LONG BEACH, California – If you came to the only known cybersecurity conference dedicated to the freight industry hoping to hear about AI-powered defenses, you were probably disappointed. At the event organized by the National Motor Freight Transport Association (NMFTA), the trade group serving the LTL sector, artificial intelligence came up mostly as a threat.
Over the first half of day one, AI was either barely mentioned or came with a warning: the bad actors are about to use it, and an already difficult fight is about to get harder. No one stood up to announce a company with a breakthrough AI tool to protect carriers and curb freight fraud.
The dark side of AI
The session by James McQuiggan, advisory chief information security officer at Apparent Security, captured the mood. He was introduced as the man who would explain “the dark side of AI,” meaning how cybercriminals put it to work. He delivered exactly that, with no mention of tools that could help security teams keep intruders from crashing a system and holding it hostage.
McQuiggan showed examples of deepfakes, with AI used to steal voices and appearances and build convincing deceptions.
“We’ve been playing around with large language models and agentic AI now for the last four plus years, and cybercriminals are doing the same thing,” he said.
The danger doesn’t only come from outside. McQuiggan warned that AI can open vulnerabilities from within, through what he calls “shadow AI”: employees using AI tools that then go awry. Companies shouldn’t assume the worst of their staff, he said. “You know that your users are going to be leveraging AI capability. They want to. They’re not doing it to be malicious. They’re doing it because they want to be more efficient.” Still, he stressed, employees must be trained on how their use of AI at work can increase the risk of a successful attack from outside.

LinkedIn was already a topic at the 2025 edition of the conference. Todd Florence, CIO of Estes Express, described how outside cybercriminals created fake profiles of attractive women, hoping an employee, presumably a man, would try to connect with them, first professionally and perhaps later more personally.
This year, McQuiggan’s take on LinkedIn was far less amusing, and AI was at the heart of it. “It’s a lot easier with agentic AI to be able to go through and collect all the information that they need overall,” he said. According to him, criminals scrape LinkedIn, company websites and employee information, targeting shippers, brokers and carriers alike. “If you’ve got fake ones that are being generated, you’re going to deal with a lot of fraud, deal with a lot of spoofed domains, all trying to make money.”
He contrasted today’s scams with the fraudulent emails of just a few years ago, notorious for their typos and clumsy grammar. Content produced by an LLM is now polished and free of those telltale errors. “In the last couple of years, we’ve been hearing about agentic AI being able to leverage that, scheduling things for us, looking at our email and sending out responses,” he said, adding that ransomware attacks are “fully leveraging AI.”
The economics are what should worry companies most. A criminal can spend as much as $100,000 on a deepfake campaign and walk away with a ransom payment in the millions.
A small gathering, a focused audience
The NMFTA meeting is relatively small, but the people in the room are intensely focused on the issue. Some work for carriers, others sell cybersecurity services to companies trying not to become a target, and a number of government officials attend as well.
Among the speakers was Melanie Padron, vice president of strategic growth at IT Architeks, who works exclusively with transportation companies on cybersecurity. She laid out the five-point “cyber battle plan” her firm follows with companies considering its services, in line with the call to action that has become the theme of these recent meetings:
-
Clearly identify who at the company owns cybersecurity, which isn’t always obvious.
-
Find out when the last independent cyber risk assessment took place.
-
Determine when the incident response plan was last reviewed.
-
Carry out a full vendor access audit.
-
Establish when the last full backup restoration audit was performed.
On that last point, Padron drew a comparison from the trucking world. “Do you have a new brake system for your trucks? Would you just trust the word, or would you test it? You test it. You inspect it. You document it. You train your drivers on it. Cybersecurity should be no different.”
Some positive AI uses on the horizon
Away from the stage, Padron pushed back on the idea that AI isn’t yet helping the defenders. She said her company is currently evaluating several AI tools aimed at the “shadow AI” problem McQuiggan described.
The Estes attack is still remembered
One of the first panels brought together two people on the front lines of trucking cybersecurity: Erica Brigance, vice president of technology at LTL carrier ArcBest (NASDAQ: ARCB), and Florence, who was appearing at another NMFTA cybersecurity event.
Florence is something of a rock star in this world. He was the chief technology official at Estes when the LTL carrier suffered a massive cyberattack on October 1, 2023, three years ago to the day, give or take: the panel took place one day before the anniversary. CEO Webb Estes was widely praised for his openness with the public about the company’s ordeal, and when he made a public broadcast to update customers and others on the recovery, Florence stood at his side.
Speaking to FreightWaves at the conference, Florence said he made numerous phone calls to customers during that period. What surprised him, he said, was how many of them responded with some version of “when we had our cyberattack.”
For Brigance, the pressure never lets up. “The threats are increasing, and the way that we are combating that is also changing greatly,” she said. “But it’s ever present. It certainly keeps me up at night. It’s certainly the reason why, as soon as I wake up in the morning, I’m looking at my phone as well.”





















