Doppel Email Security is now generally available! | Register for the webinar to learn more
General

What Is Diversion Theft?

Diversion theft tricks a courier, carrier, or employee into redirecting a shipment, payment, or data to an attacker. Learn how it works, its types, and defenses.

Doppel TeamSecurity Experts
August 28, 2026
5 min read

Diversion theft is a social engineering attack (opens in new tab) in which an attacker impersonates a trusted party to trick a courier, carrier, or employee into redirecting a delivery, shipment, payment, or data transmission to a destination the attacker controls.

The technique appears in both offline freight schemes and online schemes that redirect confidential data (opens in new tab) and payments.

How diversion theft works

Diversion theft pairs impersonation with a pretext that makes the redirection sound routine, so the victim completes what looks like an authorized handoff. In the physical variant, a thief uses forged paperwork (opens in new tab) and stolen carrier credentials to persuade dock staff to release freight to an unauthorized driver, a deception-based method the FBI classifies as strategic cargo theft (opens in new tab).

The digital variant redirects money or data instead of pallets. Attackers compromise a vendor account (opens in new tab) and modify that vendor's bank account details so a legitimate payment instruction goes to the wrong place.

In one documented incident (opens in new tab), an attacker impersonating a vendor's CFO asked the City of Mansfield, Ohio to update the banking information for ACH payments; the finance department processed the change, and a payment for a legitimate invoice went to the fraudulent account.

Cyber techniques can also support physical cargo diversion in a single attack chain. In an April 2026 FBI advisory (opens in new tab), attackers compromise broker load board accounts, post fake loads, deliver remote monitoring and management (RMM) malware to carriers that bid on them, then use the hijacked accounts (opens in new tab) to bid on real loads and reroute cargo for resale.

Redirection can also happen mid-route, when a fraudulent dispatcher contacts a driver already hauling a legitimate load and reroutes it to a destination the attacker controls.

Why diversion theft matters

Strategic cargo theft relies on fraud and deception in the US freight market. Criminals can trick shippers, brokers, and carriers into surrendering loads without using force. They can run deception-based theft remotely (opens in new tab) at low personal risk, and cyber-enabled impersonation of legitimate brokers and carriers has been surging since 2024 (opens in new tab).

On the payment side, the recovery window is short (opens in new tab). Criminals often move diverted wire transfers into cryptocurrency wallets (opens in new tab) and disperse the funds quickly. Diverted payments can also create disputes over responsibility and insurance coverage (opens in new tab), including whether policies cover losses from vendor impersonation (opens in new tab).

Because these schemes rely on impersonation, AI-generated content can weaken the familiar voice and writing cues employees watch for. Attackers use AI-generated emails (opens in new tab) and deepfake voices (opens in new tab) to make impersonation more convincing. The primary defense is process controls (opens in new tab).

Types of diversion theft

Different industries use different names for diversion theft based on the asset attackers redirect.

The major variants of diversion theft are:

  • Fictitious pickup. Using a carrier's stolen identity and falsified shipping documents, the criminal takes custody of freight from warehouse staff and removes it before they notice the deception.
  • Carrier identity theft. Criminals use another motor carrier's assigned USDOT number (opens in new tab) or a hijacked FMCSA account to secure loads under a stolen identity, then divert the shipment.
  • Fraudulent double brokering. An imposter carrier wins a load, re-brokers it (opens in new tab) to an unwitting legitimate carrier, and instructs that carrier to divert the delivery to another location.
  • Payment redirection. A compromised or spoofed vendor email account requests a change to bank details (opens in new tab), sending vendor payments, payroll, or wire transfers to attacker-controlled accounts.
  • Purchase order fraud. An attacker impersonates a legitimate organization, issues a purchase order (opens in new tab) for high-value goods such as laptops, and directs the shipment to a location the attacker controls.

How to defend against diversion theft

Effective diversion-theft controls focus on the same weak point: the unverified change request.

  1. Verify every change out of band. Call previously known numbers (opens in new tab) rather than the number in the request, and maintain a file of authorized vendor contacts, preferably in non-electronic form.
  2. Require dual authorization. Add a secondary sign-off for changes to vendor payment location, and limit the number of employees who can approve wire transfers.
  3. Vet carriers at the point of pickup. Confirm driver and truck (opens in new tab) identity, release pickup numbers only after verifying the DOT/MC number on the truck, and watch for bill of lading red flags (opens in new tab) such as a late destination change or a delivery contact swapped to a personal cell number.
  4. Monitor for impersonation infrastructure. Register domain variants (opens in new tab) close to your own, flag emails where the reply address differs (opens in new tab) from the sender, and enforce DMARC (opens in new tab) with SPF and DKIM to reduce email spoofing.
  5. Train employees on redirection pretexts. Treat urgency, secrecy, and last-minute changes (opens in new tab) to wiring instructions or delivery details as triggers to slow down and verify.

How Doppel helps

Process controls catch a bad request once it reaches an employee; the impersonation infrastructure staged ahead of that request needs separate coverage.

Doppel is the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection and Human Risk Management, detecting malicious assets across domains, social platforms, paid ads, and messaging apps, then dismantling the impersonation infrastructure (opens in new tab) connecting them. These assets include lookalike domains (opens in new tab), spoofed email senders, fake websites, and fraudulent profiles (opens in new tab).

The Doppel Threat Graph links isolated signals into a campaign-level view (opens in new tab) of the operation behind a redirection scheme. The platform's agentic AI (opens in new tab) correlates and prioritizes threats and executes takedowns at scale, leaving analysts to handle complex escalations.

Simulation turns detected threats into employee training campaigns (opens in new tab) that test accounts payable teams and dispatchers against active bank-change and redirect pretexts. See the Threat Graph and agentic AI map and dismantle the operation targeting your brand. Request a demo (opens in new tab) to get started.

Frequently asked questions about diversion theft

What is diversion theft?

Diversion theft is a social engineering technique in which an attacker impersonates a trusted carrier, vendor, or executive, then redirects a shipment or payment, and in some cases a data transmission, to a destination the attacker controls. It appears as a distinct named type of social engineering in security literature (opens in new tab) and peer-reviewed surveys (opens in new tab), alongside phishing, pretexting, and baiting. It operates across physical deliveries, email, load boards, and voice channels.

What is diversion theft in cybersecurity?

In cybersecurity, diversion theft describes tricking a victim into sending confidential data or funds to the wrong recipient, usually through a spoofed email address (opens in new tab) that appears to belong to a trusted organization such as a bank or auditing firm. It frequently overlaps with business email compromise (opens in new tab), where a compromised or impersonated account requests a change to payment details. Fully cyber-enabled versions also target physical goods: these attack chains begin with compromised load board accounts and remote-access malware and end with a truckload of freight rerouted for resale.

What is the difference between diversion theft and business email compromise (BEC)?

Business email compromise (opens in new tab) is a scam in which criminals use a spoofed or compromised email account to pose as a trusted figure and request an unauthorized transfer of funds. Diversion theft is the broader attack pattern defined by redirection, and it covers physical shipments and data transmissions as well as payments. The two overlap heavily in practice: payment diversion is one of the most common outcomes of a BEC attack, and vendor email compromise, where an attacker hijacks a supplier's account to change bank details on invoices, belongs to both categories.

What is an example of diversion theft?

In June 2026, the Manhattan District Attorney indicted eight defendants (opens in new tab) for impersonating shipping carriers in a multi-state retail theft ring. Prosecutors allege the group used real carriers' names and registration numbers to pose as legitimate carriers and brokers, made fraudulent pickups at logistics sites in Pennsylvania, Virginia, and New Jersey, and diverted roughly $4.49 million (opens in new tab) in cargo, including meat, cheese, and cigarettes, for resale on the black market.

Last updated: August 28, 2026

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.