When Theft Counts Fall and Losses Double: Peak-Season Claims Control
Cargo thefts fell in Q2 2026 while losses more than doubled. Operators face peak-season claims risk from compromise and misdirection fraud.

The trap of reading the board by incident count
Here is a decision that still gets made in too many brokerage and asset ops rooms: incident counts are down, so cargo risk must be easing. A Q2 2026 North American supply-chain theft analysis says the opposite is true. Across the United States and Canada, industry cargo-theft analysts recorded 677 supply chain theft incidents, down 26 percent from Q2 2025 and down 14 percent from the prior quarter. Estimated losses hit $304.6 million, more than double the $135.7 million estimated for Q2 2025. Among thefts with a reported commodity value, the average reached $564,009, skewed by multimillion-dollar hits.
Industry cargo-theft analysts put the failure mode in plain language. Lower incident volume should not be mistaken for lower risk. Organized groups are not necessarily trying to steal more freight. They are trying to identify the right shipment. Metals and enterprise technology sit at the center of that selectivity because value, demand, and resale opportunity now drive targeting more than sheer volume of attempts.
If your peak-season plan still treats "fewer thefts reported" as a green light to loosen verification, you are managing the wrong metric. Severity and compromise-based fraud are the story into fall, not a quieter board.
What actually declined, and what did not
The Q2 drop was not uniform across method or commodity. Physical theft of loaded equipment and non-delivery fraud involving recently acquired motor carriers fell significantly, especially in California and Texas. Business email compromise (BEC) and shipment misdirection stayed comparatively stable. In that Q2 classification set, events labeled as theft fell from 488 in Q2 2025 to 378 in Q2 2026. Fictitious pickups barely moved, from 165 to 158.
That split matters for how you staff claims and cover desks. A quieter trailer-lot pattern does not mean your email, phone, and ops-system channels got safer. Compromised accounts remain a primary access point for sophisticated schemes. Once an account is inside the chain, actors can pull shipment information, communication threads, directories, and tools that look legitimate to brokers, carriers, shippers, and receivers. Details can change after the tender already looked clean.
Metals moved against the overall decline. Metal theft rose from 54 incidents to 80. Copper remained the most frequent target, with aluminum, nickel, tungsten, and specialized industrial metals also climbing. Enterprise-grade computer and networking equipment, components, and crypto mining hardware kept drawing organized attention. Those loads can be worth millions and still move as conventional dry freight, which creates a security-profile mismatch many shops still underrate at booking.
Food and beverage declined overall. Seafood rose by 11 events. Auto parts and tires dropped. Supplements and OTC products also fell. The takeaway for operators is not a commodity scorecard to memorize. It is that selectivity is concentrating loss exposure into fewer, higher-severity events, exactly when peak freight volume and holiday staffing gaps compress judgment time.
Labor Day as a rehearsal for peak verification failure
A September 4, 2026 Labor Day cargo-theft advisory analyzed 273 incidents across Labor Day periods from 2021 through 2025 (Thursday before through Wednesday after). Annual counts rose from 33 in 2021 to 56 in 2025, a 70 percent increase, with a five-year high of 70 in 2024. Friday accounted for 55 incidents, Tuesday 49, Thursday 46, and Wednesday 44. Those four days totaled 194 of 273, or 71 percent. The weekend itself was quieter: Saturday 24, Sunday 28, Monday 27.
That pattern fits deceptive pickup and non-delivery work that needs live staff and active channels. Two risks overlap. Physical exposure rises when freight sits at rest during closures. Verification exposure rises when reduced staffing and time pressure make impersonation and instruction changes easier. California (70), Texas (38), and Illinois (22) made up 130 of 273 incidents, or 48 percent. Holiday commodity mix in that analysis leaned food and beverage (49), household goods (27), electronics (25), vehicles and accessories (20), and metals (11), with roughly $31.8 million in commodity value across the set.
That same advisory also flagged an emerging threat that should change how you design peak controls. Identity-based theft and misdirection via compromised carrier accounts, phone systems, email, and compliance platforms can happen at tender, at pickup, or after a legitimate carrier already has the freight. A delivery address or contact change mid-transit bypasses controls that only gate carrier selection. In the July 4 analysis cited in the Labor Day piece, H1 2026 losses already exceeded $359 million, with average stolen commodity value around $341,518.
Peak season from August through October is when those same failure modes collide with higher volume. You do not need a new rate dial to act. You need claims and verification discipline that treats compromise as a live channel risk, not a rare edge case.
The ops decision: when "verified at tender" is not enough
The failure mode looks familiar. A load clears carrier selection. Authority, insurance, and references look right. Someone on the desk treats that as the security event for the trip. Then a "receiver" or "shipper contact" emails a new warehouse, a new gate code, or a new AP contact after pickup. The change arrives through a channel that feels inside the relationship. The trailer moves. The claim arrives weeks later with a thin packet and a contested chain of custody.
That is not a training-video problem. It is a process design problem. Selection controls at tender are necessary. They are insufficient when misdirection happens after the freight is already in motion. Dual-channel confirmation on delivery changes, status gates before release, and permissioned edits to consignee and contact fields are how serious shops close that gap. Shops that leave address and contact edits open to anyone with a login are volunteering for contingent exposure.
Commodity flags matter just as much. Metals and enterprise tech should not inherit the same default dry-van checklist as ordinary consumer freight. If your booking workflow cannot force a higher verification path, seal protocol, GPS expectation, or claims documentation standard when the commodity profile warrants it, you are asking people to remember policy under peak pressure. Most will not.
Asset, broker, and hybrid: who owns which break
Tradeoffs differ by model.
Asset carriers own custody evidence more directly. Seals, GPS breadcrumbs, appointment stamps, and driver-side photos live closer to the tractor. The break is often documentation discipline when a yard or receiver pushes for speed, or when a mid-transit instruction change is accepted without a second channel. Contingent cargo and shipper expectations still land hard when the packet cannot prove where and when control changed.
Brokers own tender verification and counterparty identity more than custody. The break is often over-trusting a clean tender screen while under-investing in post-pickup change control. When BEC or misdirection hits, claim friction follows the paper trail of who authorized what, when, and through which channel. Margin and service both take the hit before insurance debates finish.
Hybrids sit in the worst of both if ownership is unclear. Asset legs may assume the brokerage desk verified the change. The desk may assume the driver confirmed the receiver. Claims teams inherit the gap. Peak season rewards teams that write down who owns each checkpoint: selection, pickup verification, mid-transit instruction changes, delivery release, and claims packet completeness.
None of this requires identical process across every shop. Every freight business is unique. The operators who hold up under severity encode that uniqueness into workflow rules, statuses, permissions, and exception handling rather than relying on tribal knowledge during the busiest weeks of the year.
Encoding claims control into the workflow (without turning it into theater)
Customization here is not a product pitch. It is how you make unique risk rules enforceable when the phone is ringing.
High-value commodity flags should route metals, enterprise networking gear, and similar loads onto a stricter path automatically. Dual-channel confirmation (email plus a known phone contact, or two named parties) should be required before any delivery address or contact change after pickup. Status gates should block release or delivery-complete until required fields exist. Permissions should limit who can edit consignee, contact, and appointment details. Claims packets should demand timestamps, photos, seal numbers, and GPS or location evidence as standard, not as a recovery scramble after denial. Exception workflows should treat mid-transit appointment or address changes as managed exceptions with owners and clocks, not as free-text notes in a chat thread.
None of these controls need to be identical across every customer or lane family. A metals program, a tech-components book, and a grocery book do not share the same failure modes, so they should not share the same default checklist. What they should share is a system that can enforce different rules without asking a peak-season desk to invent policy in the moment.
The concentrated environment those Q2 and Labor Day analyses describe (fewer incidents, persistent compromise and misdirection, extreme-loss exposure) rewards that kind of dull discipline. Peak volume will not wait for a perfect playbook rewrite in November. The shops that protect margin and service now decide what "verified" means after the truck is already rolling.
What leaders should decide this week
Treat Q2's falling incident count as a warning about severity, not a reason to thin controls. Re-audit which loads inherit ordinary dry-van handling even though their commodity profile matches today's preferred targets. Close the post-pickup change path that still relies on a single channel. Clarify asset versus brokerage ownership of custody evidence and instruction authority before the next holiday week compresses staffing. Require claims documentation standards that survive a disputed release.
You cannot eliminate cargo theft. You can stop managing it as if average incident volume still described the risk. Into peak, the board that is "quieter" on counts can still double your loss exposure when the wrong shipment is the one that gets through.
FAQ
Are cargo theft incidents really down if losses are up?
Yes. A Q2 2026 North American supply-chain theft analysis documented 677 U.S. and Canada supply chain theft incidents, down 26 percent year over year, while estimated losses rose to $304.6 million from $135.7 million in Q2 2025. Fewer events with higher severity and selective targeting of high-value commodities explain the split.
Why do metals and enterprise technology matter more for claims control now?
Because organized groups are following value, demand, and resale opportunity. Metal theft rose from 54 to 80 incidents in Q2 2026, and enterprise-grade computer and networking equipment often moves as ordinary dry freight despite multimillion-dollar exposure, creating a security-profile mismatch at booking and in transit.
Is verifying the carrier at tender enough to stop modern cargo theft?
No. The September 2026 Labor Day cargo-theft advisory highlights identity-based misdirection that can occur at tender, at pickup, or after a legitimate carrier already has the freight, including delivery address or contact changes that bypass selection-only controls. Post-pickup dual-channel confirmation is now as important as tender verification.
When during holiday weeks is cargo theft risk highest?
Around the holiday, not only on the holiday itself. Across Labor Day periods 2021 through 2025, Friday, Tuesday, Thursday, and Wednesday accounted for 71 percent of 273 analyzed incidents, consistent with fraud that needs live staff and active channels.
How should asset carriers and brokers split responsibility for claims exposure?
Asset operators typically own custody evidence (seals, GPS, photos, appointment stamps), while brokers typically own tender and counterparty verification. Hybrids must name owners for mid-transit instruction changes and claims packet completeness so neither side assumes the other closed the gap.
What workflow changes reduce compromise-driven claim severity without slowing every load?
Flag high-value commodities onto stricter paths, require dual-channel confirmation for post-pickup delivery changes, permission who can edit consignee and contact fields, gate release on required status evidence, and standardize claims packets with timestamps, photos, seals, and location data. Encode those rules so peak volume does not depend on memory.