The number of cargo thefts decreased sharply during the second quarter of this year, but the value of the goods stolen was up markedly.
That’s the key takeaway of a new assessment of supply chain thefts in the U.S. and Canada for the period of April, May and June. The analysis also found cargo thieves are refining thier tactics and changing their targets.
Verisk, a leading data analytics and technology provider to the global insurance industry, today released its second quarter cargo theft analysis based on findings from its CargoNet business, showing that while cargo theft incidents continued to decline, the financial impact of those crimes escalated sharply.
Verisk CargoNet said it documented 677 supply chain theft incidents across the United States and Canada in the second quarter, a 26% decline from the same period in 2025 and a 14% decrease from the previous quarter.
However, despite the lower number of incidents, total estimated cargo losses more than doubled year over year, reaching $304.6 million in the second quarter of 2026, up from $135.7 million in the same three months in 2025.
CargoNet said the average value among thefts with a reported commodity value reached $564,009, although that figure was heavily influenced by a small number of extreme, multimillion-dollar losses.
“Lower incident volume should not be mistaken for lower risk,” said Keith Lewis, vice president of operations at Verisk CargoNet. “The groups driving the largest losses are not necessarily trying to steal more freight; they are trying to identify the right shipment. Their focus on metals and enterprise technology shows how closely organized cargo theft now follows value, demand and resale opportunity.”
Non-Delivery and Physical Theft Decline, but Compromise-Based Schemes Persist
Verisk CargoNet’s analysis indicates the decline was driven in part by fewer non-delivery schemes in which cargo thieves acquired existing, reputable motor carriers, booked shipments under those companies’ established operating authorities and reputations, and picked up freight with no intent to deliver it.
CargoNet also recorded fewer organized thefts of unattended, loaded trailers and ocean containers.
The reductions were especially apparent in California and Texas. In both states, theft schemes involving business email compromise or shipment misdirection remained comparatively stable, while this form of non-delivery activity declined significantly.
CargoNet also recorded less organized activity targeting unattended, loaded equipment in major metropolitan areas such as South Florida and Dallas–Fort Worth.
The difference can also be seen in CargoNet’s incident classifications. Events classified as theft declined from 488 in Q2 2025 to 378 in Q2 2026, while fictitious pickup incidents fell only slightly, from 165 to 158 events.
Metals and High-End Technology Remain Priority Targets
The decline in theft activity was not evenly distributed across commodity categories.
Metal theft increased by 26 events, rising from 54 incidents in Q2 2025 to 80 in Q2 2026. Copper remained the most frequently targeted metal, while thefts involving aluminum, nickel, tungsten and other specialized industrial metals also increased.
Organized groups also continued targeting enterprise-grade computer and networking equipment, components and cryptocurrency mining hardware. These shipments may be worth several million dollars but frequently move through the supply chain as conventional dry freight, creating a significant mismatch between their financial value and their ordinary transportation and security profile.
Food and beverage theft declined overall. Thefts involving alcoholic and non-alcoholic beverages and mixed grocery products collectively fell by 36 events, while seafood theft moved in the opposite direction, increasing by 11 events.
CargoNet also recorded substantial decreases in thefts of auto parts and tires, along with fewer thefts involving supplements, protein products and over-the-counter medications.
Business Email Compromise Remains a Primary Threat
Business email compromise remained the primary access point for many of the quarter’s most sophisticated cargo theft schemes.
CargoNet said compromised accounts can provide criminals with access to shipment information, communication systems, contact directories and transportation management tools. That access may enable them to identify high-value shipments, impersonate trusted parties and alter shipment details while appearing legitimate to brokers, carriers, shippers and receivers.
The company also said it continues to see organized groups expand what they can obtain from a single compromised account, turning access to one business system into access to several parts of the shipment process.
Taken together, the Q2 results point to a more concentrated cargo theft environment: fewer incidents overall, but persistent account-compromise and shipment-misdirection activity and greater exposure to extreme losses.
CargoNet expects organized groups to continue specializing in metals, enterprise technology and other commodities with high values and established resale markets.
Credit: Source link
