
Key takeaways
Business email compromise and cargo theft now share one entry point: a compromised inbox, not the loading dock.
Attackers use a hijacked mailbox for fictitious pickups, shipment misdirection, and payment diversion.
Life science freight is a prime target because it is high value, compact, and often time and temperature sensitive.
Most of the fix sits in your email platform and change process: phishing-resistant MFA, mailbox rule alerts, DMARC enforcement, and out-of-band verification.
If a mailbox is compromised, reset access, remove unknown rules, and call carriers and partners to hold pending changes.
Business email compromise and cargo theft used to belong to different departments. One was an IT problem and the other was a security and logistics problem. For life science shippers, they have become the same problem, and it usually starts in an inbox rather than on a loading dock.
The numbers show why. Verisk CargoNet recorded 677 supply chain theft incidents across the United States and Canada in the second quarter, down 26 percent from a year earlier. Estimated losses still more than doubled to about $304.6 million (Verisk CargoNet, Q2 2026).
Fictitious pickups, where a thief poses as a legitimate carrier and drives away with a loaded trailer, barely moved: 158 incidents, against 165 the year before. CargoNet identified business email compromise as the primary access point for many of the quarter's most sophisticated schemes.
In other words, thieves are stealing less often and choosing their targets better. A compromised mailbox is how they choose.
How Business Email Compromise and Cargo Theft Connect
Business email compromise is rarely a dramatic break-in. It typically begins with a phishing email or a reused password on an account with no second factor. Once inside, the attacker usually does not act right away. They read.
A shipping coordinator's mailbox is a detailed map of what moves, when, and with whom. It holds pickup appointments, bills of lading, carrier and broker contacts, and the tone of every routine conversation. With that map, an attacker has three plays available:
Fictitious pickup. The attacker learns when a high-value load is scheduled and sends an impostor driver with credentials built to look right at the dock.
Shipment misdirection. A message from a real address, inside a real thread, asks for a late change to the delivery address or consignee.
Payment diversion. An invoice arrives with new remit-to bank details, and the next freight payment goes to the attacker.
None of these requires breaking anything. The attacker replies inside a conversation your team already trusts, which is why dock checks and carrier vetting alone keep missing it.
Why Life Science Freight Is a Target
Insurance broker WTW lists pharmaceuticals among the primary targets for fictitious pickups, fraud, and double brokering, alongside electronics and other high-value goods (WTW). Life science shipments carry high value in a small footprint, and many are time and temperature sensitive.
That combination creates exactly the pressure attackers want. A message marked urgent about a cold chain shipment gets acted on quickly, and a verification call can feel like a risk to the product. Clinical trial material raises the stakes further, because some of it cannot simply be reordered.
What Life Science Shippers Should Lock Down
The controls that stop this sit mostly in your email platform and your change process, not on the dock. Whether you run Microsoft 365 or Google Workspace, each of the following is achievable without new infrastructure.
1. Phishing-resistant MFA on every mailbox
Start with the accounts that see shipments and money: shipping and receiving, customer service, accounts payable, and every administrator. Prefer number-matching authenticator apps, passkeys, or hardware security keys over text-message codes, which can be intercepted or talked out of a user.
Then block legacy sign-in protocols that skip MFA entirely. An account protected by MFA everywhere except one old protocol is not protected.
2. Watch for the rules attackers leave behind
Attackers who plan to stay usually create mailbox rules. One forwards copies of mail to an outside address. Another quietly moves replies containing words like pickup, BOL, or invoice so the real owner never sees them.
Disable automatic forwarding to external addresses by default, alert on newly created inbox rules, and review sign-in activity for logins from unexpected locations. These are standard admin settings and they catch compromises that a password reset alone would miss.
3. Put your domain's email authentication at enforcement
SPF, DKIM, and DMARC let receiving mail servers confirm that a message claiming to come from your domain really did. A DMARC policy left at monitoring only does not stop anyone from sending as you to your carriers and brokers. Move it to quarantine or reject once your legitimate senders are accounted for.
Then watch for lookalike domains one character off from yours and tag messages from external senders so staff notice when a familiar name arrives from an unfamiliar address.
4. Verify every change out of band
Any change to a pickup time, carrier, driver, delivery address, consignee, or bank details gets confirmed by phone, using a number already on file, never a number from the message requesting the change.
Require two people to approve changes to payment details. Release freight only to the driver and equipment details confirmed in advance, and treat a last-minute driver swap as a stop-and-call event rather than a routine update.
5. Shrink who can see the schedule
Every person and system with access to shipment schedules is a possible entry point. Replace shared logins on carrier portals and booking tools with named accounts that require MFA.
Trim distribution lists that copy pickup confirmations to people who do not need them. Remove access the same day someone leaves, including portal accounts that are easy to forget because they sit outside your email system.
6. Train the people attackers actually target
Generic annual training does little for a receiving clerk handed a convincing pickup order at 4:45 on a Friday. Focus awareness training on the roles in the line of fire. Run an annual tabletop exercise that walks through a fictitious pickup from first email to released trailer. Practicing the verification call once makes it far easier to insist on it under pressure.
7. Read your cargo policy for cyber exclusions
WTW notes that many cargo policies carry cyber exclusions, including versions of the LMA5403 clause, that could limit coverage when a theft is deemed to arise from a cyber event. A fictitious pickup that began with a spoofed email may sit right on that line. Ask your broker how your underwriter would treat it before you need to file a claim.
Your Logistics Partner Is Part of the Control
Your own controls work best alongside a logistics partner that treats verification as part of the service. Ask your provider how they confirm change requests, who is authorized to make them on your account, and how quickly they flag an exception.
Partners such as Mercury, which pair real-time shipment visibility with proactive monitoring, give you a second signal that something is wrong while freight is still recoverable, rather than after a claim is the only option left.
If You Suspect a Mailbox Has Been Compromised
Move quickly, and in this order:
Reset the password and revoke all active sessions, so an attacker who is already signed in is pushed out.
Check the account's MFA methods and remove any device or phone number you do not recognize.
Delete unknown inbox rules and any forwarding to outside addresses.
Review sent items and recent threads for messages issued in the user's name, especially anything about pickups, addresses, or payments.
Call your carriers, brokers, and logistics partner to hold pending changes until they are verified.
Preserve sign-in and mailbox audit logs, and notify your insurer as your policy requires.
The Same Playbook Across Healthcare
None of these controls are unique to logistics. At IT Total Care, we put the same layered email security controls in place for home health and home care agencies, where a compromised scheduler's inbox can redirect caregiver payroll or patient information the same way a compromised shipping inbox redirects freight. The target changes from industry to industry. The entry point does not.
For life science shippers, the lesson from the latest data is straightforward. Business email compromise and cargo theft now run through the same doorway, and closing it is an IT task as much as a security one. Lock down the inbox, verify every change through a channel the attacker cannot reach, and the most convincing pickup order in the world becomes just another email.
Want a logistics partner that gives you that second signal? Contact Us to talk with Mercury's team about protecting your life science shipments from pickup to delivery.
About the Author
Brendan Duebner is President of IT Total Care, a veteran-owned managed IT and cybersecurity provider based in Foster City, California. IT Total Care secures email, devices, and data for healthcare organizations across the San Francisco Bay Area, with a focus on home care, home health, and hospice agencies.
Start shipping today!
Start your shipment now — no login required. Fast, secure, and guided by experts.



