blog

Your cargo. Not your carrier.

July 15, 2025. A warehouse in Worcester, Massachusetts. A truck pulls up to the loading dock. The driver has the order, the reference number, and everything matches the appointment. He loads 33,750 pounds (approx. 15.3 tons) of frozen snow crab, worth about $325,000, and drives off toward Jacksonville, Florida. The crab never arrived.

Before the truck reached the loading dock

A few days earlier, according to court documents, someone hacked into the email account of a real, operating trucking company. Let’s call it Carrier 1, as in the case files. The person impersonating an employee of this company, using the compromised email address, contacted the freight forwarder and agreed to transport the goods to the client in Florida.

No one on the forwarder's side had any reason to doubt it. The email address was real. The company being impersonated actually existed, had a history, an MC number, and references.

On the day of pickup, another man, Romoy Forbes, arrived at the site, posing as an employee of Carrier 1. He loaded the goods and drove off—but not to Florida. The crab ended up at a grocery store in Queens, where the perpetrators photographed the delivery as proof for the next link in the supply chain.

Not just the crab

The investigation by the FBI and the Massachusetts prosecutor's office was broader in scope. According to the indictment, other intercepted shipments fit the same pattern: beer worth about $35,200, pallets of blueberries, and a shipment of designer perfumes and colognes worth over $430,000. In total, the stolen goods were worth over $800,000.

Forbes, a 31-year-old Jamaican national living in Deer Park, New York, has been charged with interstate transportation of stolen goods and conspiracy to commit this crime. The charge of interstate transportation of stolen goods carries a penalty of up to 10 years in prison; the conspiracy charge carries up to 5 years.

The case is pending before a federal court in Boston. As of the writing of this article, the trial has not concluded, and the defendant is presumed innocent until proven guilty by a final verdict.

The mechanism: stolen identity, not stolen goods

In the USA, this phenomenon has a name — double brokering — and it stems from the specifics of the local market: a broker takes a transport order and then resells it, sometimes without the principal's knowledge. In Poland and the EU, there is no layer of professional brokers acting as intermediaries like in the US. But the core of this case does not lie in American brokering. It lies in something much simpler and much more universal: the hijacking of an email account belonging to a real, trusted carrier.

You’ve seen this before in Dark Stories #8, regarding the German ghost-carrier case—where the difference between the real and fake company came down to a single letter in the email domain. Here, the mechanism is even more direct: the perpetrator doesn't even need to spoof a domain. It is enough to take over the login to a real, existing email account of a real carrier—via phishing, a password leak, or malware—and spend a week or two emailing shippers looking for transport on an exchange, posing as that carrier.

This is exactly the same scenario that could happen on any Polish or European freight exchange (Trans.eu, Timocom, and similar). Registration, verification of carrier documents, history of previous cooperation—all of this is based on the assumption that you are in control of the email address and account you are writing from. If someone else controls them, all other verification is meaningless—because from the shipper's point of view, they are dealing with the same known and trusted carrier as always.

The goods targeted by this mechanism in this and similar cases are no coincidence: premium food, beverages, and cosmetics. Easily resold and difficult to trace after being sold on, they vanish from the market before anyone can react.

What this means for Polish freight forwarders and shippers

Four conclusions from this case apply directly to Polish practice, regardless of the differences in business models between the US and Polish markets.

  • First: a trusted email contact is not the same as a verified one. The address you have been corresponding with for months can be hijacked at any moment—and the reply will come from that same address, in the same style, with the same signature in the footer.
  • Second: confirmation via a second channel is the only real protection against this scenario. A phone call to the number on the carrier's official website—not the one in the email signature—before releasing goods to a new or unusual subcontractor takes five minutes. Failing to make that call could cost you the entire value of the cargo.
  • Third: the loading dock and warehouse are your last line of defense. The driver arriving to pick up the goods should be verified on-site—personal details, vehicle registration numbers, and consistency with the booking—regardless of how convincing the email correspondence leading up to the pickup was.
  • Fourth: fast-moving consumer goods that are difficult to identify after sale — food, cosmetics, alcohol, electronics — are statistically the most frequent targets for this type of fraud, precisely because they disappear from the market before anyone can even start looking for them.

The moral

No one broke into anyone's warehouse. No one cut a tarpaulin. The goods left the loading dock legally, with documentation, in accordance with the booking—exactly as they should have. The difference between a delivery and a loss came down to who was actually sitting behind the keyboard that sent the pickup notification.

This text is based on indictments and official statements from the prosecutor's office. The presumption of innocence applies to the accused until a final verdict is reached.

Our previous articles in the "Dark Stories" series

  1. Why do we need FOB? - Dark Stories #1
  2. Really CIF? - Dark Stories #2
  3. Is EXW my shield? - Dark Stories #3
  4. A ticking time bomb in hold number 4 - Dark Stories #4
  5. To copper or not to copper? - Dark Stories #5
  6. Your container is intact. You’re still paying - Dark Stories #6
  7. DDP, really? — Dark Stories #7
  8. Fake carrier fraud - Dark Stories #8
  9. Not my truck, not my problem? — Dark Stories #9
  10. How a loose cable sank a bridge and cost the shipowner $2.25 billion - Dark Stories #10

Sources

Facts and legal status as of July 2026. Criminal proceedings are ongoing; no verdict has been reached.

Want to better plan your supply chain?
Our experts will help you select a transport solution tailored to your destination, cargo type, and operational priorities. Call us at  +48 720 803 853 or email us directly at biuro@insphera.pl.