Newsletter . August 2026

    July 2026: Fintech déjà‑vu, but with trucks

    Cargo crime went fully digital and continue growing: 108,000+ thefts logged across Europe in two years, a new €3 customs duty on every cheap parcel, and freight exchanges finally checking who's really behind the wheel. Here's what changed, and what we built in response.

    Diana Apakidze
    Diana ApakidzeChief Growth Officer3 August 2026 / 8 min read

    Abschnitt 01Cargo crime just had its glow-up: no crowbars, no masks, just a forged email and a straight face.

    Over the past two years TAPA EMEA and IUMI counted more than 108,000 cargo thefts across Europe, the Middle East and Africa, and the tiny sliver of cases that actually reported a loss still added up to over €1 billion. Meanwhile Brussels decided every €40 parcel now owes customs money, carbon pricing is coming for smaller ships too, and by 2027 transport has to accept EU digital ID wallets whether it fancies it or not. In short: logistics is having fintech's identity crisis, a decade late and on fast forward. Here is what actually happened in July.

    1. CARGO THEFT AND PHANTOM CARRIERS: CRIME GOES FULLY DIGITAL

    TAPA EMEA and IUMI aren't burying the lede this year: their joint statement describes cargo crime as having moved "from the asphalt to cyberspace."

    Thorsten Neumann, President and CEO of TAPA EMEA, put it plainly:

    criminals are cloning legitimate firms, forging insurance certificates, and using look-alike domains and stolen credentials to make a fraudulent pickup look like a normal one.

    Lars Lange, Secretary General of IUMI, added that freight exchange platforms carry a key responsibility here, since bogus carriers exploit exactly the gaps those platforms leave open.

    Germany shows how fast this is moving. KRAVAG, the German transport insurer under the R+V group and the country's market leader in goods-in-transit and traffic liability cover, warned on 2 July that phantom carrier cases have climbed sharply over the past two years. KRAVAG lawyers say they now get new reports from affected customers on a weekly basis; in 2025, a full truckload disappeared in Germany roughly every third day, with damages regularly running into six and seven figures.

    The newest twist: fraudsters aren't just spoofing email addresses anymore, they're hacking directly into freight forwarders' IT systems and freight exchange accounts, which lets them intercept and reroute transport orders from the inside, a method that simple email verification can't catch.

    It isn't only a European problem. Verisk's CargoNet recorded 767 supply chain crime events across the US and Canada in Q1 2026, a 5.3% dip in volume, but with losses holding steady at $131.58 million as impersonation-based theft matures into what Verisk calls a "systematic, scalable criminal methodology." Same playbook, different continent: fraud is replacing brute-force theft as the preferred tactic on both sides of the Atlantic.

    Quellen a weider Liesmaterial

    2. EU SCRAPS THE €150 DUTY-FREE THRESHOLD: EVERY CHEAP PARCEL PAYS

    From 1 July 2026, the EU's €150 customs duty exemption for low-value imports is gone. In its place: a flat €3 customs duty per item (per tariff line) on consignments worth €150 or less, introduced as a transitional measure that runs until 1 July 2028, after which standard tariffs based on product classification are expected to apply again.

    The mechanics matter for anyone shipping small parcels into the EU. The duty is charged per item type, not per parcel, so a box containing three differently classified products can trigger three separate €3 charges. It's typically billed to the importer or seller rather than collected at the door, and a further handling fee of around €2 per consignment is expected later in the year.

    For comparison, the US dropped its $800 de minimis threshold altogether and moved straight to full tariffs, while the UK still runs a comparatively generous de minimis regime.

    For European logistics planners, this shows up in three places: thinner margins on low-ticket cross-border parcels, more pressure to get HS codes right even on small shipments, and rising demand from shippers for a clear view of duty and fees at checkout, not at the warehouse door. "It's only a €40 parcel" has stopped being a reason to skip customs discipline.

    Quellen a weider Liesmaterial

    3. DRIVER-ASSISTANCE BECOMES MANDATORY: SAFETY TECH JOINS THE BASELINE

    As of 7 July 2026, emergency braking assist, driver distraction and attention warning systems, and an expanded head-impact protection zone became mandatory on all newly registered cars and vans across the EU. GDV, the German insurance association representing more than 460 member insurers, published data alongside the rule change showing that vehicles fitted with emergency braking assist already generate 10% fewer liability claims than comparable vehicles without it.

    GDV's Director General, Jörg Asmussen, said plainly that these systems save lives.

    The system itself is also getting smarter: from July 2026, emergency braking must reliably detect pedestrians and cyclists, not just vehicles ahead.

    Because the EU applied this through one fixed, bloc-wide date rather than the more piecemeal approach the US is taking through NHTSA rulemaking, European fleets get more certainty on the hardware side, but also less runway to align driver training, telematics and insurance products with the new baseline.

    Worth flagging for risk managers: while the hardware gets safer, the loss curve keeps shifting toward fraud and non-physical attack surfaces, exactly the trend in story one.

    Quellen a weider Liesmaterial

    4. FREIGHT EXCHANGES FIGHT BACK: TAPA AND TRANS.EU LAUNCH A CERTIFIED CARRIER LANE

    If story one made you nervous about who's actually picking up your freight, here's a genuine step in the right direction. On 1 July 2026, TAPA EMEA and Trans.eu launched the Certified Carrier Exchange, the first freight exchange built entirely on verified TAPA TSR security certification rather than paperwork carriers simply declare themselves.

    Only carriers holding a valid TSR 1, TSR 2 or TSR 3 certification get in, and that status is checked automatically, in real time, against TAPA's own database, so an expired or forged certificate doesn't open the door. Trans.eu calls it a "double-locked" environment: a verified security standard, sitting behind verified access.

    It's a direct answer to the phantom carrier problem covered above, and a signal of where the whole sector is heading.

    Freight exchanges used to compete mainly on load volume. They're starting to compete on trust instead.

    The same shift identity verification went through in banking a decade ago, where gatekeeping moved from "did you fill in the form" to "can we actually confirm who you are, continuously." Worth watching whether other exchanges follow, or wait until the fraud numbers force their hand.

    Quellen a weider Liesmaterial

    5. UK CUSTOMS MODERNISATION VS. POST-BREXIT FRICTION

    Kennedys Law, the London-headquartered firm with 46 offices across 22 countries, used its July 2026 "Logistics: Bite-Size Insights" briefing to lay out where the UK is trying to modernise its post-Brexit border: HMRC is piloting AI-assisted checks for customs caseworkers, digital ATA Carnets rolled out from 1 June 2026, and legislative changes are making it easier for businesses to reclaim "at risk" duty paid on goods entering Northern Ireland.

    The tooling is genuinely useful, but it sits on top of friction that hasn't gone away.

    Hauliers and insurers are still working through disputes over delay-related liability and cargo vulnerability at UK borders. Inside the EU single market there's no equivalent friction, and EFTA countries like Switzerland and Norway have smoother customs relationships with the EU than the UK does, six years post-Brexit.

    For pan-European networks, the UK remains a special case: any commercial opportunity there needs to be weighed against a jurisdiction-specific friction premium, which in practice means tighter contract language, clearer service-level definitions, and delay-risk documentation held to the same standard as security or compliance policy.

    Quellen a weider Liesmaterial

    BONUS READ: THE DRIVER SHORTAGE DIDN'T GO AWAY

    Trans.eu, the Polish freight exchange platform with more than 900 employees and over 120,000 daily active users across 24 European countries, published a piece in late July arguing that the industry's driver shortage conversation is asking the wrong question.

    It's not about why drivers are hard to find, the article says, it's about why they leave.

    The carriers actually winning the talent fight aren't necessarily the ones paying the most, they're the ones investing in predictable schedules, respectful communication, modern fleets and a workplace culture built on trust.

    That lands alongside IRU's latest figures: Europe's road transport sector is short more than 502,000 drivers, with a further 660,000 expected to retire by 2030.

    Fraud, carbon and talent: three fronts, and none of them get solved by a hardware upgrade alone.

    Quellen a weider Liesmaterial

    Abschnitt 02Focus: The email that looks almost right.

    The most dangerous email in logistics is usually not the one that looks obviously fake. It's the one that looks almost right.

    It arrives like any other operational message. A new shipment request. A familiar-looking sender. A payment change that sounds routine enough to pass without debate. A tiny variation in the domain name that nobody notices because everyone is already late for something. That's how social engineering actually works, not with theatrical cybercrime clichés, but with timing, pressure, and just enough credibility to slip past a busy team.

    That matters more in logistics than almost anywhere else, because this is an industry built on motion.

    • Carriers move
    • Warehouses move
    • Documents move
    • Decisions move

    Speed is a strength right up until someone decides to use it against you. Fraud disguised as urgency doesn't need to beat your systems first. It only needs to beat your attention, and that's often easier than it should be.

    But we all know that most fraudulent emails don't fail because they're badly made. They only fail if someone has the time and the habit to inspect them properly, and most people don't. They scan, they recognise, they assume. If the message sounds plausible and the moment feels urgent, trust tends to get granted long before verification even starts.

    That's exactly why email-based fraud stays so effective. ENISA's Threat Landscape 2025 found phishing was the leading initial intrusion vector across the EU, involved in roughly 60% of the 4,875 incidents it analysed between July 2024 and June 2025.

    60% email-based fraud
    of the 4,875 incidents
    between July 2024 and June 2025.

    And Europol's latest organised crime assessment names phishing and business email compromise as core tools of organised criminal networks, with online fraud now the fastest-growing category of cybercrime in Europe.

    AI-supported phishing was already a major part of that picture by early 2025, according to ENISA, which makes the old "look closely and hope" habit even less reliable than it used to be.

    In logistics, that pattern feels painfully familiar. A fake message doesn't need to look perfect. It only needs to look good enough for one tired operations manager, one rushed finance colleague, or one customer service handoff sandwiched between ten other tasks.

    A single swapped letter can do the job. A newly registered domain that resembles a trusted one can do the job. A lookalike sender address with a convincing tone can do the job. Fraud doesn't need technical brilliance. Most of the time it just needs a deadline and a human being.

    Which is also why domain abuse shouldn't be filed away as an IT-only problem. The domain layer is increasingly part of the fraud story itself.

    WIPO handled more than 6,200 domain-name disputes in 2025, its busiest year in the 25-year history of that service. Separate research published in 2026 by web data firm Decodo found 28,212 deceptive domain variations already registered across just 20 popular brands, with some brands seeing over a tenth of their plausible lookalike domains already taken.

    Those aren't harmless digital leftovers. Lookalike domains get used to mimic trust, support phishing, host fake pages, misdirect replies, and borrow a reputation nobody earned.

    From personal experience working in a domain industry in 2018 at Openprovider.com, the most dangerous cases were rarely the dramatic ones. They were the subtle ones: a sender that looked close enough, a domain with just enough history to avoid suspicion, a message that made emotional sense, especially to someone already under pressure.

    That's what makes this category of fraud so hard to catch. The fake looks operationally normal right up until somebody checks the traces underneath it.

    We didn't have to take that entirely on faith. In the first two days after Trusted Carrier went live, our system ran hundreds of verification checks across real carrier communications, and the pattern held almost exactly the way the research above would predict.

    Very few flags were the obvious, badly-spelled kind of fake that anyone would catch on a bad day. Most were quiet: a domain registered a few weeks earlier, a sender address one character off from a known partner, a mismatch between the company being claimed and the infrastructure actually sending the mail. Nothing dramatic. All of it the kind of thing a busy person would wave straight through.

    Those traces matter more than ever, and there's official guidance behind that. The UK's National Cyber Security Centre recommends SPF, DKIM and DMARC to make it harder for fake emails to be sent from a legitimate domain in the first place, and advises moving to a DMARC reject policy once mail flows are correctly configured, since that's the strongest available protection against spoofing.

    But even those controls, important as they are, don't answer every operational question. A message can pass every technical check and still be wrong in context. That's where a fuller verification mindset comes in.

    This is the logic behind what we call the Trace level of verification. Trace isn't about staring at an email address and hoping intuition does the rest. It's about whether the full picture actually supports trust. Is the email properly authenticated? Does the domain carry risk signals? Is the route suspicious? Does the sending IP have a poor reputation? Has the domain or infrastructure shown up on blacklists? Does the communication itself read as consistent with normal business behaviour, or does it suddenly turn too urgent, too unusual, too convenient?

    That last question matters more than people tend to admit. Communication anomalies are often the bridge between technical abuse and human error: an unusual request for speed, a payment update that skips the normal workflow, a tone that doesn't quite sound like the company you know. None of these alone proves fraud. Together, they start to form a pattern, and patterns are exactly what operations teams should be watching for.

    The problem with a lot of traditional fraud-awareness advice is that it asks humans to do work machines should be doing instead.

    People get told to inspect domains character by character, compare spellings by hand, notice whether a letter is Cyrillic instead of Latin, all while managing deliveries, invoices, claims and customer pressure at the same time.

    That isn't really a security strategy. That's wishful thinking with a coffee dependency.

    This is especially relevant with typosquatting and homograph attacks specifically. A fraudulent domain doesn't need to fool a cybersecurity analyst for twenty minutes. It only needs to fool a busy person for twenty seconds. That's the economics of modern impersonation: the attacker invests very little, and the defender is asked to notice everything.

    Arno Vis, CEO of Openprovider, put the wider industry problem well when he said abuse management in the domain sector is "stuck in limbo," and that without a clear, unified framework and the right technology behind it, the industry will keep reacting to abuse rather than actually containing it.

    That's the gap Trace-level verification is built to close, not by asking people to notice more, but by making sure the system already has.

    **You can request one free verification at hello@trustedcarrier.net**

    Quellen a weider Liesmaterial

    Abschnitt 03PRODUCT UPDATE: From “Looks Legit” To Verified Email Identity

    Most phantom‑carrier fraud stories start in the inbox, not at the loading dock.

    In the Düsseldorf case we cited in June, a single‑character domain change turned a reputable forwarding company into a perfect disguise for a criminal group: same name, same branding, different email identity.

    As long as logistics treats email addresses as “just contact details,” attackers will treat them as the easiest way to become a trusted carrier on paper before they ever touch a truck.

    Trusted Carrier’s identity infrastructure was built on a simple principle you already use for people and companies:

    In this issue we will share how our email verification actually catches a fake carrier.

    Step one is email correctness.

    Before anything else, we confirm the address is properly formatted, resolves to a real and active mailbox rather than a dead or disposable one, and matches the pattern you'd expect from a genuine business account rather than a free webmail address dressed up to look corporate. It sounds basic, but a large share of phantom carrier attempts fall over right here, because the fraudster's actual inbox rarely holds up under a proper check.

    Step two is domain verification, and it catches three distinct things.

    • The first is typosquatting: an extra letter, a swapped character, a hyphen slipped into a familiar name, the kind of thing you only spot if you're staring at the address rather than skimming it.
    • The second is subtler and harder to catch by eye: homograph spoofing, where a Cyrillic or Greek character that looks identical to a Latin letter is swapped in, so "carrier.com" and "cаrrier.com" render the same on screen but are two completely different domains under the hood.
    • The third is a cross-check: we compare the domain behind every address against commercial registers, official company websites, platform records and known safe domains, and flag recently registered domains and other high-risk patterns automatically, before a fake carrier ever gets the chance to accept a load in someone else's name.

    For the people actually doing the work, none of this is meant to feel like a compliance obstacle course. Dispatchers see a flag: an unusual domain or a mismatch highlighted the moment a quote or dispatch instruction comes in.

    The goal is for "this doesn't look right" to be a system-generated insight, not a hunch someone has at 11pm with the truck already idling at the gate.

    This comes straight out of founder Karlheinz Toni's fintech background: running an online financing platform that verified roughly six million identities a year taught the team that the real failure mode in digital fraud usually isn't "no checks," it's checks done at the wrong time, in the wrong place, against the wrong data.

    In road transport, the inbox has quietly become the new branch office, the place where identity gets asserted and loads get accepted.

    Getting the email and the domain right, systematically, every single time, is the first and most immediate way to shut one of the main doors phantom carriers use to get in.

    This August we are opening our verification platform for one verification for free. Just send your request at hello@trustedcarrier.net , verify your company and perform one verification for free.

    Abschnitt 04July at Trusted Carrier:

    On 14 July 2026, Schmitz Cargobull hosted the NetzwerkForum TRANSPORTLOGISTIK.NRW in Altenberge, bringing together innovation and security topics from smart trailers and digital driver processes to phantom‑carrier risk.

    Mr. Toni , Trusted Carrier CEO joined the final panel discussion alongside insurers, insurance brokers and TIMOCOM, putting carrier identity and fraud‑resilient processes on stage rather than in the footnotes.

    Appearing on that panel moved Trusted Carrier from “specialist fraud topic” into the broader conversation about how transport chains should be designed and insured in practice, not just in theory.

    Additionally to it, Trusted Carrier has also become a member of the Logi‑IT Club, the innovation and IT‑focused community under the logistik.nrw umbrella. Our intention with Logi‑IT Club membership is to make carrier identity and fraud‑resilient verification part of the everyday IT conversation in logistics, not only in security conferences.

    That means showing how verified identities and email checks can plug into TMS systems, freight exchanges, telematics platforms and driver apps in a way that reduces fraud risk without adding unnecessary friction to operations.

    By engaging in this community, Trusted Carrier aims to help shift the region’s logistics IT agenda from “digitalisation for efficiency” to “digitalisation for trustworthy networks,” where identity, authorisation and agentic execution are treated as core infrastructure rather than optional extras.

    Abschnitt 05Where to Meet Us Next:

    On 27 August 2026, Trusted Carrier will participate in TAPA EMEA’s Connect & Protect event in Weeze, a cargo‑security community gathering focused on intelligence, standards and practical risk‑reduction measures across European supply chains.

    The timing is just right: TAPA EMEA, IUMI, KRAVAG and GDV have all framed phantom‑carrier fraud as a structural risk, not a temporary spike, and community events like Weeze are where the sector now compares practical tools instead of repeating the problem statement.

    Being TAPA EMEA Member, we are aiming at acting as an active contributor rather than just a silent member, because we know that we are part of the solution architecture for fraud, not simply another vendor reacting to headlines.

    Weiderliesen