惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Attack and Defense Labs
Attack and Defense Labs
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
博客园 - 司徒正美
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
Jina AI
Jina AI
GbyAI
GbyAI
Y
Y Combinator Blog
罗磊的独立博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Proofpoint News Feed
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
雷峰网
雷峰网
博客园 - 【当耐特】
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
S
Secure Thoughts
博客园 - 三生石上(FineUI控件)
Cyberwarzone
Cyberwarzone
NISL@THU
NISL@THU
J
Java Code Geeks
C
Cisco Blogs
人人都是产品经理
人人都是产品经理
Webroot Blog
Webroot Blog
腾讯CDC
博客园 - 叶小钗
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Troy Hunt's Blog
AI
AI
L
LangChain Blog
Know Your Adversary
Know Your Adversary
T
Tenable Blog
M
MIT News - Artificial intelligence
P
Privacy & Cybersecurity Law Blog
L
LINUX DO - 最新话题
Hugging Face - Blog
Hugging Face - Blog
F
Full Disclosure
P
Proofpoint News Feed
AWS News Blog
AWS News Blog
有赞技术团队
有赞技术团队
A
Arctic Wolf
Security Archives - TechRepublic
Security Archives - TechRepublic
S
Schneier on Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
W
WeLiveSecurity
The Cloudflare Blog

Proofpoint News Feed

The Hacker News Hackers find a new trick to collect Microsoft Entra user data without raising red flags Suspected Chinese snoops caught breaking into universities Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense | Proofpoint US OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Suspected North Korean actors use fake ‘coding assignments’ to steal crypto China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era | Proofpoint US Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude | Proofpoint US Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America | Proofpoint US The spy who logged me in. - YouTube Proofpoint Establishes Innovation Precedent for Source-Agnostic Modern Enterprise Investigations | Proofpoint US The Most Powerful Women Of The Channel 2026: Power 100 AI Security Gaps Create New MSSP Opportunity: Proofpoint Claude Mythos Fears Startle Japan's Financial Services Sector Proofpoint Research Reveals Half of Global Organizations Experienced AI Incidents Despite Having AI Security Controls in Place | Proofpoint US AI-Era Threats Spread Beyond Email Into SaaS, Collaboration Apps, and AI Assistants Clear market trend for software providers to help with AI: Proofpoint CEO - YouTube Cargo thieving hackers running sophisticated remote access campaigns, researchers find Freight Hacker Wields Code-Signing Service to Evade Defenses - YouTube FIFA World Cup 2026: More than One-Third of Official Partners Expose the Public to the Risk of Email Fraud | Proofpoint US Microsoft 365 mailbox rules abused for exfiltration, persistence AI Security Risks: Proofpoint CSO Ryan Kalember, Live at RSAC 2026 Axios Future of Cybersecurity: Russians suspected of using iPhone spyware 15 Top Cybersecurity CEOs On The Future Of AI Agents: RSAC 2026 How AI Agents Are Redefining the Insider Risk Threat Model 5 Ways To Protect Enterprise Value During A Merger Or Acquisition CUBE Events 20 Coolest AI And Security Products At RSAC 2026 Proofpoint Redefines Email and Data Security for the Agentic Workspace | Proofpoint US Proofpoint Pursues FedRAMP High Authorization Process for Collaboration Security | Proofpoint US Proofpoint Unveils Industry’s Newest Intent-Based AI Security Solution to Protect Enterprise AI Agents | Proofpoint US
New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams
Steve Weisman · 2026-07-01 · via Proofpoint News Feed
Long shadow truck with a thief

Illustration of a long shadow truck with a thief

getty

Last January, I told you about the great lobster heist where criminals stole 40,000 pounds of lobster meat valued at approximately $400,000 from a warehouse in Taunton, Massachusetts and vanished without a trace. The lobster had been intended for delivery to Costco stores in Illinois and Minnesota but, most likely ended up being sold on the black market to restaurants or distributors. No arrests have been made.

BOURBON THEFT

More recently, 10,800 bottles of Noble Oak bourbon valued at approximately $500,000 were stolen from a warehouse in Philadelphia by criminals who arrived at the warehouse with a truck to pick up the bourbon which was scheduled for delivery that day. In this case the driver of the truck did not have a purchase order to claim the delivery although those papers could have easily been counterfeited. However, the unsuspecting warehouse employees merely called the legitimate trucking company to confirm that they had sent a truck to pick up the bourbon and when the answer was in the affirmative, they released the bourbon. When the legitimate truck arrived, the cargo thieves had already left with the bourbon.

While truck hijacking is not a new crime, the sophisticated cargo thefts now occurring combine traditional criminal activity with sophisticated technology to bring cargo thefts to new heights. The National Insurance Crime Bureau (NCIB) estimates the annual losses from cargo theft to be $35 billion.

HIGH TECH CARGO THEFT

Setting the stage for this new method of cargo theft begins with sophisticated hackers compromising a freight broker’s load board account, which is an online marketplace where trucking loads are listed and bid on. As typical in many data breaches and other cyberattacks, the accounts are compromised through social engineering and spear phishing. After taking over a freight broker’s account, the criminals then post a fraudulent load listing offering an attractive shipment. When a legitimate trucking company or dispatcher responds to the phony load listing, the criminals reply with an email with malware contained in a link that appears to be a shipping document or contract. When the legitimate trucking company clicks on the link, remote monitoring and management (FMM) software is surreptitiously installed on the legitimate trucking company’s computer thereby giving the criminal full access to the legitimate company’s computer network enabling them to pose as the legitimate company and bid on deliveries or to pose as the legitimate company and send emails that appear to be from the legitimate company related to already contracted deliveries. The criminals invade the supply chain so that even when a truck is dispatched for a legitimate load, as happened in this particular bourbon heist, the criminals make sure they get there first. The thieves show up with trucks bearing the markings of the legitimate companies they pose as and pick up the items to be delivered. Once the loaded trucks leave the warehouse, they disable the GPS tracking used in shipments Cybersecurity company Proofpoint issued a report in November of 2025 that details precisely how these thefts are accomplished.

It has been hypothesized that more traditional organized crime rings that may have hijacked trucks in the past are partnering up with new cybercriminals who are in effect the IT department for the older crime gangs.

Testifying before the House Judiciary subcommittee, Chris Spear, the President of the American Trucking Associations said, “Straight theft has been around since trucks have been on the road. It involves the physical theft of cargo from a distribution center of the back of a truck.” However, noting the evolution of this crime, he told the committee “Strategic theft involves the use of advanced cyber tactics to trick shippers, brokers, and carriers, to divert and hand over loads. This high-tech form, cargo theft has become a digital Renaissance for thieves, surging 1,500% since 2021.”

Combating this new partnership of organized crime trucking hijackers and cybercriminals will require close collaboration between law enforcement, government agencies and the commercial trucking industry. In 2022 the Department of Homeland Security launched Operation Boiling Point (particularly appropriate for the lobster heist) to combat organized crime groups involved with cargo thefts and organized retail crime through such collaboration. However, as evidenced by cargo thefts such as the recent bourbon theft, there remains a lot of work to do.