Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-05 · updated: 2026-10-05 · tags: [incident, transport] · confidence: medium · severity: low · affected_sectors: [transport] · au_impact: true

Mexican trade officials are warning cross-border operators about identity-theft and payment-diversion schemes that have a solidly digital fraud mechanism: criminals are using spoofed internet domains and stolen transaction information to impersonate both importers and customs brokers and redirect customs-related payments. Javier Cendejas, president of the Mexican Council for Foreign Trade's Northeast chapter (COMCE Noreste), described one case at a 28 September news conference in which a foreign trade company made an electronic payment it believed was going to a legitimate customs agency, after a third party stole the identities connected to the transaction and impersonated both counterparties. The method is business email compromise adapted to freight: fraudsters register lookalike domains, impersonate executives, and send messages claiming that banking details for a transaction have changed — and they often already hold enough detail about a real shipment to make the request look authentic. The time-sensitive nature of cross-border freight amplifies the risk, since urgent demands to release cargo or avoid storage charges pressure treasury staff into transferring money without verifying through a second channel. Advance payments to customs brokers — covering handling, storage, pre-validation and transport — are the particular weak point. The escalation is measurable: IDScan.net's 2026 report found attempted identity fraud in US cargo and logistics rose 213% from 2023 to 2024 and another 30% in 2025, to 2.15% of more than 1 million identity-verification transactions. The simple control remains an out-of-band second-channel check on every banking-detail change.

Attribute Detail
Sector Transport
Date 2026-10-05
Source FreightWaves
Reliability Tier 3