A conventional sleeper tractor coupled to a dry van trailer at a rain wet carrier yard early in the morning
    Industry News

    Does Insurance Cover MC Authority Theft? The Real Cost

    TruckerPath Team

    Get Your Free Insurance Quote

    Compare quotes from top carriers in minutes

    Standard commercial trucking insurance does not cover losses from MC authority theft, also called authority hijacking or a stolen MC number, caused by phishing, credential theft, or fake portal payments. Auto liability, cargo, and physical damage policies are written to pay for crashes, cargo damage, and physical loss of a vehicle. They are not written to reimburse you for a stolen Login.gov password, a fraudulent change to your FMCSA profile, or a $200 fee you paid to a scammer who promised to "unlock" your registration. That gap matters right now because of what FMCSA disclosed on September 15, 2026.

    What happened with the Motus registration scam

    On September 15, 2026, FMCSA warned that fraudulent emails are directing motor carriers to four bogus websites built to mimic the agency's new Motus registration portal, according to FreightWaves. The phishing emails use the subject line "Notice of Required Off-Cycle Update" to pressure carriers into acting immediately, per the same FreightWaves report. FMCSA is advising anyone who clicked a suspicious link or entered account information to stop using that link, call the FMCSA Contact Center at 1-800-832-5660, and change their Login.gov password if credentials were entered, according to US Compliance Services.

    Separate from the phishing emails, some carriers have paid third-party "service providers" fees of around $200 after being falsely told the payment would unlock or expedite their stalled Motus registration, according to Truck News. The American Bus Association separately reported members receiving emails claiming their carrier account required an "off-cycle information update" and citing a fake carrier access code, per the American Bus Association. Motus itself is real: it's FMCSA's new unified registration platform, rolled out in phases starting in May 2026 to replace the old Unified Registration System, the registration side of MCMIS, and the legacy ICC licensing and insurance system, according to the Federal Register.

    Does trucking insurance cover MC authority theft or phishing losses?

    No, not under a standard policy. Commercial auto liability, motor truck cargo, and physical damage coverage respond to specific triggers like a collision, a stolen load, or a cargo claim from a shipper. They do not respond to "I gave a scammer my Login.gov password" or "I paid a fake fixer $200." Those are social engineering and fraud losses, and most standard trucking policies carry an exclusion for exactly that kind of loss because it doesn't involve a vehicle, a crash, or physical damage to freight.

    The bigger financial exposure isn't the $200 fee itself. It's what happens downstream if a fraudulent Motus account change alters your authority status, your insurance filer of record, or your company profile without your knowledge. Because Motus now consolidates your USDOT registration, your operating authority, and the BMC-91 or BMC-91X financial responsibility filings your insurer files on your behalf, according to FMCSA Registration Forms (current as of September 2026), a compromised account can create real gaps: your authority could show as inactive when a shipper or broker checks it, or your listed insurance filer could get quietly swapped. Either one can trigger a coverage dispute or a lost load right when you need your authority to be clean. You can verify your own authority status anytime directly at fmcsa.dot.gov, never through a link in an email, and you should always confirm regulatory specifics with FMCSA or your state department of insurance rather than relying on any single article, including this one. For the federal liability rules that sit alongside these filings, see 49 CFR Part 387.

    What does closing this coverage gap actually cost?

    A cyber or social engineering fraud endorsement, the coverage type built to pay for exactly this kind of loss, is not something every trucking policy includes by default, and not every insurer offers it as an add-on for small fleets. Where it is available, expect it to run as an added annual premium rather than a flat fee, and the number moves depending on your fleet size, your revenue, and whether you're adding it to an existing package or buying it standalone. As a dated estimate as of September 2026, small-fleet endorsements of this type have run in a rough range of a few hundred to a few thousand dollars a year, though this figure has no single authoritative publisher and should be confirmed carrier by carrier when you request quotes.

    ScenarioWho pays without an endorsementRough cost exposure
    Paid a fake "portal unlock" fixer feeYou, out of pocketAround $200 per the Truck News report cited above
    Fraudulent authority status change causes a lost load or contractYou, no standard coverage appliesVaries, can exceed a single load's revenue
    Double-brokering scheme exploits a spoofed carrier profileYou may face a contested cargo claimFull cargo value in dispute, potentially thousands
    Cyber/social engineering fraud endorsement added to policyInsurer, up to policy limitDated estimate, roughly a few hundred to a few thousand dollars a year in added premium
    Standard FMCSA-required liability minimums (not related to fraud)Insurer, per policy, up to the limit purchased$750,000 minimum for general freight, $1,000,000 typical in practice, per 49 CFR Part 387

    The line that should worry you most isn't the $200. It's the double-brokering row. If a fraudulent profile change lets a bad actor pose as a legitimate carrier or broker of record, your cargo can end up in a contested claim with no clean paper trail, and standard cargo coverage was never built to untangle that kind of fraud. That's an operational risk, not just a paperwork risk. The federal liability minimums in the table above are a separate, unrelated coverage requirement; they exist to cover crashes and cargo damage, not fraud, which is exactly why a fraud loss falls outside them.

    What raises or lowers your exposure here?

    Your exposure depends mostly on how much of your paperwork trail runs through a single login and how often you check it. A few things move the number in either direction.

    Carriers who never log into their FMCSA or Motus account except through a bookmarked, verified link are less exposed than carriers who click email links out of habit. Carriers who use a broker to handle their BOC-3 and BMC-91 filings have a second set of eyes that can flag a mismatch, which is part of why working with a broker who tracks your filings matters more during a rocky system rollout than during normal operations. Fleets running multiple trucks under one authority have more to lose if that authority gets flagged inactive, since every truck under it goes down at once rather than one owner-operator's single unit.

    The volume of activity flowing through the FMCSA system right now also matters. Trucker Path Insurance tracked 20,659 brand new motor carrier authorities entering the federal register between April 2, 2026 and September 14, 2026, alongside 13,608 existing carriers expanding their authority, and 1,149 new broker authorities in that same window, roughly one for every 18 new motor carrier authorities. That's a lot of new accounts, new logins, and new broker relationships being created at once, which is exactly the kind of environment where a spoofed portal or a fake "off-cycle update" email is more likely to catch someone off guard. Separately, Trucker Path Insurance tracked 47,234 FMCSA insurance cancellation filings nationwide between April 6, 2026 and May 25, 2026, a reminder of how much authority status changes hands even without fraud involved, and how easy it is for a single account compromise to get lost in that churn.

    What should you do about it right now?

    Check your authority status only by typing fmcsa.dot.gov directly into your browser, never through a link in an email. If you clicked a suspicious Motus link or entered your Login.gov credentials anywhere that felt off, follow the steps outlined above: stop using that link, call the FMCSA Contact Center, and change your password right away.

    Ask your agent or broker to confirm your BOC-3 and BMC-91 filings still show correctly in Motus after any recent account activity, and ask specifically whether your policy includes a cyber or social engineering fraud endorsement, since most standard commercial auto and cargo policies exclude losses from phishing-induced credential theft or fraudulent fee payments. If you're not sure what your current policy covers, our trucking insurance tips page walks through the coverage types worth asking about, and our overview of truck insurance options covers how liability, cargo, and add-on endorsements fit together in one package.

    Frequently Asked Questions

    Share this article

    FacebookXPostText

    Ready to Get Started?

    Get personalized insurance quotes tailored to your business

    Ask me anything!