Joe Ohr
Article Summary
As cybersecurity researchers demonstrate the ability to manipulate commercial truck systems, the industry must move past easily exploitable, self-certified ELDs to protect hours-of-service regulations and keep fatigued drivers off the road.
- Trucking vulnerabilities exposed at DEF CON: The NMFTA showcased commercial vehicle vulnerabilities at the hacker conference, revealing how easily truck systems—including braking controllers—can be manipulated.
- The flaw in self-certification: Relying on manufacturers to self-certify ELDs creates a system ripe for manipulation, turning what should be a safety device into a tool to bypass Hours-of-Service (HOS) regulations.
- The white-label loophole: Roughly three-quarters of registered ELDs share underlying hardware and software, meaning revoking a single noncompliant model does not fix the root vulnerability on America’s highways.
- A call to action for the FMCSA: The FMCSA must overhaul its registry by requiring independent third-party testing, Software Bills of Materials (SBOMs), and the ability to revoke entire families of noncompliant white-labeled ELDs.
DEF CON, one of the world’s largest hacker conferences, is a weeklong event that brings cybersecurity professionals, researchers, students and hobbyists together each August in Las Vegas to share their findings and get their hands on technology to see what they can do with it.
To many in the cybersecurity and information technology industries, this is the premier event of their professional year. For me, it was a scary event where I saw what was actually possible.
This year, the National Motor Freight Transportation Association (NMFTA) brought the trucking industry to DEF CON. NMFTA extends its sincere thanks to Hirschbach for working with us to make this experience a reality, and to the Maritime Hacking Village for providing the space, support and partnership needed to make the event such a success.
In the village, attendees could examine and attempt to hack into the connected devices used by the entire supply chain, from shipboard maritime systems to freight terminal operations, railroads and now trucking.
DEF CON attendees had the opportunity to connect to the vehicle and test their ability to identify and interact with truck systems. Most of us are around trucks quite a bit; it was fun to watch people interact with and climb into the cab. We even had to ask people to please not pull the horn. The truck attracted participants of all skill levels, from those connecting to a truck for the first time to experienced hackers who arrived with specific targets in mind.
The hands-on experience provided a unique opportunity for attendees to explore the cybersecurity of commercial vehicles in a real-world environment.
NMFTA cybersecurity researcher Ben Gardiner presented his findings into a security patch quietly included into a software update pushed out as part of a safety recall for braking controllers found in tractors and trailers. The flaw allowed for a remote attacker to disable the anti-lock braking systems on tractors, putting drivers and their cargoes in danger.
NMFTA acquired Bendix EC80 units and examined pre- and post-patch firmware versions on these devices. We discovered that the security update was not associated with a published Common Vulnerability and Exposure (CVE) entry, which obscured facts from carriers which could lead to flawed risk assessments.
Though the vulnerability was patched, Gardiner emphasized the nature of modern truck telematic devices requires transparency from manufacturers about security vulnerabilities and what the manufacturers are doing about them. NMFTA believes a lack of a CVE slowed down the adoption and criticality of the patch.
Call to action: End ELD self-certification
The purpose of an ELD is not to create an electronic log. Its purpose is to create a trustworthy electronic record. Hours-of-service (HOS) rules exist for one fundamental reason: fatigued drivers operating 80,000-pound commercial vehicles are a threat to everyone on the road.
For decades, enforcement depended largely on paper logbooks. That system had an obvious weakness; the person being regulated was also responsible for documenting compliance. Drivers determined what went into the logbook, and dishonest operators could maintain records that showed compliance regardless of what occurred.
ELDs were supposed to change that. The ELD mandate replaced trust in handwritten records with trust in technology. ELDs automatically capture vehicle and driver activity, reduce the administrative burden on drivers and provide law enforcement with a standardized mechanism for verifying HOS.
But that system only works if the ELD itself can be trusted. Today, that trust is not adequately protected. ELD manufacturers self-certify their devices when registering them with the Federal Motor Carrier Safety Administration (FMCSA). The government and the trucking industry are therefore relying heavily on manufacturers to attest that their own products comply with federal requirements and accurately record driver activity.
For a technology that serves as a primary enforcement mechanism for federal HOS regulations, self-certification is no longer sufficient. As we know, an ELD is a computer. It contains hardware, software, communications capabilities, databases and applications. Like any computer system, it can contain vulnerabilities or functionality that allows information to be manipulated. If an ELD can be intentionally altered to make a driver appear compliant when that driver has exceeded legal HOS, the ELD is no longer a safety device; it becomes a tool for defeating the regulation it was designed to enforce.
The white-label problem makes this far worse
NMFTA’s own research identified an even more serious systemic weakness: white-labeled ELDs. Of approximately 1,050 ELDs registered with FMCSA, NMFTA researchers determined that roughly three-quarters appear to share underlying hardware and software with other registered devices.
Essentially identical products can be rebadged and registered under dozens — or even hundreds — of different names. That means revoking a single model may accomplish very little.
FMCSA currently revokes ELD registrations largely on a model-by-model basis. But if the underlying hardware, software, application or backend infrastructure is shared across numerous registered products, removing one name from the registry does not necessarily remove the underlying problem from America’s highways.
It can simply change names
NMFTA’s research indicates that approximately 720 currently registered ELD models may share the same underlying vulnerability. If an ELD is revoked, an operator may be able to move to another registered product using substantially the same hardware and software. In some cases, the same physical hardware may be used with a different Android application. In others, multiple products may even rely on shared backend infrastructure.
So, let’s pause and take a moment to think about what that means. A regulator can identify a problem, revoke an ELD, announce that action to the industry — and the same underlying technology may continue operating legally under another name.
That is not an effective certification system. It is a loophole. And sophisticated, bad actors know how to exploit loopholes.
This is not merely a paperwork or technology issue. An ELD capable of falsifying HOS records can allow a driver to operate beyond federally permitted limits while presenting apparently legitimate records during an inspection. The result is potentially a fatigued driver operating a commercial motor vehicle next to families traveling on America’s highways. That makes ELD integrity a public safety issue.
Certification must follow the technology, not the label on the box or on the application
FMCSA should move away from a system that primarily certifies and revokes individual product names and toward one that evaluates the underlying technology and organizations behind those products. At a minimum, FMCSA should:
- Require a Software Bill of Materials (SBOM) identifying the software components used by every registered ELD.
- Require independent, third-party testing and attestation of ELD accuracy, security and resistance to tampering.
- Identify common hardware, software, applications and backend infrastructure across white-labeled products. That is a question on the form.
- When a vulnerability or intentional manipulation capability is identified, investigate and, when warranted, revoke the entire affected family of ELDs — not simply one model name.
- Proactively analyze ERODs data for anomalies associated with specific devices and device families.
- Require meaningful alerts and records when an ELD is disconnected, disabled or otherwise prevented from accurately recording vehicle activity.
- Train roadside inspectors to recognize indicators of ELD manipulation and known problematic ELD families.
- Strengthen accountability and oversight for ELD providers whose critical operations are conducted outside North America.
- Validate the integrity of the FMCSA ELD registry itself, including manufacturer identities, physical addresses, telephone numbers, email addresses and other registration information.
Most importantly, these requirements need deadlines and consequences. Existing ELD providers should be given a defined period to meet strengthened certification requirements. Providers that cannot demonstrate compliance, security, data integrity and resistance to manipulation should lose their certification.
The trucking industry should not have to guess whether a federally registered ELD actually does what it claims to do. Law enforcement should not have to wonder whether the hours displayed on a roadside inspection are real. And the motoring public should not bear the risk created by technology designed to make an exhausted driver appear compliant.
The purpose of an ELD is not to create an electronic log. Its purpose is to create a trustworthy electronic record. If that record cannot be trusted, the entire regulatory system built around it begins to fail.
Self-certification has reached its limit. FMCSA should independently verify these devices, identify the technology behind white-labeled products and remove entire families of noncompliant ELDs from North America’s highways.
Yevgeniy Melnik
- Multiple logbook fraud (double-logging)
Some drivers maintain two sets of logs — one for the ELD, one for reality. Logs are edited or selectively erased to make it appear the driver was resting when they were actually driving. Brokers booking these drivers may unknowingly assign loads to operators running well outside legal HOS limits.
Impact on brokers and law enforcement:
- Severe legal exposure if a load is assigned to a fraudulent carrier and an accident follows.
- Plaintiff attorneys cite the falsified logs as evidence of negligent selection.
- FMCSA violations can revoke carrier authority.
How to prevent it:
- Vet carriers against ELD compliance history before booking.
- Monitor logs for excessive manual edits — a high edit count is a tell.
- Use AI-based fraud detection that flags double-logging patterns automatically.
- Night-time deliveries while logs show sleep hours
Drivers falsify sleep periods on the ELD while continuing to drive overnight. Carriers under pressure to complete urgent loads may push drivers to do this. Brokers booking overnight deliveries may not realize the driver is in violation until something goes wrong.
Impact:
- Fatigue-related crashes are dramatically more likely when the driver hasn’t actually slept.
- If a manipulated log is discovered after a crash, liability exposure increases sharply.
How to prevent it:
- Cross-reference log entries against geolocation pings and fuel-transaction data.
- Train enforcement personnel to spot the inconsistencies between claimed sleep periods and the truck’s actual movement.
- Disconnecting the ELD device
Some operators physically disconnect or tamper with the ELD to avoid recording driving hours entirely. This lets carriers consolidate multiple loads or hide excess driving time — boosting profit per truck while violating compliance.
Impact:
- Shipment tracking becomes unreliable; ETAs are inaccurate.
- Audits become difficult because the operational record has gaps.
- Brokers who unknowingly book these carriers face the same negligent-selection exposure.
How to prevent it:
- Require tamper-resistant ELDs that alert on unauthorized disconnects.
- Use independent GPS tracking that doesn’t rely on the ELD.
- Cross-reference log timestamps against pickup and drop-off records.
Some carriers also consolidate multiple shipments without informing the broker, which compounds these issues. See our guide on unauthorized load consolidation for more on how that works and how to detect it.
How brokers and law enforcement should respond
ELD manipulation isn’t a niche problem. It’s the entry point to fatigue crashes, freight fraud, and significant broker liability. Effective response combines policy, technology, and ongoing audits.
- Use ELD verification tools. Validate device tamper-resistance and check for known compromise patterns.
- Audit carrier logs regularly. Suspicious edit counts and mismatched trip data are detectable signals.
- Cross-check telematics, fuel, and toll data. Independent data sources catch most manipulation; the gaps light up when you correlate them.
- Implement AI-based fraud detection. Software that flags manipulated ELD records and alerts compliance teams scales the audit function.
If you want help building or auditing a carrier compliance program — or you’re a mid-size brokerage that doesn’t have a Director of Risk on staff — that is what fractional risk consulting is for. Three tiers, retainer-based, no exclusivity.
Frequently asked questions
What is ELD manipulation?
ELD (Electronic Logging Device) manipulation is the falsification of a driver’s hours-of-service records — typically to hide driving time that exceeds federal limits. Common methods include running parallel log sets, marking driving time as sleeper-berth, and physically disconnecting the device while driving.
How do brokers detect falsified ELD logs?
Cross-reference log entries against independent data sources. Geolocation pings, fuel-card transactions, toll records, and pickup or delivery timestamps each capture the truck’s actual location at known times. When ELD logs claim a driver was resting at 2 AM but a fuel transaction places them on the road, you have proof of falsification.
What are the FMCSA penalties for ELD tampering?
Civil penalties for ELD violations can exceed $10,000 per occurrence under 49 CFR 395, plus suspension or revocation of operating authority. Criminal charges are possible when falsification is willful and contributes to an accident. Carriers caught tampering generally face out-of-service orders during roadside inspections.
Can a broker be held liable for a carrier’s ELD violations?
Yes — particularly under negligent-selection and vicarious-liability theories. If a broker books a carrier with a known pattern of ELD violations or HOS infractions, and a driver from that carrier crashes, plaintiff attorneys will argue the broker was on notice. Documenting carrier vetting and rejecting carriers with poor compliance histories is the strongest defense.
Jenny Glasscock
Hours-of-service violations are fairly easy to detect on a driver’s log. After all, ELDs are designed to keep track of drivers’ hours and will flag instances when they exceeded their allotted driving time.
However, just because the ELD system did not detect an HOS violation doesn’t mean it’s not there, concealed by log falsification.
The issue of log falsification isn’t new. It was prevalent both in the days of paper logs and still today in the ELD era. What has changed is the way drivers falsify logs: unplugging an ELD, working without being logged in or making deliveries while on personal conveyance, for example.
Log falsification isn’t something carriers should take lightly. According to FMCSA data from 2019 to 2023, “a false report of driver’s record of duty status” accounted for 4.9% of all roadside inspection violations, was the fourth most common driver violation and one of the top out-of-service violations.
While law enforcement can only see a driver’s logs from the last eight days, carriers and drivers aren’t out of the woods once this time passes. Companies are required to retain drivers’ logs for six months, which exposes them to the risk of fines or a reduction in their safety rating.
“If there comes a time when you have a crash and attorneys or law enforcement start digging into your records and find falsifications, it’s all going to come to the surface. That’s probably the worst thing that could happen when it comes to hours of service,” said Brian Runnels, vice president of safety at Reliance Partners, a Tennessee-based trucking insurance agency that aims to help motor carriers manage safety risk.
This is why it’s vital that safety departments understand how drivers falsify logs, look out for it daily and address it internally to prevent it from happening in the future. Runnels identified three valuable reports safety personnel should watch for signs of log falsification.
Reports to help catch log falsification
- Odometer report
An ELD’s odometer report provides a truck’s mileage from the beginning and end of each day.
A jump in the odometer reading from day to day means the ELD did not record those miles, which is a red flag that can be a sign the device came unplugged. Drivers can unplug the device in order to avoid being tracked by the ELD and hide the fact they drove beyond their hours-of-service limits.
“Those miles must be assigned to whoever was in the truck,” Runnels advised. “It could have been in the shop and moved around by the mechanic. But if there’s no good reason, it must be assigned back to the driver.”
- Unidentified driving report
When a driver logs out of his or her ELD and drives, but the device is still plugged in, the miles driven are still recorded. However, in most cases, the hours are not automatically added to the driver’s log.
Once the driver logs back into the system, most ELDs will ask drivers to claim any time driven as on-duty driving time. It will be considered unidentified, or unassigned, driving time if it is not claimed by the driver.
While sometimes not claiming unidentified driving time is a mistake, it’s also something drivers do when trying to conceal HOS violations; if drivers were to accept that time as on-duty drive time, it would put them over their legal work hours.
Motor carriers must retain unidentified driving records for six months, and as per the Federal Motor Carrier Safety Regulations (FMCSRs), they must “annotate the record, explaining why the time is unassigned; or, assign the record to the appropriate driver to correctly reflect the driver’s hours of service.”
Safety personnel will need to determine whether unassigned driving time should be assigned as on-duty driving time, on-duty yard move or off-duty personal conveyance. The driver then must verify it and accept it on his or her log.
- Personal conveyance report
Personal conveyance is driving done off duty for a non-working reason and does not count toward a driver’s hours of service limits. Drivers falsify logs by misusing personal conveyance, often switching from on-duty driving to personal conveyance once their available hours are up. This can be to finish delivering their current loads, advance their locations for their next pickups or even to perform other work-related moves such as driving to the repair shop.
Motor carriers should pull their fleets’ personal conveyance reports and review all annotations from drivers to ensure they are adhering to FMCSA guidelines and company policy.
Current FMCSA parameters for personal conveyance do not include specific time or distance limits, only descriptions for when it can be used, which some consider too vague. Drivers who unintentionally use personal conveyance improperly can still be dinged for false logs.
“That may have a drastic effect on a company’s safety scores because those rules are weighted so heavily. A lot of the time, drivers are also put out of service, so that is going to add points to their hours-of-service score. When you start getting a few of these falsifications, that will really wreak havoc,” Runnels said.
Carriers can enforce stricter personal conveyance guidance or turn off the function altogether, but this may not solve the root of the problem entirely: Runnels said this tends to cause an uptick in HOS violations. This could be because drivers are still met with the same scenarios that caused them to use personal conveyance in the first place.
Preventing log falsification
Whether it happens on paper or an ELD, the core reason for log falsification still remains the same: “It’s all about getting somewhere with not enough time to get there,” Runnels said.
This is an issue the industry as a whole has always grappled with but will not hold up as an excuse in the eyes of the law in roadside inspections.
Runnels recommends carriers get ahead of the issue.
“You should be telling drivers, ‘Look, we don’t put up with falsifications. If you’re going to have a problem with your hours, you need to contact us.’ Follow through with that,” Runnels said.
Dispatchers should always work with drivers to ensure they are being assigned loads they can run legally. After all, coercion of drivers to take actions that would result in violations is not only an ethical issue but is also an infraction of the FMCSRs.
Ultimately, while proactive steps should ideally help prevent falsification, Runnels advises all carriers to have a plan in place to monitor drivers’ logs and address any inconsistencies.
(Artificial intelligence detects false electronic logging device (ELD) and Hours-of-Service (HOS) log entries by cross-referencing multi-source data streams and flagging behavioral anomalies that contradict a claimed duty status.
Cross-Referencing Independent Data
- Data Fusion: AI ingests millions of data points, matching ELD digital logs against external, independent validation sources like state turnpike toll timestamps, fuel card swipes, and automated license plate reader (ALPR) or weigh-station camera captures.
-
- Telematics Mismatch: Machine learning models instantly spot discrepancies where a truck’s engine control module (ECM) or GPS telemetry registers high movement, but the driver’s log records an “off-duty” or “sleeper berth” status.
Behavioral and Pattern Anomaly Detection
- Unassigned Driving Analysis: AI flags clusters of unassigned or “ghost” driving miles—moments where the vehicle moves without an active driver login—and predicts if a driver is covertly operating the truck to bypass rest limits.
- Edit and Tamper Tracking: Algorithms monitor patterns in back-end log edits, frequency of manual status overrides, and suspicious spikes in “personal conveyance” usage to isolate intentional manipulation.
- Network & Device Fingerprinting: Advanced platforms identify anomalous real-time log alterations or sudden data corrections that happen immediately when a commercial vehicle approaches an inspection site or weigh station.)
In a case no one ever wants to publicize or even discuss, despite an all-star defendant cast and an extensive investigation into the June 19, 2021, I-65 tragedy that killed 8 children
Rob Carpenter
I’m going to start by saying that I am not an emotional person. I am well known for being one of the most emotionless people alive. This case was difficult even for me. This will be a two-part series. I first wrote about this story in February 2024. There is just so much wrong in this case, so much that was overlooked by the government and by the press. I have had the entire court file on this case for years, if you would like it and the complete NTSB report, I can provide it because it’s one of the most emotional cases I have ever worked on in highway accidents. Eight children died in flames on a rainy Alabama afternoon, and today the driver who killed them is back behind the wheel of another commercial truck. The June 19, 2021, crash on Interstate 65 near Greenville wasn’t just about excessive speed in wet conditions, as federal investigators concluded. It was the inevitable result of a broken system that allowed a driver with a questionable record to operate a commercial vehicle, and three years later, that same driver now operates his own trucking company under active federal authority.
Mamuye Ayane Takelu, the 41-year-old driver whose Freightliner pushed the Tallapoosa County Girls Ranch van into a deadly inferno, faced no criminal charges for killing eight children. Instead, he formed E&V LOGIN TRUCKING LLC in April 2024, obtained USDOT number 4233479, and returned to hauling freight on the same highways where he committed mass vehicular homicide. The system is broken. E&V Login Trucking started a year ago in GA, and since then, it has been operating an “Incomplete vehicle” with state violations, one of which is not having proper DOT door markings.
The owner, Alebachew Ademe, continues to operate several businesses to this day, including Lux Limousine, LLC, a limousine company, and has formerly operated several freight businesses.
At 2:21 that Saturday afternoon, what should have been a routine traffic slowdown became a horrific inferno that claimed 10 lives. The Tallapoosa County Girls Ranch van, carrying eight children ages 4 to 17 returning from a beach vacation, was struck and pushed into the median where it was consumed by fire along with five other vehicles. The sequence was brutal in its simplicity, an Auto Transport’s Volvo truck-tractor, traveling at 51 mph in wet conditions, plowed into stopped traffic. Moments later, Asmat Express’s Freightliner, driven by 41-year-old Mamuye Ayane Takelu, slammed into the melee at highway speeds, pushing the children’s van into the median where fuel from ruptured truck tanks ignited an inferno.
Eight children died from thermal and blunt-force trauma. Autopsy reports showed soot in all their airways, they were alive when the fire consumed them. It didn’t have to happen this way.
The man behind the wheel of the second truck represents everything wrong with America’s commercial driver licensing system. Mamuye Ayane Takelu, was operating a 40-ton commercial vehicle despite a driving record that should have disqualified him from hauling freight on American highways. Yet neither the National Transportation Safety Board nor the Federal Motor Carrier Safety Administration bothered to investigate the most basic questions about his background.
Takelu had been involved in three crashes during the 10 years before he killed eight children, a rate significantly higher than the industry average. He obtained his commercial driver’s license in 2016, during the peak period of refugee resettlement in Clarkston, Georgia, where his employer was based.
The NTSB investigation found that Takelu was traveling at approximately 60 to 73 mph when he encountered the traffic jam on the wet bridge. Instead of maintaining control, he veered left across lanes, struck the bridge rail, plowed through the median, and crushed the children’s van between his truck and the first commercial vehicle. Investigators found no evidence of impairment or cell phone use, but Takelu’s actions suggest either fundamental incompetence or complete disregard for basic safety principles.
Here’s what investigators never bothered to ask: What was Takelu’s immigration status at the time of the crash? How did he obtain his CDL, and were proper procedures followed? What was his English proficiency level, and could he actually understand American traffic regulations and safety requirements? Were translators used during post-crash interviews? These aren’t academic questions, they go to the heart of whether a qualified driver was operating that commercial vehicle and should ever have been placed on the highway.
Recent federal enforcement data reveals the scope of the problem investigators ignored. Violations for “Driver cannot read or speak the English language sufficiently to respond to official inquiries” have skyrocketed across multiple states. New data released by the FMCSA via Trucksafe Consulting indicates that violations and enforcement have skyrocketed.
Today, Takelu’s runs his own single-truck operation in GA. No criminal charges were filed against the driver who killed eight children. The system that enabled him to kill children continues operating exactly as it did in 2021.
Asmat Investment LLC, doing business as Asmat Express, was established in 2014 as an interstate carrier, operating 13 power units with 13 drivers according to 2017 data. Asmat reported 1.725 million miles in 2016, which is mathematically impossible for 13 trucks unless they were being driven around the clock in violation of federal hours-of-service regulations. The company provided no real driver training beyond a policy manual, had minimal safety oversight, and showed a pattern of violations that should have triggered intensive federal scrutiny.
Asmat’s location in Clarkston is the key to understanding how this tragedy became inevitable. Clarkston, dubbed “the Ellis Island of the South,” has welcomed over 40,000 refugees in the past four decades. Today, 52.9% of the city’s population is foreign-born, with residents speaking more than 60 languages within a 1.4-square-mile area. The Ethiopian community is among the largest refugee populations.
This diversity should be celebrated, but it has also created a regulatory black hole where marginal trucking operations exploit immigrant communities. Multiple sources confirm that Clarkston has become notorious for substandard CDL schools offering training in languages other than English, “fresh recruit” programs that funnel refugees into trucking through federally funded workforce schemes, and “chameleon carriers” that shut down and reopen under new names after safety violations.
The Ethiopian trucking pipeline in Clarkston represents systematic safety fraud on an industrial scale. CDL schools target Ethiopian refugees with promises of quick employment, provide training materials in Amharic despite federal English requirements, and exploit community networks to help drivers obtain licenses without proper English proficiency. Carriers like Asmat Express then exploit this pipeline for cheap labor, putting inadequately trained drivers behind the wheels of commercial vehicles.
Following the crash, FMCSA conducted a compliance review that revealed exactly what you’d expect: unsafe driving practices, failure to maintain proper records, inadequate safety management controls, and driver qualification deficiencies. The agency’s response to eight dead children was pathetically insufficient. Asmat received an Unsatisfactory safety rating on September 15, 2021, three months after killing children. The company was upgraded to Conditional status just 19 days later, after submitting a corrective action plan.
By 2023, Asmat Express had quietly ceased operations. No corporate executives faced criminal charges. The system that enabled this tragedy continues operating exactly as before.
The third layer of institutional failure involves MoLo Solutions, the Chicago-based freight brokerage that connected Asmat Express with the load they were hauling when they killed eight children. Founded in 2017, MoLo epitomized the technology-driven brokerage model that prioritizes volume over safety, connecting 70,000 carrier partners with 500 shippers while generating explosive revenue growth.
MoLo’s business model was built on utilizing technology to match freight with the most cost-effective available capacity, disregarding safety considerations. The company’s 100% year-over-year revenue growth to $274 million in 2020 came from prioritizing speed and cost over proper carrier vetting. This is the business model that puts dangerous carriers like Asmat Express in a position to kill families.
Three months after the Alabama crash, ArcBest Corporation acquired MoLo Solutions for $235 million cash. The timing is crucial because ArcBest inherited all pre-acquisition liabilities from MoLo’s broker decisions, including responsibility for the negligent vetting that connected a dangerous carrier with freight. ArcBest became legally responsible for MoLo’s failure to properly screen Asmat Express for safety qualifications and their decision to continue the business relationship despite the carrier’s problematic record.
Legal documents reveal specific failures in the broker-carrier relationship. MoLo failed to screen Asmat Express for safety qualifications properly, continued their business relationship despite the carrier’s problematic record, provided inadequate oversight of driver qualifications and carrier management, and prioritized profit over safety by focusing on volume rather than thorough vetting. When ArcBest acquired MoLo, they assumed liability for all these safety decisions and became financially accountable for the victims of pre-acquisition negligence.
This creates a perfect example of how the freight brokerage system can enable dangerous operations while major corporations profit from deadly decision-making, then shield themselves from accountability through complex corporate structures. The broker that connected a killer driver with freight faces no criminal charges, and the corporation that profited from the acquisition continues business as usual. This is exactly why TQL and CH Robinson have two separate broker liability cases at the Supreme Court.
The National Transportation Safety Board’s investigation, while technically thorough in some respects, demonstrates the agency’s institutional blindness to systemic failures that enable mass casualty trucking crashes. The NTSB correctly identified “unsafe speeds of multiple vehicles during rain, low visibility, and wet road conditions” as the probable cause. Still, this technical finding obscures the deeper institutional failures that made the tragedy inevitable.
NTSB investigators conducted a comprehensive crash reconstruction, including detailed speed calculations using video evidence and data recorders, a weather impact assessment, and an evaluation of the emergency response. They got the physics right but they completely overlooked the human and institutional factors that led to an unqualified driver being behind the wheel of a commercial vehicle in the first place.
The investigation’s critical oversights reveal either stunning incompetence or deliberate avoidance of inconvenient truths. There was no investigation of immigration status or English proficiency of the key driver, minimal examination of carrier vetting failures by brokers, no analysis of regulatory gaps that allowed marginal carriers to operate, and insufficient focus on institutional failures that enabled the tragedy.
FMCSA’s regulatory response was equally inadequate. The agency conducted standard compliance reviews and safety rating adjustments but implemented no systemic changes to carrier oversight procedures, no new broker accountability measures, and no enhanced CDL verification requirements.
Every regulatory agency involved in this investigation had strong incentives to avoid examining the immigration and language competency issues that were central to this tragedy. The result was an investigation that treated symptoms while ignoring the disease, ensuring that the system responsible for eight dead children continues operating exactly as before.
The Pruitt crash exposes multiple gaps in the current commercial vehicle safety system, but the most glaring involves the integrity of commercial driver licensing. There’s no systematic verification of immigration status during CDL application processes, inadequate English proficiency testing for commercial drivers, limited background checks for foreign-born applicants, and inconsistencies in licensing standards from state to state.
The carrier oversight system is equally broken. The FMCSA operates on a reactive enforcement model, taking action only after crashes occur. There are inadequate entry barriers for new motor carriers, limited ongoing monitoring of carrier safety performance, and insufficient penalties for safety violations. Companies like Asmat Express can operate for years with obvious safety deficiencies before anyone takes meaningful action to address them.
Broker accountability represents another massive gap. There’s limited liability for carrier selection decisions, inadequate safety screening requirements for carrier networks, corporate shield strategies that limit accountability, and profit incentives that prioritize volume over safety. Brokers can connect dangerous carriers with freight, profit from the arrangement, and face no meaningful consequences when people die.
The English proficiency requirement has been federal law since the 1930s, requiring commercial drivers to “read and speak the English language sufficiently to converse with the general public, to understand highway traffic signs and signals in the English language, to respond to official inquiries, and to make entries on reports and records.” But enforcement was essentially suspended in 2016 when the Obama administration directed inspectors not to place drivers out of service for English proficiency violations.
This enforcement gap created precisely the conditions that enabled Takelu to operate a commercial vehicle despite questionable English skills. It wasn’t until President Trump signed an executive order in 2025 requiring strict enforcement of English proficiency requirements that the system began addressing this obvious safety hazard. By then, it was too late for the eight children who died because regulators were more concerned about appearing discriminatory than protecting public safety.
Today, nearly four years after killing eight children, the key players in this tragedy have vanished into the regulatory ether. Mamuye Ayane Takelu operates a trucking company and no criminal charges were filed despite his role in a mass casualty event.
Asmat Express ceased operations by 2023, but the ownership structure was never revealed, and there’s no way to know whether the same people are operating successor companies. The pattern is classic “chameleon carrier” behavior where dangerous operators shut down after crashes and reform under new identities. Without meaningful background checks or ownership verification, nothing prevents the same people from starting new companies and exploiting new batches of inadequately trained immigrant drivers.
The broader network continues operating exactly as before. Other Clarkston carriers are still in business; the Ethiopian driver pipeline continues to channel refugees into commercial vehicles; the CDL mill system remains intact; and there was no systematic enforcement of English requirements until the 2025 policy change. The regulatory capture that enabled this tragedy persists, ensuring that more families will face similar tragedies.
Civil lawsuits were settled with sealed amounts and no admission of wrongdoing by corporate defendants. The system killed eight children and faced no meaningful consequences.
The institutional failures that killed the Tallapoosa County Girls Ranch children are symptoms of a regulatory system that has been captured by corporate interests and immigration advocacy groups that prioritize political correctness over public safety. Until federal agencies began cracking down on English proficiency violations in 2025, this system continued operating exactly as it did when it enabled Takelu to kill eight children.
The refugee-to-trucker pipeline that produced Takelu continues operating in communities across America. Federal funding programs still incentivize the recruitment of “fresh recruits,” including immigrants, refugees, and other populations that qualify for workforce development subsidies. CDL schools continue targeting immigrant communities with training programs that prioritize quick licensing over competency development. Marginal carriers continue exploiting these vulnerable populations for cheap labor while putting the American public at risk.
The brokerage system that connected dangerous carriers with freight remains fundamentally unchanged. Technology platforms continue prioritizing cost and speed over safety considerations. Corporate liability shields continue to protect major players from meaningful accountability when their decisions result in mass casualties. The economic incentives that made this tragedy profitable for multiple parties remain in place.
How many other drivers like Mamuye Ayane Takelu are currently operating commercial vehicles on American highways? How many other carriers like Asmat Express are exploiting immigrant communities while flying under the regulatory radar? How many other brokers are prioritizing profit over public safety in their carrier selection decisions? These aren’t academic questions – they’re life-and-death issues that regulators continue avoiding.
Recent high-profile crashes involving foreign-born drivers with limited English skills suggest that the problem has worsened, not improved. The system that killed eight children in Alabama continues producing similar tragedies across the country. Until there’s meaningful reform of CDL integrity, carrier oversight, and broker accountability, more families will pay the ultimate price for regulatory failure.
The death of eight children in a preventable crash represents more than a tragic accident – it’s the inevitable result of a regulatory system captured by forces that prioritize corporate profits and political correctness over public safety. From the Ethiopian immigrant driver with a questionable record to the marginal carrier with minimal oversight to the broker that prioritized volume over vetting, every institution that should have protected these children failed them.
Mamuye Ayane Takelu was the man behind the wheel, but he was enabled by a system that allowed him to operate a commercial vehicle despite obvious warning signs. Asmat Express was the carrier that employed him, but it was enabled by regulators who allowed it to operate despite minimal safety controls. MoLo Solutions was the broker that connected them with freight, but they were enabled by a system that prioritizes profit over proper vetting.
The children of Tallapoosa County Girls Ranch, ages 4 to 17, from troubled backgrounds, finally experiencing joy on a beach vacation, were burned alive because American regulatory agencies were more afraid of appearing discriminatory than of children dying in preventable crashes. Every agency involved in investigating their deaths had powerful incentives to avoid examining the core issues: immigration status, English proficiency failures, CDL mill operations, federal funding programs that incentivize dangerous driver recruitment, and corporate exploitation of immigrant communities.
The pattern of enablement is clear and continues today. Refugee resettlement programs channel immigrants into trucking without proper safety oversight. CDL mills provide licenses without adequate English training. Marginal carriers exploit cheap foreign labor. Brokers profit from connections with dangerous operators. Major corporations benefit from cheap freight rates. Regulators often overlook apparent safety violations to avoid potential claims of discrimination.
This was an instance of institutional failure at every level of the commercial trucking safety system. Eight children deserved better from the government that was supposed to protect them. Their deaths weren’t accidents, they were the predictable result of a system that values corporate convenience over children’s lives.
Until we address these systemic failures through criminal prosecution of unqualified drivers, federal investigation of CDL mill operations, corporate accountability for negligent brokers and carriers, and regulatory reform that puts American safety over foreign sensitivities, more children will die in preventable crashes. The fight for accountability and systemic reform continues in memory of eight children who were betrayed by every institution that should have kept them safe.
Tim Henry
What you need to know
- CSA is a diagnostic tool, not just a scorecard: Treating Compliance, Safety, Accountability data strictly as a report card is a costly mistake. Fleets must look past the surface rankings to uncover hidden operational, process and communication gaps before they escalate.
- Small trends predict major liability: Serious financial and legal risks rarely start with dramatic spikes. Minor, repeated violations—like localized maintenance or lighting defects—can build a documented pattern of systemic neglect that plaintiff attorneys will weaponize in the event of a crash.
- Prioritize low-threshold BASIC categories: While fleets naturally focus on their highest scores, they must pay critical attention to categories with lower intervention thresholds, such as Unsafe Driving and hours-of-service compliance, where even minor increases trigger rapid regulatory scrutiny.
- Turn data into targeted action: Use localized enforcement insights and specific violation trends to move away from generic safety training. Instead, implement location-specific ELD alerts and high-impact, one-on-one driver coaching to mitigate risks before violations occur.
Most fleets know their safety scores.
They may not check them every week, but they generally know where they stand relative to intervention thresholds. They know whether a broker has asked about them during a bid process, and they certainly know when an insurance carrier references them during renewal discussions.
But knowing the number and understanding what it actually means are two very different things. For many carriers, the Compliance, Safety, Accountability (CSA) Safety Measurement System has become little more than a report card. Fleets monitor the numbers, react when they rise too high and otherwise leave them alone.
For years, the industry conversation around CSA has focused heavily on percentiles, thresholds and rankings. But treating CSA strictly as a scorecard may be one of the most expensive mistakes a fleet can make. Misinterpreting CSA data can influence insurance premiums, trigger deeper audits, shape litigation arguments and affect how shippers evaluate carriers during procurement. The numbers themselves are only part of the story.
CSA does not just reflect safety performance. It reveals operational weaknesses that fleets might otherwise overlook. When violations cluster, repeat or trend upward within a particular Behavior Analysis and Safety Improvement Categories (BASIC) category, they often point to gaps in processes, oversight or communication.
An increase in Driver Fitness violations may signal weaknesses in medical certificate tracking or onboarding procedures. Repeated vehicle maintenance issues might indicate preventive maintenance processes are drifting out of sync with operational demands. Rising hours-of-service violations can sometimes reflect dispatch pressure or inconsistent log auditing.
CSA does not explicitly explain why these issues occur. But it does point to where fleets should start investigating.
Small trends can become big problems
The most expensive CSA issues rarely appear as dramatic spikes. More often, they emerge as gradual patterns that accumulate over time.
For example, say a small flatbed carrier serving regional construction projects experienced a slow increase in vehicle maintenance violations — brake adjustments, lighting defects and minor inspection findings. None of the violations individually appeared serious, and the fleet remained below intervention thresholds. But over time, those violations created a documented pattern.
How fleets should actually analyze CSA data
Fleets that treat CSA as an operational diagnostic tool can often identify issues early, before they become regulatory, legal or insurance problems.
Start by tracking your scores over time. Regularly reviewing CSA data helps fleets see whether performance is improving or trending in the wrong direction. Look closely for spikes tied to specific violations or patterns tied to certain drivers. For example, a sudden increase in lane-restriction violations might point to a particular route, driver group or operational pressure point.
Next, identify the BASIC categories that present the greatest risk. Naturally, fleets should focus on the categories with the highest scores. But they should also pay particular attention to BASICs with lower Federal Motor Carrier Safety Administration intervention thresholds, such as Unsafe Driving and hours-of-service compliance. Even modest increases in these areas can attract enforcement attention.
Location analysis can also reveal important insights. Many fleets find that specific states are responsible for a disproportionate share of their violations. A deeper review may reveal that certain weigh stations, inspection locations or stretches of highway account for the majority of issues. Often, this reflects enforcement emphasis in that area—for example, a particular state focusing inspections on items like windshield wipers or lighting violations.
From there, fleets should drill down into the specific violations that are contributing to higher scores. Unsafe Driving violations, for instance, are often dominated by speeding citations. But a deeper analysis may reveal other contributors, such as seatbelt violations or following too closely. Understanding exactly what violations are driving scores allows fleets to target corrective actions more effectively.
Finally, compare performance against industry benchmarks. CSA scores are relative by design, so understanding how your fleet compares to similarly sized carriers can help put the numbers into context.
Turning CSA data into action
Once fleets understand what is driving their violations, the next step is turning that information into operational improvements.
Start by raising awareness across the organization. Everyone who can influence CSA performance—from drivers to dispatchers to maintenance teams—should understand why the scores matter and how their actions affect them. Providing regular companywide updates on safety performance can reinforce accountability and encourage improvement.
Data can also help identify drivers who may benefit from additional coaching. One-on-one meetings with drivers who disproportionately impact CSA scores can provide an opportunity to review violations, discuss expectations and reinforce best practices.
Training should also be targeted. Rather than delivering generic safety instruction, fleets can use CSA insights to focus training on the specific behaviors contributing to elevated scores.
Technology can also play a role. Fleets can create location-specific alerts delivered through electronic logging devices (ELDs) and mobile devices that notify drivers when they enter areas known for specific enforcement patterns or violation risks. For example, fleets can send real-time reminders when drivers enter corridors where speeding citations are frequently enforced, helping drivers avoid violations before they occur.
Reading CSA the right way
CSA reports alone cannot explain why violations occur. They do not reveal whether patterns stem from scheduling pressure, equipment maintenance gaps, or inconsistent compliance oversight.
Fleets that learn to read CSA data diagnostically gain something far more valuable than a better score. They gain early visibility into risks that could eventually affect insurance costs, litigation exposure, and business relationships with shippers. In an industry where safety performance increasingly influences insurance underwriting and procurement decisions, that insight can become a competitive advantage.
Ransomware, phishing, and DDoS attacks are disrupting fleets, exposing vulnerabilities in digital freight operations and supply chains.
Jenna Hume
Key takeaways
- Cyberattacks on transportation are on the rise, putting fleet systems, data, and operations at increasing risk.
- Ransomware, phishing, and DDoS attacks can halt dispatch, delay freight, and drive costly downtime.
- MFA, system updates, training, and response plans help fleets reduce cyber risk and protect operations.
Eric Van Egeren, generated by Shutterstock/AI
As technology has advanced and permeated more and more of our personal and professional lives, cybersecurity has become an increasing concern. Cybercrimes have more than doubled since 2018, according to the Federal Bureau of Investigation (FBI). From 2018 to 2024, the FBI received 5 million cyberattack complaints, with reported losses totaling $56.7 billion. The recent rise of artificial intelligence (AI) has only further complicated cybercrime.
For the trucking industry, cybercrime is an ever-growing problem, especially as more and more technology finds its way into truck cabs. Closely connected to cargo theft, cybersecurity in trucking has its own quirks and challenges. But before we get to those, let’s discuss the basics of what cybersecurity is, inside and outside of the trucking industry.
Cybersecurity basics for fleets
Cyberattacks are “any kind of malicious activity that attempts to collect, disrupt, deny, degrade, or destroy information system resources or the information itself,” according to the National Institute of Standards and Technology’s (NIST) Computer Security Resource Center.
Common types of cybercrime include phishing, ransomware, malware, data breaches, and more. The most common goal of digital criminals when targeting businesses is financial gain, though espionage and sabotage are other motivations.
Cybersecurity, therefore, is the “practice of protecting people, systems, and data from cyberattacks by using various technologies, processes, and policies,” according to IBM.
Some of the business sectors most affected by cybercrime are health care, manufacturing, financial services, small businesses, and transportation.
Why cybersecurity is critical for fleet operations and uptime
Trucking and the supply chain today are more digital than ever, with technologies such as telematics, electronic logging devices (ELDs), electronic bills of lading (eBOL), artificial intelligence (AI), autonomous vehicles (AVs), and more. Fleets can now operate more safely and efficiently with greater visibility thanks to this new technology.
But this advanced technology comes at a cost. In this new digital age, industries like trucking have become targets of digital criminals. The transportation sector saw an 186% increase in cyberattacks from June 2020 to June 2021, according to a 2021 study. Transportation ranked ninth among the top 10 most commonly targeted industries in 2025.
And when cybercrime occurs, it doesn’t just affect the industry; its effects trickle down the supply chain, eventually impacting the public and consumers. This is because cybersecurity incidents often cause unexpected downtime and delays, especially when telematics and routing technology are affected. In addition to impacting freight delivery, this results in lost revenue and tarnished reputations for trucking companies.
45582385 | Hotshotsworldwide | Dreamstime.com
Top cyber threats targeting fleets and supply chains
Like cargo theft, digital criminals are constantly adapting existing cybercrimes and creating new methods. Here are the details on the most common cybercrimes affecting trucking:
Ransomware
Ransomware is a type of malware that holds a victim’s data or devices hostage until a ransom is paid, according to IBM. Ransomware is one of the most common types of cybercrime, and it has evolved into subcategories such as double- and triple-extortion.
Double extortion is when cybercriminals threaten to leak a victim’s data online. Triple extortion involves threatening to use the stolen data to attack an organization’s customers or business partners.
Phishing
A phishing attack occurs when a cybercriminal sends an email that appears familiar but is an attempt to steal personal information, such as passwords, the National Motor Freight Traffic Association (NMFTA) states. These emails typically look like an email address for an individual or organization, with one letter, number, or punctuation mark that looks different.
DoS and DDoS attacks
Two similar cybercrime methods are Denial of Service (DoS) and Directed Denial of Service (DDoS). According to NMFTA, both types of attacks overload a system with requests and prevent access. The system shuts down when overloaded with too many requests.
When a system like this shuts down, the organization or individual cannot use it. In trucking, this could halt an entire fleet and its drivers, resulting in delays, lost revenue, spoiled products, and more, not to mention the stress this situation puts on drivers, dispatchers, managers, and others.
The difference between the two types of attacks is that DoS is system-to-system, whereas DDoS is multiple systems against one system, Fortinet states.
MITM attack
A man-in-the-middle (MITM) attack occurs when a hacker intercepts communication between two parties and modifies information.
NMFTA provides the following example of an MITM attack: “Imagine a company sends a client a message that requests they wire payment to the company’s bank account. A hacker could receive this message, replace the company’s bank account with their own, and then potentially walk away with tens of thousands of dollars.”
Brute-force attack
A brute-force attack is a type of data breach that tries every possible combination of letters, numbers, and symbols to guess the correct password eventually. This, in turn, allows a hacker to access an organization’s system.
How fleets can strengthen cybersecurity and reduce risk exposure
With so many cybercrime methods, there are also plenty of ways trucking companies can protect themselves. For every niche method of cybercrime out there, there’s a niche method of cybersecurity. But here are some broad ways fleets can protect themselves with cybersecurity.
Conduct regular audits
Conducting regular audits can help fleets identify weaknesses in their security systems before hackers find them, according to Keystone Technology Consultants. This can be done with a fleet’s IT professionals or outside cybersecurity consultants.
Use rigid authentication measures
Multifactor authentication (MFA) is another measure to protect fleet technology systems. According to Isaac Instruments, MFA requires individuals to provide more than one form of identification to log in to email or other company systems. MFA can include passwords, fingerprints, authenticator apps, email codes, etc.
Keep tech updated
When fleets fail to update their technology, they leave themselves vulnerable to new cyber threats. Promptly updating technology, and even enabling automatic updates, further protects fleet data. NMFTA found that one-third of data breaches are from vulnerabilities that technology updates would have prevented.
Train employees on cybersecurity
It may seem cliché, but proper cybersecurity awareness and training are a major way fleets can protect themselves. These training sessions shouldn’t just teach staff how to identify phishing and other scams; they should also focus on procedures for when cybercrimes do occur.
NMFTA recommends that every employee at a trucking company receive cybersecurity training, from not sending sensitive information by email to creating strong passwords.
Make cybercrime incident plans
As with cargo theft, fleets can’t just focus on prevention; they need plans in place for when cybercrimes occur. NMFTA suggests the following steps that fleets might implement as part of these plans:
- Notifying management
- Not negotiating with hackers
- Changing passwords
- Unplugging servers
- Uploading backups