their recurring methods more quickly. Second, carriers and freight forwarders are much more aware of the risks. More people can identify suspicious behaviour and report it before it leads to serious losses.
Michał Pakulniewicz: Does that mean you are now one step ahead of the fraudsters?
I would not put it that way. Security can create a dangerous sense of confidence if we are not careful. Every new safeguard encourages criminals to look for a different way in. This is not a battle that can be won permanently; it is an ongoing race. We learn how they operate, and they learn how we respond. That cycle never really ends.
Michał Pakulniewicz: What matters most in that race today?
Response time. A few years ago, we often learned about a problem only after a theft had occurred. Our goal now is to identify a threat before the incident takes place. If suspicious activity can be stopped several hours earlier, it is often possible to prevent the entire incident. That is why we are investing so heavily in data analysis and the automation of security processes.
Michał Pakulniewicz: Are you also referring to AI? Artificial intelligence is increasingly being discussed in cybersecurity. What role will it play in protecting transport platforms?
It is a natural direction for the industry. For many years, most security systems were rule-based. If we knew that fraudsters followed a particular pattern, we could build a mechanism to recognise it. The problem is that criminals change their methods quickly. When a new attack technique appears, traditional rules are no longer enough.
We do not see AI as a replacement for analysts. Its role is to identify unusual relationships between many signals at the same time. People are very good at examining individual cases. A system, however, can compare thousands of events at the same time and identify a pattern that no one has described before. That makes a major difference.
Michał Pakulniewicz: So rather than looking for a specific type of fraud, you need to look for abnormal behaviour among marketplace users?
Exactly. We will not always know what the next attack will look like. We can, however, see when a particular user’s behaviour suddenly deviates sharply from everything we have observed before. Those are the cases we want to identify much earlier than in the past.
Michał Pakulniewicz: It sounds like a technology race — or a contest between an anti-doping agency and athletes who are constantly looking for new ways to cheat.
That is a very accurate comparison. And, just as in sport, we are often half a step behind the people trying to cheat. They are constantly developing new scenarios, while our job is to recognise them as quickly as possible and build effective defences.
There is no doubt that criminals are using new technology too. We are already seeing phishing campaigns that are far more sophisticated than they were two years ago. Fake websites can look almost identical to legitimate ones.
Messages are written in polished language and are becoming harder to distinguish from genuine communications. As artificial intelligence develops, these campaigns are likely to become even more convincing. Our own tools therefore need to evolve just as quickly.
Michał Pakulniewicz: Does that mean complete security on freight marketplaces is impossible?
It is impossible. Anyone working in cybersecurity would probably give you the same answer. No system can be made impossible to bypass. All we can do is keep raising the barrier and shortening the time it takes us to respond. That is what matters most.
Michał Pakulniewicz: In our previous conversation two years ago, you said that you were one step behind criminals. How would you describe the situation today?
I would say that the gap has narrowed significantly. Two years ago, we often reacted only after criminals introduced a new method. Today, we can spot changes much faster and respond with the right solutions. If I had to use a simple comparison, I would say that we are no longer a full step behind. We may be a quarter-step behind — and that is a meaningful improvement for us.
We know this race will never end. It will continue for as long as cybercrime exists.
Michał Pakulniewicz: What can carriers and freight forwarders do themselves?
Above all, they need to stay alert. That may sound obvious, but haste is often a criminal’s greatest ally. Check the website address, verify who sent the message and ask whether the request actually makes sense. If someone suddenly asks you to log in again or tries to move the conversation off the platform, that should raise a red flag. Many fraud attempts have been stopped simply because someone asked one additional question at the right time.









