For transportation cybersecurity, AI isn’t helping fight..so far

AI is accelerating cybercriminal capabilities in freight/logistics — deepfakes, polished phishing, and AI-scraped company data are enabling ransomware campaigns costing victims millions. No defensive AI tools exist yet to counter these threats.
As logistics becomes more digitized, ecommerce brands face cascading risk: a compromised carrier or broker can delay inventory, trigger stockouts, and crush marketplace rankings — this is supply chain fragility meeting cybersecurity reality.
Ecommerce brands using 3PLs, freight brokers, or carriers are one spoofed email away from a supply chain disruption that halts fulfillment. Audit which internal employees have public LinkedIn profiles tied to your brand's logistics operations — those are now active targets.
Operational Impact
This story may require teams to revisit workflows, monitoring, or platform assumptions.
Bottom Line
AI-powered freight fraud is live — your 3PL relationship is the attack vector.
Source Lens
Industry Context
Useful background context, but lower-priority than direct platform, community, or operator intelligence.
Impact Level
medium
AI-powered freight fraud is live — your 3PL relationship is the attack vector.
Key Stat / Trigger
$100,000 deepfake campaign investment returning millions in ransomware payments
Focus on the operational implication, not just the headline.
Full Coverage
Long Beach, California–At the only known conference related to cybersecurity in the freight industry, there wasn’t much discussion here of AI as a tool that can be used to fight cyber crooks.
Instead, during the first half of day one of the cybersecurity conference sponsored by the National Motor Freight Transport Association (NMFTA), the trade group servicing the LTL industry, the topic of AI was either not discussed at great length or came with a warning that the bad guys are going to use it, making an ongoing battle even tougher.
What wasn’t heard were statements along the lines of “hey, there’s this one company that has built this great AI-powered tool to protect cybersecurity and fight freight fraud.”
The presentation by James McQuiggan, the advisory chief information security officer at Apparent Security, was more an example of how the cybersecurity industry is approaching AI, seeing it as a foe rather than an asset, at least at this point.
The dark side When McQuiggan was introduced, it was to say that “he’s going to be talking about the dark side of AI, how cybercriminals use it for their purposes.” And that was what he spoke about, with no reference to any tools–yet–that might help the cybersecurity teams fend off intruders looking to crash a system and take it hostage.
McGuiggan made presentations of “deepfakes” stealing voices and appearances, using AI to produce the deceptions. “We’ve been playing around with large language models and agentic AI now for the last four plus years, and cybercriminals are doing the same thing,” McGuiggan said. And that’s important.
McGuiggan said AI can create cybersecurity vulnerabilities not just from an outsider successfully hacking a company, whether driven by AI or not, but through internal use of an AI tool that goes awry. McGuiggan referred to it as “shadow AI.” “You know that your users are going to be leveraging AI capability,” McGuiggan said. “They want to.
They’re not doing it to be malicious. They’re doing it because they want to be more efficient.” But he added that the internal users need to be educated on the risks their use of AI in a company setting can do to raise the risks for a successful outside attack.
LinkedIn still a problem At the 2025 edition of the NMFTA cybersecurity conference, one example of cybercriminals seeking access to a company that caught the attendees’ attention came from Todd Florence, the CIO of Estes Express, who said outside cybercriminals were setting up faked LinkedIn accounts featuring beautiful women, hoping an internal employee (presumably male) would seek to connect with them, hoping to meet them professionally…and then maybe personally.
McGuiggan’s reference to LinkedIn at this year’s conference was less lighthearted. And AI played a role. “It’s a lot easier with agentic AI to be able to go through and collect all the information that they need overall,” he said. “Cybercriminals are going through and scraping LinkedIn, your websites, people that work at your organization.
You know shippers and brokers, carriers, and if you’ve got fake ones that are being generated, you’re going to deal with a lot of fraud, deal with a lot of spoofed domains, all trying to make money.”
He contrasted the fraudulent emails that would arrive from cybercrooks just a few years ago, infamous for their frequent misspellings and bad grammar, with what is coming off an LLM today. Today’s output has eliminated those errors and is highly polished, McGuiggan said.
“In the last couple of years, we’ve been hearing about agentic AI being able to leverage that, scheduling things for us, looking at our email and sending out responses,” McGuiggan said. Ransomware attacks are “fully leveraging AI,” he added.
What companies are up against, McGuiggan said, is a situation where a cybercriminal can invest as much as $100,000 on a deepfake campaign, and come back with a ransom payment in the millions. The NMFTA meeting is a relatively small gathering, but it is attended by people laser-focused on the issue.
Maybe they’re with a carrier; maybe they’re providing cybersecurity services to companies trying to figure out how not to be a mark. There are a range of government officials as well.
Melanie Padron, the vice president of strategic growth at IT Architeks, who works solely with transportation companies on cybersecurity issues, spelled out the five-point “cyber battle plan” she said IT Architeks undertakes with companies that are considering hiring their services. Melanie Padron addresses the NMFTA cybersecurity conference.
The plan touches on points she made in her presentation, and aligns with sort of a general “call to action” that has been the self-help theme at these recent meetings.
The plan: one, clearly identify the person at a company who owns cybersecurity (which isn’t always clear); two, determine the last time there was an independent cyber risk assessment; three, determine when the most recent incident response plan was studied; four, get a “full
Audit your team's LinkedIn exposure now: search your company name + 'logistics' or 'shipping' on LinkedIn — if employees list carrier/3PL relationships publicly, that data is being scraped and weaponized for fraud.
In the next 30 days, brief your ops and purchasing team on AI-polished phishing — the old 'bad grammar' signal is gone; verify any payment or routing change requests via a second channel, always.
Original Source
This briefing is based on reporting from Freightwaves. Use the original post for full primary-source context.
Style
Audience