惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
H
Help Net Security
The Cloudflare Blog
Y
Y Combinator Blog
A
Arctic Wolf
Cyberwarzone
Cyberwarzone
G
Google Developers Blog
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
博客园 - Franky
罗磊的独立博客
Martin Fowler
Martin Fowler
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
博客园 - 三生石上(FineUI控件)
N
News and Events Feed by Topic
F
Fortinet All Blogs
N
News | PayPal Newsroom
J
Java Code Geeks
www.infosecurity-magazine.com
www.infosecurity-magazine.com
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
Google Online Security Blog
Google Online Security Blog
Recorded Future
Recorded Future
博客园 - 聂微东
S
Securelist
C
CERT Recently Published Vulnerability Notes
小众软件
小众软件
Cisco Talos Blog
Cisco Talos Blog
S
Security Affairs
NISL@THU
NISL@THU
A
About on SuperTechFans
PCI Perspectives
PCI Perspectives
N
News and Events Feed by Topic
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Jina AI
Jina AI
Microsoft Azure Blog
Microsoft Azure Blog
AWS News Blog
AWS News Blog
GbyAI
GbyAI
C
Cyber Attacks, Cyber Crime and Cyber Security
V
Vulnerabilities – Threatpost
D
Docker
P
Proofpoint News Feed
W
WeLiveSecurity
Help Net Security
Help Net Security
The GitHub Blog
The GitHub Blog
The Last Watchdog
The Last Watchdog
The Hacker News
The Hacker News
博客园 - 叶小钗

Proofpoint News Feed

The Hacker News Hackers find a new trick to collect Microsoft Entra user data without raising red flags Suspected Chinese snoops caught breaking into universities Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense | Proofpoint US OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Suspected North Korean actors use fake ‘coding assignments’ to steal crypto China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era | Proofpoint US Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude | Proofpoint US Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America | Proofpoint US The spy who logged me in. - YouTube Proofpoint Establishes Innovation Precedent for Source-Agnostic Modern Enterprise Investigations | Proofpoint US The Most Powerful Women Of The Channel 2026: Power 100 AI Security Gaps Create New MSSP Opportunity: Proofpoint Claude Mythos Fears Startle Japan's Financial Services Sector Proofpoint Research Reveals Half of Global Organizations Experienced AI Incidents Despite Having AI Security Controls in Place | Proofpoint US AI-Era Threats Spread Beyond Email Into SaaS, Collaboration Apps, and AI Assistants Clear market trend for software providers to help with AI: Proofpoint CEO - YouTube Cargo thieving hackers running sophisticated remote access campaigns, researchers find Freight Hacker Wields Code-Signing Service to Evade Defenses - YouTube FIFA World Cup 2026: More than One-Third of Official Partners Expose the Public to the Risk of Email Fraud | Proofpoint US Microsoft 365 mailbox rules abused for exfiltration, persistence AI Security Risks: Proofpoint CSO Ryan Kalember, Live at RSAC 2026 Axios Future of Cybersecurity: Russians suspected of using iPhone spyware 15 Top Cybersecurity CEOs On The Future Of AI Agents: RSAC 2026 How AI Agents Are Redefining the Insider Risk Threat Model 5 Ways To Protect Enterprise Value During A Merger Or Acquisition CUBE Events 20 Coolest AI And Security Products At RSAC 2026 Proofpoint Redefines Email and Data Security for the Agentic Workspace | Proofpoint US Proofpoint Pursues FedRAMP High Authorization Process for Collaboration Security | Proofpoint US Proofpoint Unveils Industry’s Newest Intent-Based AI Security Solution to Protect Enterprise AI Agents | Proofpoint US
New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams
Steve Weisman · 2026-07-01 · via Proofpoint News Feed
Long shadow truck with a thief

Illustration of a long shadow truck with a thief

getty

Last January, I told you about the great lobster heist where criminals stole 40,000 pounds of lobster meat valued at approximately $400,000 from a warehouse in Taunton, Massachusetts and vanished without a trace. The lobster had been intended for delivery to Costco stores in Illinois and Minnesota but, most likely ended up being sold on the black market to restaurants or distributors. No arrests have been made.

BOURBON THEFT

More recently, 10,800 bottles of Noble Oak bourbon valued at approximately $500,000 were stolen from a warehouse in Philadelphia by criminals who arrived at the warehouse with a truck to pick up the bourbon which was scheduled for delivery that day. In this case the driver of the truck did not have a purchase order to claim the delivery although those papers could have easily been counterfeited. However, the unsuspecting warehouse employees merely called the legitimate trucking company to confirm that they had sent a truck to pick up the bourbon and when the answer was in the affirmative, they released the bourbon. When the legitimate truck arrived, the cargo thieves had already left with the bourbon.

While truck hijacking is not a new crime, the sophisticated cargo thefts now occurring combine traditional criminal activity with sophisticated technology to bring cargo thefts to new heights. The National Insurance Crime Bureau (NCIB) estimates the annual losses from cargo theft to be $35 billion.

HIGH TECH CARGO THEFT

Setting the stage for this new method of cargo theft begins with sophisticated hackers compromising a freight broker’s load board account, which is an online marketplace where trucking loads are listed and bid on. As typical in many data breaches and other cyberattacks, the accounts are compromised through social engineering and spear phishing. After taking over a freight broker’s account, the criminals then post a fraudulent load listing offering an attractive shipment. When a legitimate trucking company or dispatcher responds to the phony load listing, the criminals reply with an email with malware contained in a link that appears to be a shipping document or contract. When the legitimate trucking company clicks on the link, remote monitoring and management (FMM) software is surreptitiously installed on the legitimate trucking company’s computer thereby giving the criminal full access to the legitimate company’s computer network enabling them to pose as the legitimate company and bid on deliveries or to pose as the legitimate company and send emails that appear to be from the legitimate company related to already contracted deliveries. The criminals invade the supply chain so that even when a truck is dispatched for a legitimate load, as happened in this particular bourbon heist, the criminals make sure they get there first. The thieves show up with trucks bearing the markings of the legitimate companies they pose as and pick up the items to be delivered. Once the loaded trucks leave the warehouse, they disable the GPS tracking used in shipments Cybersecurity company Proofpoint issued a report in November of 2025 that details precisely how these thefts are accomplished.

It has been hypothesized that more traditional organized crime rings that may have hijacked trucks in the past are partnering up with new cybercriminals who are in effect the IT department for the older crime gangs.

Testifying before the House Judiciary subcommittee, Chris Spear, the President of the American Trucking Associations said, “Straight theft has been around since trucks have been on the road. It involves the physical theft of cargo from a distribution center of the back of a truck.” However, noting the evolution of this crime, he told the committee “Strategic theft involves the use of advanced cyber tactics to trick shippers, brokers, and carriers, to divert and hand over loads. This high-tech form, cargo theft has become a digital Renaissance for thieves, surging 1,500% since 2021.”

Combating this new partnership of organized crime trucking hijackers and cybercriminals will require close collaboration between law enforcement, government agencies and the commercial trucking industry. In 2022 the Department of Homeland Security launched Operation Boiling Point (particularly appropriate for the lobster heist) to combat organized crime groups involved with cargo thefts and organized retail crime through such collaboration. However, as evidenced by cargo thefts such as the recent bourbon theft, there remains a lot of work to do.