Fake MOTUS Portals Are Turning Registration Updates Into Credential-Theft Traps

By Eric Bratton, Founder and Executive Editor, Freight Intel Report

Published

FMCSA’s registration-fraud warning is not a generic reminder to watch
for suspicious email. It identifies a specific impersonation pattern
built around Motus, the agency’s motor-carrier registration system:
messages that pressure recipients to complete an “off-cycle update”
through a fake “New MOTUS Portal.”

The distinction matters because a registration-update request can
look operationally plausible. Carrier and broker records do require
maintenance, and a rushed compliance message can reach accounting,
safety, dispatch or executive staff who are accustomed to acting quickly
when authority or registration appears at risk. The fraud succeeds when
urgency substitutes for independent verification.

FMCSA lists four bogus domains associated with the scheme:

  • dot.motusdatasboard.com
  • dot.motusdatadesk.com
  • dot.motuswebdeck.com
  • dot.motusfunction.com

The legitimate service is FMCSA’s Motus registration system. FMCSA
also notes a visual clue: the real product name is “Motus,” not an
all-capital “MOTUS” label used to make a fake portal look official.
Navigate directly to FMCSA’s official website and independently verify
its address before entering credentials or business information.

Why
shippers should care about a carrier-registration phishing campaign

The immediate targets may be motor carriers and other FMCSA
customers, but compromised credentials or identity data can move
downstream into shipper risk. A criminal who captures registration
information, personal information or account access may gain material
that can be used to impersonate a transportation provider, alter
public-facing contact details, support fraudulent onboarding, or make a
later cargo or payment instruction appear more credible.

That does not mean every phishing victim will become a cargo-theft
incident, and FMCSA’s alert does not establish that the listed domains
have been used to divert freight. The operational lesson is narrower:
registration identity and freight identity should be treated as
connected controls. A suspicious compliance notice is not only an IT
matter when the affected record helps shippers and brokers decide who
may receive a load.

The five-control response

  1. Do not use the link in the message. Navigate
    directly to FMCSA’s official website and independently verify its
    address before entering credentials or business information.
  2. Separate compliance urgency from freight urgency.
    Do not allow a claimed registration deadline to bypass carrier
    onboarding, pickup verification or payment-change controls.
  3. Escalate unexpected record-change requests. Require
    a second reviewer and an out-of-band callback to a previously validated
    contact before changing carrier, broker, bank, email, phone or dispatch
    records.
  4. Reverify after a suspected compromise. If a
    transportation provider reports clicking a false portal or disclosing
    information, independently confirm authority, insurance, known contacts,
    driver and equipment details before the next release.
  5. Preserve and report the evidence. Save the message,
    headers, domain, screenshots and timestamps. FMCSA directs targets to
    its Contact Center and also identifies the Federal Trade Commission, FBI
    Internet Crime Complaint Center, local police and state attorneys
    general as reporting channels. Navigate directly to the relevant
    agency’s official website and independently verify its address before
    submitting credentials or business information.

A practical handoff rule

No single email-domain check can prove that a carrier, broker or
shipment is safe. The useful rule is procedural: when a compliance
message introduces a new link, contact, credential request or record
change, pause the affected transaction until the request is verified
through a channel obtained independently.

That control belongs at the intersection of cybersecurity, carrier
onboarding and freight release. If those teams treat the event as
somebody else’s problem, the fraudster gets the gap.

Source

External addresses are presented as plain text under FIR’s source
policy.

  • FMCSA, “Fraud Alerts,” current alert on bogus Motus apps and links.
    Address: fmcsa.dot.gov/registration/fraud-alerts

This article is general educational information, not legal,
regulatory, compliance, cybersecurity, insurance or business advice.
Users remain responsible for independent verification and their own
policies and decisions.

Get the signal before the market moves.

Independent freight intelligence for shippers, carriers and brokers—delivered when the development is worth your attention.

We don’t spam! Read our privacy policy for more info.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *