The Soft Underbelly: How OSINT Helps Protect the Trucking Industry

By Jen Snell

Editor's note: Babel Street’s Jessica Lewis McFate discusses cargo theft, threat intelligence, and supply chain risk on SiriusXM’s On the Move. In the interview below, she explains how open-source intelligence and publicly available information can help transportation and logistics organizations recognize emerging criminal tactics, vet partners more effectively, protect the information they rely on, and make better decisions in an increasingly complex threat environment.
Babel Street's Senior Director of Intelligence Solutions, Jessica Lewis McFate, recently joined Dan Ronan, host of On the Move, for a live conversation on SiriusXM about the evolving security threats facing the trucking and logistics industry.
Drawing on her career in military intelligence and national security, Jessica explored how criminals, cartels, and nation-state actors are using publicly available information, artificial intelligence, and increasingly sophisticated deception tactics to target supply chains.
The conversation covered the changing nature of cargo theft, the digital risks created by connected vehicles and infrastructure, the importance of vetting supply chain partners, and why access to more information does not necessarily produce better intelligence.
Her central message for transportation and logistics leaders was clear: threats that once appeared distant are moving closer to home, and companies must become more deliberate about how they identify, evaluate, and act on risk.
The following interview has been edited for length and clarity.
Interview Highlights
- Criminals are using public information, AI, and digital deception to target supply chains.
- Cargo theft is becoming more organized, sophisticated, and difficult to spot early.
- Vendor vetting is essential because trusted partners can expose cargo, systems, and data.
- OSINT helps organizations detect risk, validate signals, and monitor emerging threats.
- AI can accelerate analysis, but source verification remains critical.
- Transportation leaders need better intelligence, not just more information.
The new face of intelligence and digital risk
Dan Ronan: When people hear the word "intelligence," they tend to think of spies and national security. But intelligence applies to other industries as well. Are bad actors gathering information about the trucking industry to cause disruption?
Jessica Lewis McFate: Certainly, although it is not always about causing disruption. Often, it is about making money.
A significant amount of intelligence activity — even activity associated with traditional national security threats — ultimately resolves down to criminality. Bad actors are people who do bad things, and trucks represent incredibly lucrative illicit potential. The threats facing trucks and commercial supply chains are not that far removed from the threats facing governments and states.
Dan: Companies invest heavily in cybersecurity, spam filters, and tools designed to stop phishing attacks. Are most of these attacks simply broad campaigns that are unlikely to succeed?
Jessica: There are many cyberattacks that are impersonal. They are sent out in waves and are not expected to succeed at a high rate.
But the analogy that comes to mind is defensive driving. When you are on the road, your safety is not based solely on how good a driver you are. It also depends on how effectively you anticipate and evade the threats created by everyone else. We now have to operate on the internet with that same defensive-driving mentality in both our personal and professional lives. The threats are everywhere, and while most may not reach you, the one that does can have catastrophic consequences.
It is also important to recognize that cyber risk extends beyond emails and laptops. Some of the devices that provide the least amount of human interaction can create the greatest cyber effects. It may be a vehicle, a heating system, a sensor, or another connected device that we do not instinctively think of as part of the internet.
At the same time, those connected devices — and the information people intentionally publish online — create an enormous amount of potentially useful open-source intelligence. I sometimes describe this using the Ratatouille principle: not every piece of information is good, but a good piece of information can come from anywhere. The craft of intelligence is finding the signals that can tell you something decisive.
What Is Open Source Intelligence (OSINT)?
Open source intelligence, or OSINT, is intelligence developed by collecting, evaluating, and analyzing publicly available information, including news, social media, forums, public records, and other open data sources. In modern threat intelligence, OSINT helps organizations identify emerging risks, validate signals, understand threat actors, and turn scattered information into actionable insight.
How criminals exploit publicly available information
Dan: How are criminals using publicly available information to support cargo theft, fraud, and other schemes?
Jessica: Start by considering how logistics companies market themselves, connect with other businesses, and participate in supply chains. Companies publish information online because they want to attract customers and partners. But it has become remarkably easy to impersonate a legitimate company, particularly within an international supply chain.
One of the most immediate opportunities for a bad actor is to pose as a trusted member of the ecosystem and obtain access that should never have been granted. The company may appear legitimate, have a convincing digital presence, and use the right industry language. The victim willingly provides access because the deception looks credible.
Another concern is that geopolitical adversaries seeking access to resources entering the United States are among the world's most sophisticated practitioners of information manipulation. They understand how to generate information at scale to influence behavior and commercial decisions. These activities can range from overt disruption — such as attacks against ships and infrastructure — to more subtle efforts involving sanctions, regulatory compliance, technology dependencies, or commercial relationships.
An offer that appears to solve a business or compliance problem can also create geopolitical exposure. That is part of the modern information environment: influence does not always look like propaganda, and a security threat does not always look like an attack.
America's supply chain as a soft target
Dan: Are trucking companies making mistakes that give organized crime groups too much information about their operations?
Jessica: The industry is adapting to new types of threats and to the information that AI and modern situational-awareness capabilities make available.
The good news is that systematic theft and orchestrated campaigns against the trucking industry can often be seen developing. These are not always random, isolated events. With the right information, organizations can identify patterns and indicators before an incident occurs.
But companies can no longer draw a boundary around the continental United States and assume the threat environment here is fundamentally different from what carriers experience in Mexico or other higher-risk markets. Those threats have extended into the United States. In some respects, the interior of the country can become a soft underbelly precisely because companies are less likely to expect sophisticated, organized attacks here.
Transportation leaders need to keep their eyes open and consume information from a range of sources. Not everything online is deception. Much of it can provide valuable situational awareness when it is evaluated properly.
What smaller carriers can do
Dan: Large freight carriers have extensive security teams and formal protocols. What can an independent carrier or a company operating 12 or 18 trucks do to strengthen its security?
Jessica: Maintain as much direct human contact as possible. I am a strong proponent of AI-based technologies, but one of the greatest vulnerabilities today is assuming technology will handle relationship-based vetting for you. It will not vet your business partners for you.
Large carriers may actually be more exposed in certain respects because they must interact with so many smaller businesses. That creates more opportunities for a questionable organization to enter the ecosystem.
Do not assume that every organization in a partner's network is trustworthy simply because you trust the primary partner. Know who will have physical access to your cargo, systems, and data. Work closely with the people who will put their hands on your freight or connect to your technology.
Smaller companies should lean into the advantages of being small. They may have a better opportunity to understand their direct supply chains, know their partners personally, and recognize when something does not look right.
Dan: A large global carrier is also a much bigger target because that is where the money and freight are concentrated.
Jessica: Yes, and the carrier can also inherit the threat profile of its customers. If a carrier delivers to a military installation, law enforcement organization, government agency, or another strategically important customer, an adversary may target the carrier as a pathway to that ultimate destination.
There is now a sliding spectrum of threats — from an individual criminal using AI to become more systematic and effective, to a cartel or nation-state actor hiding behind what appears to be a legitimate company. These organizations need to make money, and they have no hesitation about stealing from legitimate businesses. The challenge is that they increasingly operate in ways that do not feel like warfare and may not look like crime until after the damage has been done.

Protecting the information supply chain
Dan: Given your background in military and national security intelligence, what keeps you up at night?
Jessica: What concerns me most is the possibility that we become detached from information sources we can properly evaluate.
The same principle that applies to vetting a supplier also applies to information. You should not automatically trust a second-tier partner because you trust the intermediary that introduced you. Similarly, you should not automatically trust a claim because it was delivered through a polished interface or summarized convincingly by an AI system.
My own supply chain is information: authentic, authoritative, accurate information that depicts what is really happening in the world. There are many threats to that supply chain.
AI makes it incredibly easy to ask questions about current events and emerging risks. That accessibility can be extremely valuable for logisticians and security teams. But AI is only as reliable as the source information underneath it. If those sources have not been evaluated for manipulation, deception, bias, or adversarial influence, it becomes very difficult to build ground truth on top of them.
The adversary I worry about today is the adversary of truth. That adversary is extremely active.
Ransomware and the normalization of extortion
Dan: We hear about major ransomware incidents such as the Colonial Pipeline[1] attack, but how many organizations quietly pay millions of dollars in cryptocurrency to make an attacker go away?
Jessica: It is very likely happening more frequently than the public realizes.
The response can also vary based on geography and confidence in local institutions. In some places, turning immediately to law enforcement or regulatory authorities is normal. In others, companies may have so little confidence in those mechanisms that paying the attacker appears to be the most practical option. For some businesses, the ransom may be comparable to the cost of a compliance fine or prolonged operational interruption. They may also have little expectation that law enforcement can protect them or recover their systems.
Companies have faced those calculations for a long time. What has changed is that the line between markets where paying is considered normal and markets where organizations expect to rely on law enforcement appears to be moving farther west. That is deeply concerning.
How OSINT can make trucking companies safer
Dan: How can open-source intelligence help make trucking and logistics companies safer?
Jessica: OSINT gives organizations access to significantly more information, but they must protect themselves while collecting and evaluating it. Organizations should consider how they access the internet, including whether their IP address, identity, or physical location is unnecessarily exposed during research. They should then be aggressive in interrogating publicly available information for potential threats, suspicious companies, emerging criminal tactics, geopolitical developments, and risks along their routes or within their partner networks.
But do not trust something simply because it has been summarized well. Review the underlying sources. Understand who created the information, why it was published, and why it has been placed in front of you. If you do not know the source, you cannot confidently trust the information. At a minimum, organizations should validate important conclusions using multiple independent sources.
Dan: It comes back to "trust, but verify."
Jessica: Exactly. Verification is harder than it used to be, but it is more important than ever.
From more information to better intelligence
The trucking industry is becoming increasingly connected, but connectivity alone does not create security.
Criminal organizations and nation-state actors can use the same public information, digital platforms, and AI capabilities available to legitimate businesses. They can identify valuable cargo, impersonate trusted partners, map commercial relationships, exploit technology dependencies, and hide within complex supplier networks.
The answer is not to withdraw from the digital environment. It is to operate within it more intelligently. Transportation and logistics organizations must understand who has access to their cargo and systems, continually evaluate their partners, protect their digital footprint, and demand traceable sources behind the intelligence informing their decisions.
Because in an environment shaped by AI-generated content, sophisticated deception, and globally connected threats, receiving an answer is easy. Knowing whether that answer can be trusted is what matters.
Learn more about how Babel Street helps organizations identify emerging threats, investigate hidden connections, and make intelligence-informed decisions.
Endnotes
1. Easterly, Jen and Fanning, Tom, Cybersecurity & Infrastructure Security Agency (CISA), “The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years,” May 2023, https://www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years