How Freight BEC Works: Rate-Con Spoofing and Factoring Fraud in Microsoft 365
Freight business email compromise works by hijacking or imitating a broker, carrier, or factoring company's email account, then using that trusted thread to alter a rate confirmation, change remittance instructions, or hand a load to the wrong truck. The money or the freight moves before anyone notices the email was forged. I have worked these cases inside trucking and 3PL clients, and the pattern is almost always the same: a real conversation, a small change to a payment field, and a wire that clears in hours.
Most people picture a hacker breaking through a firewall. Freight BEC is quieter than that. The attacker rarely needs to break anything. They read your email, learn how you do business, and then send a message that looks exactly like the ones you already trust.
Why freight is a target, not collateral damage
Trucking and brokerage run on email and PDFs. A rate confirmation, a factoring NOA, a remittance change, a setup packet. These documents carry real dollars and they move fast, often outside business hours when a dispatcher just wants the load covered. That speed is the whole point of the business, and it is also the opening.
The fraud numbers back this up. The FBI's Internet Crime Complaint Center logged roughly 21,442 business email compromise complaints in 2024 with close to $2.8 billion in losses, making BEC the second costliest crime category that year by dollars lost (2024 IC3 Annual Report). Over the decade ending in 2023, IC3 tracked more than $55 billion in exposed losses from BEC across over 305,000 incidents (IC3 BEC public service announcement). Freight is a slice of that, but it is a fat slice, because the documents are routine and the payees change all the time.
Layered on top of email fraud is the physical theft. CargoNet reported 3,625 cargo theft events in 2024, a 27% jump over the prior year, and called out strategic theft, fictitious pickups, and double brokering as the fastest-growing methods (CargoNet 2024 supply chain risk trends). Many of those strategic thefts start with a compromised or spoofed email. The keyboard comes first, the missing trailer comes second.
Rate-con spoofing: changing the numbers that matter
A rate confirmation is the contract for a single load. It names the broker, the carrier, the pickup and delivery, the agreed rate, and increasingly the payment terms. An attacker who controls a broker mailbox, or who registers a lookalike domain, can intercept that rate con and send a doctored version.
The edits are small on purpose. A new line that says factoring has changed. A revised remittance email. Sometimes just a different reply-to address so the carrier's questions go to the attacker instead of the real broker. The carrier hauls the load in good faith, then bills an account the broker never controlled. By the time accounting reconciles, the load is delivered and the money is gone.
I have also seen the reverse. The carrier's mailbox is the one compromised, and the attacker sends the broker an updated W-9 and banking page so the legitimate carrier's payment lands in a mule account. Same trick, opposite direction. The forged thread is always built on a real one, which is why it slides past a busy dispatcher.
Factoring fraud: stealing the payment, not the freight
Factoring is where freight BEC gets expensive quietly. A carrier sells its invoices to a factoring company, which pays the carrier up front and collects from the broker later. The whole arrangement runs on a Notice of Assignment, an email that tells the broker where to send payment. Change that email, and you redirect every invoice for that carrier.
The attacker either spoofs the factoring company or compromises the carrier's email and sends a fake NOA, or a fake update to an existing one, pointing remittance at a new account. The broker, doing exactly what the document tells them, pays the fraudster. IC3 has documented BEC funds increasingly routed through third-party payment processors, peer-to-peer apps, and cryptocurrency exchanges, which makes recovery harder once the transfer clears (IC3 BEC PSA). A single redirected factoring relationship can bleed for weeks before anyone catches the pattern.
Double brokering: the load that walks off
Double brokering is the freight-specific endgame of an identity takeover. A fraudster steals a legitimate carrier's identity, often by harvesting MC numbers, insurance certs, and email from compromised inboxes or load boards, then bids on a load using that stolen identity. The broker awards the load to the imposter. The imposter re-brokers it to a real, unsuspecting carrier and pockets the payment when it arrives.
Sometimes the load delivers and only the money is stolen. Sometimes the load never delivers at all, which is how an email scam becomes a stolen trailer of electronics on a CargoNet report. The FBI treats cargo theft as organized crime for good reason (FBI on cargo theft), and the entry point is frequently a mailbox, not a parking lot.
How attackers get inside Microsoft 365
Almost every freight client I work with runs on Microsoft 365. Attackers know that, and they target it directly. The common path is a phishing page that captures a login, then a session token, which lets them bypass basic MFA and read mail without tripping a password reset.
Once inside, they get patient. They create inbox rules that auto-forward or auto-delete messages with words like invoice, rate con, factoring, or remittance, so the real owner never sees the fraudulent thread. They watch for a live deal, then strike at the moment a payment instruction is in motion. The compromise can sit dormant for weeks. That is why detection has to look at behavior, not just spam scoring.
What actually stops freight BEC
Generic email filtering is not enough, because the malicious message often comes from a real, trusted account. You need controls aimed at how freight money moves. At EFROS we treat it as freight-grade email security: anomaly detection tuned to rate confirmations and remittance changes, isolation of factoring-related email so a banking change cannot quietly slip through, and lookalike-domain monitoring on our clients' top 50 shipper and carrier contacts so a one-character impersonation gets flagged before a dispatcher replies.
Underneath that sits the Microsoft 365 hardening: Conditional Access and Intune to shut down stolen-token logins, plus alerting on the auto-forwarding and hidden-rule tricks attackers rely on. We pair it with phishing simulation and awareness built around freight scenarios, dark-web and executive-identity monitoring, and a bundled incident-response retainer with a guaranteed four-hour response SLA and a named incident commander, because when a wire is in motion you do not have time to shop for help.
The operational rule that catches the most fraud costs nothing: any change to banking, factoring, or remittance gets verified by a phone call to a known number, never the number in the email. Technology buys you the alert. The callback closes the gap.
If your dispatch and accounting teams move money on email every day, it is worth pressure-testing exactly how a forged rate con or fake NOA would travel through your shop. You can see how we structure that defense on the EFROS cargo fraud defense page, or call us at +1-765-888-8888 to walk through your current exposure.
Frequently Asked Questions
What is freight business email compromise?
Freight business email compromise is a fraud where an attacker hijacks or imitates a broker, carrier, or factoring company's email to alter rate confirmations, redirect payments, or steal a carrier's identity to double-broker a load. Because the message comes from a real or near-identical address, it bypasses the trust controls that normally protect a deal. The result is a diverted payment, an unpaid carrier, or in some cases a stolen shipment.
How do attackers divert factoring payments?
They send a fake or altered Notice of Assignment, the email that tells a broker where to remit payment for a carrier's invoices. By spoofing the factoring company or compromising the carrier's mailbox, they change the remittance account so the broker unknowingly pays a fraudster instead of the real factor. A single redirected factoring relationship can lose money for weeks before the mismatch is caught.
Is Microsoft 365 secure enough to stop this on its own?
Default Microsoft 365 settings stop a lot of spam and basic phishing, but freight BEC often arrives from a legitimate, compromised account, which sails past spam scoring. You need Conditional Access to block stolen-token logins, monitoring for malicious inbox-forwarding rules, and detection tuned to rate confirmations and remittance changes. The platform is a strong foundation, not a finished defense.
How can a dispatcher tell a rate confirmation is fake?
Watch for last-minute changes to payment terms, factoring, or remittance details, a reply-to address that differs slightly from the broker's normal domain, and pressure to move quickly outside business hours. The single most reliable check is a callback: confirm any banking or factoring change by phone using a number you already have on file, never the number printed in the suspect email.
What does EFROS do specifically for trucking and 3PL clients?
EFROS provides freight-grade email security, including rate-con anomaly detection, isolation of factoring-related email, and lookalike-domain monitoring on each client's top 50 shipper and carrier contacts. That sits on top of a 24/7 SOC, SentinelOne endpoint protection, Microsoft 365 and Intune hardening, and a bundled incident-response retainer with a guaranteed four-hour response SLA and a named incident commander. The program is mapped to NIST CSF 2.0 and TAPA for quarterly board-grade reporting.
About the author

Stefan Efros
CEO & Founder, EFROS
Stefan founded EFROS in 2009 after 15+ years in enterprise IT and cybersecurity. He sees how the pieces connect before others see the pieces themselves. Focus: security-first architecture, operational rigor, and SLA accountability.
Related articles
More from the EFROS blog on cybersecurity and adjacent topics.
Quishing: The QR-Code Phishing Attack Your Email Filters Miss
Quishing hides phishing links inside QR code images, so text-based email filters never see the URL. Here's why it slips through and the controls that actually stop it.
DMARC for Small Business: Stop Attackers From Spoofing Your Domain
A plain-English DMARC, SPF, and DKIM guide for SMBs. How DMARC stops domain spoofing, why p=none isn't enough, and how to move safely to p=reject.
The 2026 Phishing Landscape for Small and Mid-Size Businesses
What phishing looks like in 2026 for US small and mid-size businesses: AI-written lures, MFA-bypass AiTM attacks, vendor impersonation, and what to fix first.