LIVE · cybersecurity feed
Live wire
ai

‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware

Experts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.

zeroday.news ·

Criminal organizations are reportedly employing increasingly brazen and violent tactics to steal high-value AI hardware and data center equipment, according to industry experts and law enforcement sources. Two recent incidents in California involved the deliberate immobilization of security escort vehicles accompanying shipments of technology from Silicon Valley to Southern California, followed by the disappearance of the semi-trucks and their cargo.

In one instance, a security escort vehicle was rear-ended in what appeared to be a hit-and-run. In another, an escort vehicle was forced into a tailspin by a PIT maneuver. In both cases, the escorts were rendered inoperable, and the semi-trucks, which continued without stopping, were subsequently lost, along with millions of dollars in data center gear. While law enforcement has not publicly confirmed details due to ongoing investigations, cargo industry professionals, including J.J. Coughlin of the Southwest Transportation Security Council and Danny Ramon of Overhaul, have corroborated aspects of these events, describing them as "coordinated assaults" targeting "AI hardware."

The consultant and former Los Angeles sheriff’s detective Gerardo Pachuca, who has investigated cargo theft for 25 years, stated that he has never witnessed such audacious methods. He, along with Coughlin and Ramon, believes the truck drivers were likely complicit, a growing trend in cargo theft. No injuries were reported in either incident, and the perpetrators remain at large. This escalation in tactics has raised concerns that these isolated cases could signal a new, violent trend in freight crime, now often facilitated by cyber-based scams.

Cargo theft has seen a rise since the start of the COVID-19 pandemic, with the booming AI data center industry creating a lucrative new target. Although the overall number of thefts decreased by 26 percent year-over-year last quarter, the value of stolen goods more than doubled, driven by criminals targeting expensive cargo. Verisk CargoNet, an analytics and risk assessment firm, noted that these high-value shipments often travel with standard security, creating a significant mismatch between their financial worth and their transportation security profile.

Examples of high-value thefts include an April incident where 34,560 optical transceiver cables and 96 network switch modules, components used in data centers, were reportedly stolen en route from Olive Branch, Mississippi, to Richardson, Texas. Law enforcement has had some success in recovering stolen goods. In May, authorities in Southern California seized $4 million worth of stolen cargo, including Deepcool AI data center cooling equipment, and made one arrest. In June, the California Highway Patrol recovered over $2.2 million in merchandise from three separate incidents, including eight pallets of Celestica server switches for Meta, valued at $550,000, after a prospective buyer reported a suspicious deal. The same day, approximately $1 million in data center equipment, including Meta server switches, was found in a reportedly stolen trailer in the Chicago area.

Modern cargo heists frequently exploit the fragmented nature of the freight industry. Rather than physical break-ins, criminals often use social engineering or phishing to hack into truck operators' email accounts, take over their businesses, and use legitimate motor vehicle registrations to sign up for shipments. GPS trackers on stolen trucks can be spoofed or deactivated to evade detection. Another method involves legitimate business owners illegally selling their motor carrier numbers, which are unique identifiers assigned by federal regulators to trucking companies.

The increased value of cargo has led to a surge in demand for escort companies, which serve as a final line of defense. Michael Duffy, CEO of Solutions Group International, noted that his escort business, once primarily busy during holiday shopping seasons, now operates year-round, with clients moving liquid cooling parts, servers, and computer chips. Escort operators are now exploring ways to enhance security, with some encouraging personnel to contact emergency services at the first sign of suspicion.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of […]

ai

Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do

Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'

ddos

Large-scale DDoS attacks disrupted Threema secure messaging service

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]

security

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows […]

malware

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]

breach

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit […]