How did we get here?
Freight logistics is quite a fragmented industry. From the production line all the way to consumers or customers, there are generally multiple parties in the mix to get goods from point A to point B. At a high level, transportation of goods does not seem overly complex. Maybe it’s a warehouse or the production facility; a truck shows up, loads the goods and transports them to the store. However, the reality is, complexity is quite high. This includes inventory systems, brokers and their systems, bills of lading, payment systems, vehicle telematics and of course a ton of data and the goods themselves. Freight logistics, and logistics more broadly, have been heavily paper-based but had to innovate and move operations and their data online. However, controls, governance and security gates have traditionally been de-prioritized. Shipping goods is a cost center, and the goal is to keep costs low. Well, the bad guys have noticed.
Think about it this way: I could try to walk into a store with mounted security cameras, security guards standing at the doors, locked shelves and try to steal whatever is behind that locked shelf and risk being caught — or I can exploit a transportation management system, divert an entire truckload and completely cover my tracks for a much bigger payday with arguably less immediate risk. Or even better, pin it on someone else. Just to prove how lucrative this scheme is, instead of breaking into a car to steal it, thieves went after a transporter to steal NBA legend Shaquille O’Neal’s Range Rover during transport. It takes coordination and planning to get that done, and apparently a compromised transporter.
How hackers get the goods
Generally, just like with every compromise, attackers look for the easiest way in. However, certain patterns are emerging of how the perpetrators are accomplishing these heists, which include business email compromise (BEC), identity theft/carrier impersonation, load board hacks and freight redirection and Electronic Bill of Lading (eBOL) tampering. As previously mentioned, there are many handoffs and parties involved in the logistics process. Each handoff, or trust boundary if you’re thinking in terms of a threat model, carries risks and has potential vulnerabilities that a threat actor could exploit. What we also see is that carriers (transporters) have large, varying degrees of cybersecurity maturity, generally no requirements for standardization and often not sufficient resources to defend against increasingly complex cyberattacks.


