The NMFTA cybersecurity conference in Long Beach emphasized AI’s role in empowering cybercriminals in the freight industry rather than providing immediate defensive solutions. Speakers warned about deepfakes, agentic AI and "shadow AI"—internal, unsupervised use that can increase risk—and described how polished, AI‑driven scams are outpacing traditional detection methods. IT Architeks recommended a five‑point defensive checklist focused on ownership, assessments, incident response testing, vendor audits and backup restoration. Panelists said defenders are evaluating AI tools, but companies must prioritize tested fundamentals now.
Freight Cybersecurity: At NMFTA Conference AI Is More Threat Than Shield — For Now

Long Beach, California — At the only conference focused specifically on freight cybersecurity, artificial intelligence emerged as a growing threat rather than a ready-made defense. During morning sessions at the National Motor Freight Transport Association (NMFTA) cybersecurity meeting for the less‑than‑truckload (LTL) industry, speakers warned that cybercriminals are increasingly using AI to scale, polish and automate attacks.
AI’s Dark Side: Deepfakes, Agentic AI and Shadow AI
James McQuiggan, advisory chief information security officer at Apparent Security, framed his remarks around the “dark side” of AI. He demonstrated how deepfakes can steal voices and likenesses, and explained that large language models (LLMs) and agentic AI are being used by attackers to automate reconnaissance and craft highly convincing fraud.
“We’ve been experimenting with large language models and agentic AI for years, and cybercriminals are doing the same,” McQuiggan said. He warned that AI risks arise not only from external attacks but also from employees’ unsupervised use of AI—what he called shadow AI.
McQuiggan emphasized that staff often adopt AI tools innocently to boost productivity, but uncontrolled use can expose sensitive data and expand the attack surface for external adversaries.
Social Engineering Gets More Convincing
Todd Florence, chief information officer at Estes Express, shared how attackers set up fake LinkedIn profiles—sometimes using attractive photos—to socially engineer employees into connecting and sharing information. McQuiggan added that agentic AI makes it easy to scrape LinkedIn, corporate websites and employee profiles to assemble believable fake identities and spoofed domains. Phishing messages now often lack the obvious grammar or spelling errors that once exposed scams.
Ransomware actors are also leveraging AI. McQuiggan warned that bad actors can invest roughly $100,000 in a sophisticated deepfake campaign and demand ransom payments in the millions.
Practical Defense: A Five‑Point Cyber Battle Plan
Melanie Padron, vice president of strategic growth at IT Architeks, outlined her firm’s five‑point “cyber battle plan” for transportation companies:
- Name a clear executive or manager who owns cybersecurity responsibilities.
- Confirm the timing of the last independent cyber risk assessment.
- Verify when the incident response plan was last exercised or updated.
- Perform a full vendor access audit to identify third‑party risks.
- Conduct a comprehensive backup restoration and access audit to ensure recoverability.
Padron used a practical analogy: if you install a new brake system on a truck, you test, inspect, document and train on it—cybersecurity should be treated the same way.
Where Defenders Stand
On the sidelines, Padron noted that IT Architeks and other vendors are evaluating AI tools designed to detect and manage shadow AI and other internal risks. Panelists including Erica Brigance, vice president of technology at ArcBest, and Todd Florence said defenders are experimenting with AI-driven tools, but stressed that basic controls—ownership, risk assessments, incident response testing, vendor audits and verified backups—remain the highest priority.
Florence’s remarks recalled Estes’ major attack on October 1, 2023, and the company’s highly public recovery efforts. That incident remains a cautionary example of the reputational and operational costs of a successful cyberattack.
Bottom Line
At this NMFTA meeting, the consensus was clear: AI is already reshaping the threat landscape for transportation cybersecurity, and attackers are moving quickly. While defensive AI tools are emerging, transportation firms should first harden fundamentals and regularly test plans and recovery procedures to reduce the risk of becoming a target.
Help us improve.


































