The U.S. House recently passed the Combating Organized Retail Crime Act (CORCA) by a 348–60 vote, with the Association of American Railroads praising it as legislation "designed to combat sophisticated criminal networks targeting America's supply chains." The numbers behind that language are stark: major U.S. railroads alone reported more than 75,000 theft incidents valued at over $200 million in losses in 2025 — a more than 50% increase year-over-year. Travelers Insurance estimates $3.5 billion to $10 billion in annual losses in the U.S. and Canada.
Federal legislation is welcome. But it is reactive by nature. Enforcement tools, coordination centers, and federal grants do not retroactively fix your contracts, and they do not resolve loss allocation disputes between commercial parties who failed to address these scenarios in writing.
So what can shippers and logistics companies do right now — before a theft occurs, before a dispute lands in arbitration?
Start with the Carmack Amendment liability caps — 0.50 per pound, more, or no caps at all?
Most shipper-carrier and shipper-3PL agreements are signed on someone else's standard form, with liability caps designed to protect the other party The Carmack Amendment (49 U.S.C. § 14706) sets a federal floor for carrier liability on interstate shipments — but it also permits carriers to limit that liability, and most do. Shippers who leave declared value blank or accept a released value limitation in the carrier tariff cap their recovery at whatever that limitation states — often $0.50 per pound. For a 500-pound pallet of electronics worth $8,000, that means a maximum recovery of $250.
Motor carriers and freight forwarders should consider limiting their liability using the Carmack Amendment liability caps. They should also consider strengthening their defenses against liability (such as Acts of God, government action, shipper’s default and the like).
For shippers, if your contracts haven't been reviewed since rates spiked post-pandemic, there's a reasonable chance the liability language no longer reflects the actual value of what's moving. Shippers should review declared value clauses, per-shipment caps, and any language that shifts the burden of proof. If possible, removing the liability caps will be even better.
Fraud-specific duty of care vs. generic “reasonable care.”
Freight fraud — particularly double-brokering, identity spoofing, and fictitious pickup schemes — has surged to levels that make generic "reasonable care" language in broker agreements legally insufficient. Deceptive pickup schemes, where criminals use fake identities, forged credentials, and carrier impersonation to secure loads, jumped 31% year over year in Q1 2026 alone, with nearly half of those incidents occurring in California. The broader trend is worse: strategic theft has jumped 1,475% between Q1 2022 and Q4 2024, with double-brokering scams accounting for roughly half of all strategic cargo theft incidents. Fraudsters frequently use stolen, inactive, or "aged" Motor Carrier (MC) numbers to appear legitimate on load boards. In fact, Travelers Insurance notes that criminals are increasingly purchasing MC numbers in bulk to steal multiple shipments before authorities catch on.
Shippers’ contracts with brokers and 3PLs should expressly require carrier identity verification protocols: Federal Motor Carrier Safety Administration (FMCSA) authority confirmation, cross-referencing MC numbers against phone numbers and addresses, and prohibition on re-brokering without written consent. Turning operational best practices into contractual duties will ensure that when a broker tenders the freight to a fraudulent carrier, this can be treated as breach of contract, not merely an error in judgment.
Turn operational visibility into contractual obligation and add data breach protections
Manufacturers, suppliers, and distributors depend on real-time access to shipment data controlled by their carriers or logistics providers.
Consider requiring in your agreements event-based shipment tracking with defined update intervals; incident notification windows; access to carrier GPS and telematics data upon request; and document preservation obligations that activate on loss or delay. At the same time, cargo theft increasingly follows data theft. Since at least 2024, cyber threat actors have gained unauthorized access to the computer systems of freight brokers and carriers — typically via spoofed emails, fake URLs, and compromised carrier accounts — then deceive shippers, brokers, and carriers into handing over goods.
Bad actors alter the compromised carrier's registration details with the FMCSA and update insurance records, meaning legitimate companies often do not discover they have been compromised until brokers report missing shipments booked in their name.
A shipper whose logistics provider is breached faces a layered dispute: who bears the cargo loss, and who bears liability for the data exposure that enabled it? The logistics agreements should address cybersecurity obligations with specificity. What security standards is the provider required to maintain? What notification obligations apply in the event of a breach affecting shipment data? What indemnification flows from a data-enabled theft? These questions are not hypothetical. They are already arising in disputes.
Pay close attention to indemnification provisions
The indemnification language, "each party shall indemnify the other for losses arising from its own negligence," may be too generic in a cargo theft scenario involving a third-party criminal. Shippers need a language that addresses the specific fact patterns that generate losses: unauthorized re-brokering, failure to verify carrier identity, breach of chain-of-custody protocols, and theft occurring during unauthorized stops or deviations.
Improve operations and security to eliminate gaps
Parties on both sides should train their teams to recognize and avoid malfeasance risks.
The legislative moment is useful — but limited
CORCA will strengthen law enforcement tools, improve data sharing, and establish a national coordination center within Homeland Security Investigations to allow increased collaboration between federal, state, and local agencies. That matters. But the problem is not waiting for legislation — and despite substantial industry investments in security, only about one in ten theft attempts currently leads to an arrest.
The best time to prepare for supply chain theft is before it occurs. The second best time is now — with a review of the contracts governing your freight relationships and a realistic assessment of where they leave you exposed.
Federal legislation is welcome. But it is reactive by nature. Enforcement tools, coordination centers, and federal grants do not retroactively fix your contracts, and they do not resolve loss allocation disputes between commercial parties who failed to address these scenarios in writing.
So what can shippers and logistics companies do right now — before a theft occurs, before a dispute lands in arbitration?
Start with the Carmack Amendment liability caps — 0.50 per pound, more, or no caps at all?
Most shipper-carrier and shipper-3PL agreements are signed on someone else's standard form, with liability caps designed to protect the other party The Carmack Amendment (49 U.S.C. § 14706) sets a federal floor for carrier liability on interstate shipments — but it also permits carriers to limit that liability, and most do. Shippers who leave declared value blank or accept a released value limitation in the carrier tariff cap their recovery at whatever that limitation states — often $0.50 per pound. For a 500-pound pallet of electronics worth $8,000, that means a maximum recovery of $250.
Motor carriers and freight forwarders should consider limiting their liability using the Carmack Amendment liability caps. They should also consider strengthening their defenses against liability (such as Acts of God, government action, shipper’s default and the like).
For shippers, if your contracts haven't been reviewed since rates spiked post-pandemic, there's a reasonable chance the liability language no longer reflects the actual value of what's moving. Shippers should review declared value clauses, per-shipment caps, and any language that shifts the burden of proof. If possible, removing the liability caps will be even better.
Fraud-specific duty of care vs. generic “reasonable care.”
Freight fraud — particularly double-brokering, identity spoofing, and fictitious pickup schemes — has surged to levels that make generic "reasonable care" language in broker agreements legally insufficient. Deceptive pickup schemes, where criminals use fake identities, forged credentials, and carrier impersonation to secure loads, jumped 31% year over year in Q1 2026 alone, with nearly half of those incidents occurring in California. The broader trend is worse: strategic theft has jumped 1,475% between Q1 2022 and Q4 2024, with double-brokering scams accounting for roughly half of all strategic cargo theft incidents. Fraudsters frequently use stolen, inactive, or "aged" Motor Carrier (MC) numbers to appear legitimate on load boards. In fact, Travelers Insurance notes that criminals are increasingly purchasing MC numbers in bulk to steal multiple shipments before authorities catch on.
Shippers’ contracts with brokers and 3PLs should expressly require carrier identity verification protocols: Federal Motor Carrier Safety Administration (FMCSA) authority confirmation, cross-referencing MC numbers against phone numbers and addresses, and prohibition on re-brokering without written consent. Turning operational best practices into contractual duties will ensure that when a broker tenders the freight to a fraudulent carrier, this can be treated as breach of contract, not merely an error in judgment.
Turn operational visibility into contractual obligation and add data breach protections
Manufacturers, suppliers, and distributors depend on real-time access to shipment data controlled by their carriers or logistics providers.
Consider requiring in your agreements event-based shipment tracking with defined update intervals; incident notification windows; access to carrier GPS and telematics data upon request; and document preservation obligations that activate on loss or delay. At the same time, cargo theft increasingly follows data theft. Since at least 2024, cyber threat actors have gained unauthorized access to the computer systems of freight brokers and carriers — typically via spoofed emails, fake URLs, and compromised carrier accounts — then deceive shippers, brokers, and carriers into handing over goods.
Bad actors alter the compromised carrier's registration details with the FMCSA and update insurance records, meaning legitimate companies often do not discover they have been compromised until brokers report missing shipments booked in their name.
A shipper whose logistics provider is breached faces a layered dispute: who bears the cargo loss, and who bears liability for the data exposure that enabled it? The logistics agreements should address cybersecurity obligations with specificity. What security standards is the provider required to maintain? What notification obligations apply in the event of a breach affecting shipment data? What indemnification flows from a data-enabled theft? These questions are not hypothetical. They are already arising in disputes.
Pay close attention to indemnification provisions
The indemnification language, "each party shall indemnify the other for losses arising from its own negligence," may be too generic in a cargo theft scenario involving a third-party criminal. Shippers need a language that addresses the specific fact patterns that generate losses: unauthorized re-brokering, failure to verify carrier identity, breach of chain-of-custody protocols, and theft occurring during unauthorized stops or deviations.
Improve operations and security to eliminate gaps
Parties on both sides should train their teams to recognize and avoid malfeasance risks.
- Deep-Dive Verification: Don't just check if an MC number is active. Look for recent, suspicious changes in the Federal Motor Carrier Safety Administration (FMCSA) database—such as a sudden change in address, phone number, or a shift to a generic email provider for a company that has been operating for a decade.
- Continuous Monitoring: Vetting is not a one-and-done event. Implement automated onboarding platforms that continuously monitor your carrier network for plummeting safety ratings or sudden shifts in operational patterns.
- Zero-Trust Communication: Train your dispatch and warehouse teams to verify exactly who they are communicating with. Call the phone number registered in the FMCSA directory, not just the number at the bottom of an email signature.
- Cyber Hygiene: Mandate Multi-Factor Authentication (MFA) across your Transportation Management Systems (TMS) and load boards. Restricting who can view pickup numbers, facility details, and commodity types severely limits your attack surface.
- Strict Rerouting Protocols: Establish ironclad rules around rerouting freight. Any request from a driver or dispatcher to change the destination facility while in transit must trigger a rigorous internal approval process involving the shipper, the broker, and the consignee. Never approve a reroute based solely on an inbound phone call.
- Blind BOLs & Concealed Data: Limit the descriptive information on the Bill of Lading (BOL). Use internal reference numbers instead of explicitly stating that a trailer is full of high-value electronics, copper, or pharmaceuticals.
- Direct Telematics Integration: Rely on API integrations and GPS telematics directly from the driver's Electronic Logging Device (ELD) or a secure smartphone app. Real-time, unalterable location data is one of the strongest deterrents to "ghost shipments."
- Anti-Fraud Training: Conduct regular training for your teams on how to spot load phishing emails, fraudulent load board posts, and manipulation tactics used by organized crime rings. Empower your dock workers to turn away a driver if their paperwork, digital credentials, or demeanor don't match the expected profile—without fear of penalization for delaying a load.
The legislative moment is useful — but limited
CORCA will strengthen law enforcement tools, improve data sharing, and establish a national coordination center within Homeland Security Investigations to allow increased collaboration between federal, state, and local agencies. That matters. But the problem is not waiting for legislation — and despite substantial industry investments in security, only about one in ten theft attempts currently leads to an arrest.
The best time to prepare for supply chain theft is before it occurs. The second best time is now — with a review of the contracts governing your freight relationships and a realistic assessment of where they leave you exposed.
Subscribe to my LinkedIn Newsletter and never miss a good read!
Share this blog post
Disclaimer: This blog post is not legal advice. It is for informational purposes only. Reading this content does not create an attorney-client relationship. Consult with a licensed attorney to address your specific issues. Do not act upon this information without seeking professional legal counsel. IB Law Firm does not endorse any of the cited sources and is not responsible for the content of linked resources