Freight forwarders face six specific cyber threats in 2026: business email compromise (BEC), rate manipulation via phishing, ransomware on ops systems, vendor supply chain attacks, data exfiltration of trade partner records, and account takeover on carrier portals. The defenses that actually cut loss (in order of impact) are MFA on every ops system and email, DMARC / SPF / DKIM, quarterly phishing simulation, endpoint detection and response (EDR), immutable 3-2-1 backups, least privilege access reviews, vendor security due diligence, an incident response plan with tabletop exercises, cyber insurance sized to your revenue and shipment volume, and a documented FMS and SaaS vendor security posture review. This guide walks through each threat with a freight forwarding example, ranks the defenses by real world impact, catalogues the verified incidents you can point to when the board or the insurer asks, and gives you the exact questions to ask your freight management software (FMS) vendor about security.
Freight forwarders sit at three intersections that attackers value. First, money moves through the forwarder: customer prepayments for ocean or air freight, carrier disbursements, duty and tax remittances to CBP and other authorities, and third party charges (drayage, warehousing, chassis, demurrage) that the forwarder collects and pays on behalf of the shipper. A single fraudulent wire instruction inside a normal rate email can move six or seven figures before anyone notices.
Second, forwarders hold personal and commercial data: importer of record details, consignee names and addresses, sometimes passport numbers and driver license scans for customs filings, and the full commercial invoice and packing list for every shipment. This is trade data that criminal buyers pay for and that state aligned actors want for supply chain intelligence.
Third, forwarders are trusted vendors inside their customers' supply chains. A compromised forwarder is a way into a Fortune 500 shipper's booking system, PO data, and vendor payment flow. Enterprise shippers now treat cyber posture at their forwarder as a procurement gate; a forwarder who fails a security review loses the account regardless of rate or service.
The combination (money, data, and supply chain access) is why freight forwarders now sit inside the same threat model as banks and hospitals, without the security budgets those industries carry.
Attacker sends a spoofed or hijacked email that looks like a normal shipper or carrier instruction, then asks the forwarder to update payment details, release cargo, or approve a rate change. The email usually lands during a high pressure moment (peak season, a vessel roll, a late Friday cutoff) so the ops or finance team acts without a phone verification. Losses from BEC in freight forwarding often exceed ransomware losses because the money moves inside a normal transaction.
Watch out
A single fraudulent wire instruction inside a normal rate email can move six or seven figures before anyone notices. BEC and rate manipulation quietly cost freight forwarders more per year than ransomware because the fraud lands inside a normal transaction and often takes weeks or months to surface in a customer audit.
Attacker phishes a rate desk credential (rate manager, ops manager, or accounting), then either modifies rates inside the FMS or inserts fraudulent surcharges on customer invoices. This is quieter than BEC because the loss is spread across many invoices and often gets missed until a customer audit or a periodic rate review. It is one of the fastest growing attack patterns against mid market forwarders in 2025 to 2026.
Attacker encrypts the forwarder's ops systems (FMS, accounting, file server, customs system) and demands payment. The direct extortion is only part of the loss; the operational shutdown (unable to book, quote, invoice, or file entries) drives customer switching, contractual penalties, and cargo loss during the encryption window. Expeditors International (February 2022) is the most fully disclosed freight forwarding example; CMA CGM (September 2020) is the most fully disclosed carrier example.
Attacker compromises a software vendor, a managed service provider, or an integration partner and rides that trusted relationship into your systems. The 2020 SolarWinds and 2021 Kaseya patterns showed how quickly a single vendor compromise can reach hundreds of downstream customers. For a forwarder in 2026, the highest risk vendor tiers are your FMS, your accounting system, your customs filing system, your rate management engine, and any managed IT provider that holds domain admin.
Attacker gets into the FMS or file store and copies out commercial invoices, packing lists, importer of record data, and shipper price sheets. The stolen data is sold, used to impersonate the shipper in downstream BEC attacks, or held over the forwarder as a secondary extortion lever ("pay or we publish your customer contracts"). Double extortion (encrypt plus exfil) is the dominant ransomware model since 2022.
Attacker takes over the forwarder's login on a carrier portal (CMA CGM eBusiness, Maersk MyMaersk, Hapag-Lloyd Online Business Suite, MSC MYMSC, and so on) and books cargo, changes shipping instructions, or reroutes containers. This is a category that most forwarders do not track as a cyber loss because it presents as a booking error, but the underlying cause is credential compromise on an external portal that shares a password with the forwarder's email.
The ranking below is by real world loss reduction for freight forwarders, not by IT audit checklist order. Do them in this order.
Watch out
A backup that a domain admin can delete is not a ransomware defence. Modern ransomware tooling looks for backup shares as its first move after credential escalation, and a nightly job that overwrites the same NAS folder is a single command away from being wiped. At least one copy must be immutable (write once, no admin delete) or the restore path does not survive the attack.
For the ops and finance side, a modern platform that centralises bookings, rates, and invoicing in one place also collapses the number of systems on the audit surface. Fewer disconnected surfaces means fewer credentials to phish and fewer file stores to exfiltrate. See how Shipment Tracking and Operations Software for Forwarders and Freight Billing and Accounting Software for Forwarders consolidate operational data into a single audited platform.
The incidents below are all publicly disclosed by the affected company or by primary regulatory filings. They are the ones you can safely cite in a board memo or a customer security review.
These four incidents cover the full spectrum: global carrier wiper (Maersk), carrier ransomware (CMA CGM), forwarder ransomware (Expeditors), and terminal operator shutdown (DP World). If your board asks "does this happen to companies like us?", these are the four names to name.
Cyber insurance is now table stakes for a forwarder above roughly 20 million USD in annual revenue, and increasingly for smaller shops when enterprise customers require it in the vendor questionnaire. Coverage areas that matter for freight forwarders:
Most 2026 carriers require MFA, EDR on all endpoints, backups tested annually, and a documented incident response plan as pre conditions. If you cannot answer yes to those four, expect either a declined renewal or a 30 to 60 percent premium increase.
Every FMS vendor should be able to answer these ten questions in writing. Send them at RFP and at every renewal.
Score the answers on a red / amber / green rubric and file them in the vendor register. Repeat annually.
One control is worth naming because it is the one integration teams get wrong most often. GoFreight signs outbound webhooks with HMAC-SHA256 and a signed timestamp for replay mitigation, and integration partners are expected to verify that signature before acting on the payload. An unverified webhook endpoint is an open write path into your operational data, whatever the rest of the stack looks like.
For the rest of the posture, run the same questionnaire you would run on any vendor. Ask GoFreight for its current security pack covering certification status, MFA enforcement, encryption at rest and in transit, SSO and SAML availability by plan tier, penetration testing cadence, data residency options, the incident notification SLA written into your contract, and the data deletion policy on account closure. Score the answers on the same rubric as every other vendor and file them in the register.
Consolidating booking, rate, invoicing, and customer portal data on a single audited platform also reduces the number of credentials, file stores, and integrations an attacker has to work through. See the Customer Portal and Freight Billing and Accounting product surfaces for how that consolidation lands operationally.
Ship Faster. Scale Smarter.
See how GoFreight consolidates bookings, rates, invoicing, and customer visibility on one audited platform, so your cyber posture improves at the same time your operations get faster.
What are the top cyber threats freight forwarders face in 2026?
Freight forwarders face six specific threats in 2026: business email compromise (BEC), rate manipulation via phishing, ransomware on operations systems, vendor supply chain attacks, data exfiltration of trade partner records, and account takeover on carrier portals. BEC and rate manipulation are quieter than ransomware and often move more money over a full year, because the fraud lands inside a normal rate email or a normal payment instruction and takes weeks or months to detect.
Why are freight forwarders such attractive cyber targets?
Freight forwarders sit at three intersections attackers value: money moves through the forwarder (customer prepayments, carrier disbursements, duty and tax remittances), personal and commercial data lives in the FMS (importer of record, consignee, sometimes passport), and the forwarder is a trusted vendor inside enterprise supply chains. A compromised forwarder is also a way into the shipper's booking, PO, and vendor payment flow, which is why enterprise shippers now treat forwarder cyber posture as a procurement gate.
What is business email compromise (BEC) in freight forwarding?
BEC is a fraud pattern where an attacker sends a spoofed or hijacked email that looks like a normal shipper or carrier instruction and asks the forwarder to change payment details, approve a rate change, or release cargo. In freight forwarding, BEC usually lands during a high pressure moment (peak season, a vessel roll, a late Friday cutoff) so the ops or finance team acts without a phone verification. Total BEC losses in freight forwarding often exceed ransomware losses because the money moves inside a normal transaction.
How does rate manipulation via phishing work?
An attacker phishes a rate desk credential (rate manager, ops manager, accounting) and then either modifies rates inside the FMS or inserts fraudulent surcharges on customer invoices. Because the loss is spread across many invoices, it typically gets missed until a customer audit or a periodic rate review. Rate manipulation is one of the fastest growing attack patterns against mid market freight forwarders in 2025 to 2026.
Does GoFreight enforce MFA and how does it protect customer data?
GoFreight signs outbound webhooks with HMAC-SHA256 and a signed timestamp to prevent replay attacks, which is confirmed from client documentation. MFA enforcement on the GoFreight platform, encryption at rest and in transit, SSO / SAML availability, SOC 2 Type II, and ISO 27001 status are being confirmed with the GoFreight product and security teams and will be updated in this article once the client verifies each item.
What is the 3-2-1 backup rule and why does it matter for freight ops?
The 3-2-1 rule is three copies of your data on two different media with one copy offsite. The 2026 update for ransomware resilience is that at least one copy must be immutable (write once, no admin delete) so an attacker who reaches domain admin cannot wipe the backups during the encryption phase. This is the difference between a ransomware event that stops the business and one that becomes a restore project.
How much cyber insurance does a mid sized freight forwarder need?
Coverage depends on revenue, shipment volume, and customer mix. A general starting point for a 20 to 100 million USD revenue forwarder is a policy that includes explicit BEC and social engineering fraud coverage, ransomware and business interruption, third party liability, regulatory response, and contingent business interruption for vendor incidents. Most 2026 carriers require MFA, EDR on all endpoints, tested backups, and a documented incident response plan as pre conditions.
What security questions should I ask an FMS vendor?
Send the same ten questions to every FMS vendor at RFP and at every renewal: current SOC 2 Type II availability, ISO 27001 status, encryption at rest and in transit, MFA enforcement on admin access, SSO / SAML availability and cost, penetration testing cadence, incident notification SLA to customers, data residency options, webhook and API signing, and data deletion policy on account closure. Score the answers on a red / amber / green rubric and file them in your vendor register.
What is DMARC and does my forwarding company need it?
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a policy that tells receiving mail servers what to do with email that claims to be from your domain but fails SPF or DKIM alignment. Set to p=reject once alignment is clean, DMARC stops attackers from spoofing your own domain in a BEC attack against your customers. Every freight forwarder should have SPF, DKIM, and DMARC at enforce; this is one of the highest impact, lowest cost cyber controls available in 2026.
What should be in a freight forwarder incident response plan?
A one page runbook covering: who calls whom in the first 30 minutes (CEO, COO, IT lead, insurance broker, outside counsel), how ops continues to book and invoice if the FMS is offline (paper backup or vendor failover), how finance stops outbound wires during the containment window, how customers are notified and by whom, and where the offsite immutable backups live and who has the restore rights. Rehearse it in one tabletop per year. The plan matters less than the fact that ops and finance have walked through the first 90 minutes.
How often should phishing simulations run?
Quarterly against every user, with a short training module (five to ten minutes) for anyone who clicks. Monthly is unnecessary friction and drives click fatigue. Annual is too slow to bend the click through rate downward. Quarterly is the cadence that most managed security service providers see the fastest year over year improvement on for logistics and freight forwarding customers.