Trucking companies are being warned about a new phishing campaign aimed at users of the Federal Motor Carrier Safety Administration’s (FMCSA) Motus registration system.
The scam relies on emails that imitate the newly introduced federal registration platform and direct recipients to one of four fraudulent websites. The messages claim that an off-cycle profile update requires immediate attention, creating the kind of urgency that can push recipients into clicking before verifying where the link actually leads.
FMCSA is urging carriers and other users to avoid all four fraudulent destinations.
“Latest reports indicate that bad actors have started to impersonate the Motus website application,” FMCSA wrote. The legitimate Motus service is available at motus.dot.gov.
The fraudulent emails refer to their destination as the “New MOTUS Portal.” The use of all capital letters is itself another warning sign: federal officials identify the system as Motus, rather than “MOTUS.”
One legitimate website, four fraudulent portals
There is only one official Motus website. Its address ends in dot.gov, which is a key distinction carriers should verify before entering credentials or company information.
FMCSA has identified the following four websites as fraudulent:
REAL:
-
motus.dot.gov
FAKE:
-
dot.motusdatasboard.com
-
dot.motusdatadesk.com
-
dot.motuswebdeck.com
-
dot.motusfunction.com
The campaign uses the subject line “Notice of Required Off-Cycle Update- Motus email.”
Inside the message, recipients are encouraged to click a “New MOTUS Portal” button. The button sends users to an external website rather than the legitimate federal registration system.
FMCSA recommends that customers carefully examine the destination of every link before clicking, particularly when an email demands an immediate profile update or other account action.
The example shown in the agency’s warning is dated August 2026. The broader rolling fraud-alert webpage carries a September 11 update. FMCSA notes that this timestamp applies to the webpage as a whole and not necessarily to each individual alert listed on it.
Scam emerges during Motus transition
The timing of the campaign comes as carriers and other regulated entities adjust to Motus, which FMCSA launched May 19 as its new USDOT registration system.
The platform is used by carriers, brokers and other regulated entities to submit applications and update company information. It replaces several legacy processes as part of a broader modernization effort, with users accessing the system through Login.gov.
The transition has already created operational challenges.
On September 10, regulators temporarily suspended biennial-update enforcement in an effort to limit disruptions during the Motus rollout. The decision also paused USDOT-number inactivation for missed filings that were due after June 1.
Officials said additional guidance would be released as recovery work continues.
That transition, however, does not make unsolicited emails requesting immediate action legitimate. Carriers should continue to follow official FMCSA instructions rather than relying on links contained in unexpected correspondence.
What companies should do
Companies that receive a suspicious Motus-related message should avoid clicking its links or entering registration credentials on unfamiliar websites.
Fraud complaints can be submitted to the Federal Trade Commission or the FBI Internet Crime Complaint Center. Reports can also be made to local police departments and state attorneys general.
For registration-related questions, FMCSA can be reached at 1-800-832-5660.
Scope of campaign remains unclear
FMCSA has not said when the fraudulent campaign began or how many recipients may have encountered the messages.
The agency’s warning does not provide a victim count, estimates of financial losses or any confirmed cases of account takeover. Authorities have also not linked the fraudulent websites to unauthorized registration changes or cargo theft.
FreightWaves has requested additional information from FMCSA and will update the article if the agency responds.
Why the warning matters to carriers
Federal registration information plays an important role in the freight ecosystem. Brokers and shippers rely on carrier registration records to help establish who controls a trucking company.
A successful account takeover could therefore undermine safeguards that depend on federal identity and registration information.
The immediate threat may begin with something as simple as an email, but compromised registration credentials can potentially create wider problems for companies operating across the freight network.
CFCO
In my opinion, CFCO training gives freight teams practical habits for identifying impersonation attempts before criminals can capture valuable credentials.
The program reinforces identity checks, access controls, domain verification and escalation procedures that can be incorporated into everyday operations. Those practices can help employees recognize when an apparently urgent request is asking them to make profile changes through an unfamiliar website.
For trucking companies navigating the Motus transition, that additional layer of awareness can make the difference between clicking a suspicious link and reporting it as a potential threat.















