FMCSA warned the industry on September 15 that scammers are impersonating its new Motus registration portal with four lookalike sites and a phishing campaign that uses the system’s own transition confusion against the carriers it targets.
FMCSA issued a fraud alert on September 15, 2026, warning motor carriers about four lookalike websites impersonating its new Motus registration portal. The emails directing carriers to those sites carry the subject line “Notice of Required Off-Cycle Update- Motus email” and push recipients to click a button labeled “New MOTUS Portal.” That label is one of the tells. FMCSA writes the system name as Motus, not all caps. The scammers wrote it in all caps, which shows they didn’t read the agency’s own documentation before building the scheme.
There is one legitimate URL. It ends in .gov. It’s motus.dot.gov. The four the agency flagged are dot.motusdatasboard.com, dot.motusdatadesk.com, dot.motuswebdeck.com, and dot.motusfunction.com. None carries a government domain. Each one looks close enough to pass a quick glance, which is the only glance most dispatchers running a small fleet will give an email that arrives with an urgent federal compliance header.
The emails claim the carrier needs an “off-cycle” profile update, meaning a required filing that falls outside the carrier’s normal schedule. That framing is doing a lot of work. A carrier that recently completed its biennial update would ordinarily know there’s nothing else due. But Motus is four months old, the biennial enforcement has been temporarily suspended, and guidance has been coming in rolling waves since May. In that environment, an email claiming something extra is required doesn’t automatically read as a lie.
The scam isn’t accidental timing. It’s a direct product of the transition. FMCSA launched Motus on May 19, 2026 as its replacement for the Unified Registration System and several other legacy platforms that carriers, brokers, and freight forwarders had used for years. The Federal Register notice published April 29, 2026 described the new system and noted that FMCSA had seen what the agency called a significant upswing in “presumed fraudulent activity where erroneous information about a registered entity is being used, resulting in cargo and monetary theft in the motor carrier industry.” Motus was the answer. The system introduced mandatory identity and business verification through IDEMIA and CLEAR, built-in fraud checks to flag questionable registration applications for investigator review, and a single consolidated dashboard that replaced what previously required multiple logins across separate government websites. The agency sent 2.2 million letters to registered users as part of the transition, and 18 percent of them, roughly 396,000, came back undeliverable. That number says a lot about the state of the registry Motus was designed to clean up.
The scam is convincing for one reason: the real Motus system requires carriers to verify their identity and connect their account to an existing USDOT record. Fraudsters are mimicking that legitimate process. The email looks like part of an onboarding flow carriers already expect because they are, in fact, in the middle of one. The confusion the transition created is the attack surface. FMCSA suspended enforcement of biennial updates on September 10 to reduce disruption during the transition period, pausing USDOT number inactivation for filings due after June 1, 2026. That suspension removed one compliance pressure. It didn’t remove the email campaign already running against carriers who don’t know what is and isn’t required right now.
The mechanism is what the industry calls credential harvesting. The email creates urgency, the button routes to a lookalike site, and the site collects whatever the carrier enters: login credentials, company data, officer information, potentially a DOT PIN. That material has real value. Brokers and shippers use carrier registration records to confirm who controls a trucking company. A successful account takeover doesn’t just compromise the carrier’s own operations; it compromises the vetting record that every broker downstream relies on to confirm they tendered a load to the right entity. An altered registration record is how a bad actor plants themselves inside a legitimate company’s identity. The industry has a name for the broader play: double brokering, identity takeover, chameleon operations. The federal record is the foundation those schemes require. This campaign is trying to get inside that foundation through the front door, while the lock is being replaced.
FMCSA’s fraud alert page has a long history with this category of scam. The agency has previously flagged fake FMCSA Portal landing pages, spoofed portal URLs, fraudulent compliance notices, and fake action-required notices. The Motus campaign follows the same architecture as those earlier phishing runs but with a higher-value target: the new system is the single point of control for registration identity across the entire regulated fleet. Getting credentials to Motus isn’t like getting credentials to the old URS. The old system was fragmented enough that a takeover in one area didn’t necessarily reach another. Motus is a unified dashboard by design. That’s its strength and, right now, its exposure.
The agency’s alert page recorded a September 11 update. FMCSA has not disclosed when the email campaign began, how many recipients it reached, whether any accounts were compromised, or whether any confirmed registration changes trace to the fake portals. The warning includes no victim count or financial loss figure. Authorities have not connected the sites to cargo theft yet, according to the FreightWaves report. That’s where the record sits today. It can change.
If you received one of these emails, don’t use the link in it. Type motus.dot.gov directly into your browser, confirm the URL ends in .gov before entering any credentials, and hover over any link before you click it to see where it actually routes. Legitimate FMCSA correspondence won’t ask you to submit payment or sensitive financial information by email. Company names, DOT numbers, and addresses are publicly available data, so their presence in an email doesn’t make that email legitimate. Report suspicious contacts to the FTC, the FBI Internet Crime Complaint Center (IC3), your local police, or your state attorney general. FMCSA registration questions go to 1-800-832-5660. That number is real. The “New MOTUS Portal” button is not.




Leave a Reply