The ELD fraud desk
What an hours-of-service cheating service actually looks like from the inside. Both from the original June article now with the rest of the specifics unavailble to everyone who mirrored round 1's data
It’s been two months since I first covered the white label ELD fraud story in depth. I’ve covered it several times before that. How do I know so much about ELD fraud? Well, we advise the government on it. We assist in investigations of it. We’re expert witnesses involved in highway accident litigation and driver wage claims where it plays a large part. There's always a story, but there's seldom “the” story. This is “the” story. Round two. The comparable storylines from round one and my Dragon in the cab article aren't lost on me.
On December 23, 2023, a driver typed six words into a Telegram chat: “I need my 14 hours reset.” A person calling himself Simon answered. “You have only 2 hours of cycle time sir.” Then, without a beat: “Are you loaded? If yes, then when and where was your last pickup?” The driver said yes, and asked for a 70-hour reset. Simon asked where the last pickup was. Friday at 9 a.m., the driver told him. A federal record that said the driver was nearly out of hours was about to say he had a fresh clock, and the desk’s only question was where the load had come from so the fabricated log would match the freight.
That is the product. Not a defective app, not a device that glitches, but a staffed service desk that edits the federal hours-of-service record on request, and often without being asked. I spent the last several months reading 2,179 of those messages from one channel alone, plus five more channels, a stack of Illinois court filings, a bilingual corporate authorization out of Wyoming and Moldova, and two FMCSA device lists. What the records show is that the “electronic logging device” a couple hundred trucks were running was never the point. The point was the person on the other end of the chat who could rewrite what the device recorded.
The white-label pattern has been reported in the trade press: revoked devices, a Chicago-area fleet, drivers swearing in court that a Telegram group added hours to their logs. The messages, the credentials, and the corporate paper underneath that pattern have not. What follows is that layer: the actual exchanges, the actual back-end portals, the actual document that ties ten brands to one man. This is not the allegation. This is the file.
What “white label” means, and why it hides everything
A trucking company is required to run an electronic logging device, an ELD, that automatically records when the truck is moving and ties that to a driver’s duty status. The device is supposed to make the driver’s record of duty status, the RODS, hard to fake, because the truck’s own motion writes the log instead of a pen. That is the entire safety theory: a tired driver can lie on paper, but he can’t lie to the engine.
White labeling is the practice of one company selling an ELD that runs on another company’s software, under its own brand name. There is nothing illegal about it. Most consumer electronics work this way. The problem it creates for a safety registry is simple: the FMCSA lets a provider self-certify, meaning the provider fills out a form attesting that its device meets the technical spec, and the agency lists it. When one hidden platform sits under fifty brand names, revoking one brand does nothing to the other forty-nine. You have cut off a head, and the body was never on the list.
I built a detector for exactly this pattern and ran it against the whole FMCSA registered-device list. One family of device identifiers came back looking like a single issuer wearing 172 different company names: 178 devices sharing one sequential counter, the leading character swapped to match each brand, in 177 of 178 cases. “48 ELD” registers as 4RS123. “888 ELD” registers as 8RS262. They share zero phone numbers, zero websites, and no meaningful address clusters. The only thing they share is the one field the brand owner does not get to choose. Membership in that family is not proof of misconduct, and about 78 percent of it has never drawn an enforcement action. A legitimate white-label vendor with 172 honest resellers produces the same fingerprint. What the fingerprint proves is a shared issuer. What it takes to prove the fraud is the chat.
One platform, seven badges
Seven ELD brands present to the market as unrelated competitors: Phoenix, Ironman, Action, Robinhood, RedFox, Extreme, and Dragon. On March 20, 2025, a single Telegram account posted a single message containing, for all seven, the brand login and the back-end portal each one actually runs on. Every one resolved to a numbered instance of one platform called FORTEX: fortex-ph1.us, fortex-irm1.us, fortex-act1.us, and so on down the line. Everyone logged in as the same user: “Support.” The same account reposted it five days later.
You do not hold the administrator password to a competitor’s platform. You hold it to your own. On four separate dates that same March, the same account posted rotating admin passwords for five to seven of the brands at once, in one message, from one keyboard. That is not seven companies buying software from a vendor. That is one operator holding the master keys to what the public registry lists as seven independent devices.
The parent is a Wyoming company called Workspace Holding LLC, managed by a man named Radu Murzac. I am describing a documented corporate instrument, not inferring one. A bilingual Romanian and English authorization dated January 3, 2022, with three later annexes, all signed by Murzac, lists ten ELD subsidiaries and grants administrative access to each of them to a company in Chisinau, Moldova, called Data Drive SRL. The grant is not vague. It names “admin panels, APIs, staging/production environments” and “databases.” Ten brands, one parent, one offshore crew holding the keys, in Murzac’s own signature.
Of the ten declared subsidiaries, seven are or were on the FMCSA registry. Six of those are revoked: TMS ONE (doing business as ELD ONE), Phoenix, Action, Dragon, Ironman, and Robinhood. The seventh, ELD 88 LLC, is live today, registered at the identical suite in Elgin, Illinois that the revoked flagship used. It was declared a subsidiary in December 2022, almost three years before the first revocation. It was not a successor built in a hurry when enforcement hit. It was inventory: registered early, parked at the flagship’s own address, and switched on when the others burned.
The phone company kept the receipts
The Telegram credentials tell you the brands share a platform. The phone records tell you they share an owner, and they come from the vendor’s own provisioning system, not a chat anyone can call fabricated. Every one of these brands routes its published customer-support and callback numbers through a single RingCentral account. The account has a name. It is called LOG 365.
On that one LOG 365 account sits an extension labeled “TMS One / Support,” and the physical desk phone assigned to it, a Polycom VVX 150, is registered to Radu Murzac, 1425 North McLean Boulevard, Unit 900, Elgin, Illinois. That is the flagship suite, the same address ELD 88 operates from today. Murzac’s name is on the hardware. The same account carries extensions named ELD One, TMS One, Log Office, Audit Department, Monitoring Department, and a block of lines labeled DDS: DDS Manager Mihailo, DDS Monitoring, DDS Accounting, DDS Sales. DDS is Data Drive SRL, the Moldovan company to which the January 2022 authorization handed the admin keys. Sitting next to those are extensions named Serbia Office, Uzbekistan Office, and DDB Balti. Balti and Chisinau are the two Moldovan cities named in the desk’s own internal staff briefing. The offshore crew and the brand switchboard are not two operations that happen to be connected. They are line items on the same phone bill.
The entity list filed in the Cook County case makes the wiring explicit. Next to each brand’s FMCSA-registered phone number, the plaintiffs annotate the carrier: Phoenix (224) 347-9637, RingCentral LOG 365. Action (224) 998-3789, RingCentral LOG 365. Dragon, Ironman, RedFox, Extreme, Royal, Zenith, all RingCentral LOG 365. ELD 88 and Robinhood route through a second account named ELD ONE. Eleven brands that market themselves as competitors answer the phone through two switchboards, and both switchboards carry Murzac’s flagship name. On July 16, 2025, a RingCentral representative went into the LOG 365 account and reassigned the whole block of brand numbers in one sitting, one after another, including the reassignment of a line to (224) 347-9637, the number Phoenix had registered with the federal government. One person, one afternoon, renumbering seven “independent” ELD companies from inside a single account.
“Everything is already set up for your company”
On October 23, 2025, the FMCSA revoked Phoenix ELD, an action the Extra Mile plaintiffs obtained through their own litigation. The next day, October 24, the desk sent this to customers:
Hi, earlier you spoke with your account manager about switching to Dragon ELD. Unfortunately, we were informed today that Phoenix ELD has been revoked. However, everything is already set up for your company on Dragon ELD, so there’s no need to worry. All you need to do is delete the Phoenix ELD app and install Dragon ELD once you are empty.
One day. The first clause is the whole story: customers had already been contacted about switching before the revocation was announced. Dragon ELD had been a declared subsidiary since June 2023, 28 months earlier. Revoking a device is supposed to be enforcement. Against this operation, it was a product migration, and the migration was pre-staged. That is why device-by-device revocation does not work here. You are playing whack-a-mole against a company that pre-registers the next mole years in advance and moves the customer in a single business day.
The menu
The Phoenix channel alone runs 19 unbroken months, December 2023 to July 2025, 2,179 messages, 405 of them requests to reset a clock or add drive time. Reading them in order, the thing that stops you is how routine it is. There is no code, no negotiation. A driver asks, the desk delivers, the desk signs off with a reminder to certify the falsified days because certification “is required by FMCSA and it’s mandatory.”
The requests are placed the way you’d order lunch. On December 28, 2023, a driver wrote “I need to get more time.” An agent calling himself Sam answered, “Hello! My name is Sam, and I will assist you further today! How many hours do you need?” The driver said “6 hours.” Sam: “Your request is done! Please log out/log in. Also, please, check and complete the profile form and certify all the days, it’s required by FMCSA and it’s mandatory.” Certify the forgery, because the agency requires it. The desk closed nearly every edit with that same line. When a driver asked for “full 79 to start my week,” the agent noted he had 69 hours in his cycle, the driver said “make it 70 pls,” and the agent said “ok.” The federal limit is 70. They knew it, and they built the forgery right up to the line.
Sometimes the desk doesn’t wait to be asked. On May 7, 2024, with no request from the driver, an agent wrote: “hello sir, our monitoring department has found that you drove disconnected, and we fixed it, please do log out log in.” The same message goes out again on May 16, again on May 31, word for word, to different drivers. Driving “disconnected” means the truck moved with the ELD unplugged, which leaves a gap the system flags. The monitoring department found the gap and closed it, and told the driver after the fact. The driver did nothing. On November 9, 2025, the operator channel shows the monitoring output raw: a portal name, a carrier, a driver, “Status: Driving,” “14-Hour On Duty Limit,” and a timestamp reading “13m ago.” It is a bot watching the whole fleet’s clocks and flagging violations for a human to erase.
The part that isn’t about hours
On December 27, 2023, the desk messaged a driver on its own initiative: “Hello sir, we noticed that you drove in personal use 246 miles, can we put this driving on today’s log?” The driver said yes, blamed a Bluetooth problem, and the desk moved it. Personal Conveyance is an off-duty allowance for moving a truck when you’re not working, and it categorically cannot advance a load. 246 miles is a driving day. The desk found it and offered to relocate it, not to question it.
Four separate times, the desk told drivers never to claim an Unidentified Driving Event: “never accept the UNIDENTIFIED DRIVER please,” “please do not accept the unidentified records never!” An Unidentified Driving Event is the FMCSA’s own safety net under 49 CFR 395.32, the flag the system raises when a truck moves with no driver logged in. Claiming it puts the real hours back on the real driver’s log. Telling a driver never to claim it, in writing, repeatedly, is an instruction to defeat the one automatic check the regulation builds in. That is the most chargeable line in the whole corpus, because it is an instruction and not a favor.
And on March 28, 2024, a driver wrote that his clock started “without the pre trip.” An agent named Adriana answered, “Done! I did PTI as well, you can start driving.” A pre-trip inspection under 49 CFR 396.11 is a physical act a driver performs on the vehicle, brakes, tires, lights, before the wheels turn. A support agent in a chat window created the record of an inspection that never happened and cleared the truck to roll. That is not an hours edit. That is a fabricated vehicle-safety record, and it is the kind of thing that gets read aloud to a jury after a crash.
They keep the enforcement calendar
The CVSA International Roadcheck is the industry’s known annual inspection blitz, three days every spring. Both years in the record, the desk treated it as a scheduling event. In 2024 drivers wrote in asking for a pre-blitz cleanup (”This is all so, safety week! Please review my logs for any violations and fix them”), and the desk complied. In 2025 the desk didn’t wait: on May 5, ahead of the May 13 to 15 Roadcheck, it pushed an “Attention! DOT week is approaching” notice to the fleet with an instruction file attached. The enforcement surge that is supposed to catch these logs is a save-the-date on the fraud desk’s own calendar, and they run the same play every year.
On January 31, 2026, the desk went a step past the calendar. It circulated a list, sourced to someone identified only as “MVN,” titled as the weighing stations where inspections using road cameras had been recorded. Eight stations, in Arizona, Maine, Minnesota, Missouri, and Oregon, each with GPS coordinates. The instruction attached to it: “Once you see a driver is in this region, inform him.” They maintain geofenced counter-enforcement intelligence and push warnings to drivers heading into camera range. This is not editing a log after the fact. This is routing trucks around the cops.
Why this reaches a courtroom
All of this lands on a live case. Extra Mile International Inc. is the named defendant in Owirodu v. Extra Mile International, 2024CH06818, in the Circuit Court of Cook County, brought by Kreitman Law with Gregory Wilkowski. The fleet’s own driver, Roberto Hernandez, truck 3043, wrote into the desk on December 23, 2023: “I bought a tablet I downloaded PHOENIX ELD to have it on 24/7 so I won’t use cellphone whats the username and password to login.” Fifteen Extra Mile drivers are named across these channels. The court’s January 6, 2026 order already authorizes discovery into the Telegram messages, into a company called Route One Go, and into the white-label platform provider behind the devices, including its source code, database schemas, and audit logs.
Two exchanges from the Extra Mile channels go past hours-of-service and into something a safety regulator can’t reach on its own. In one, dated March 2, 2025, the back office hands the desk a pre-written cover story for a driver named Mario Jones: if he calls or writes about his hours, tell him the ELD isn’t working, and here’s the date range to give him. That is not troubleshooting. It is a script for lying to your own driver about his own record. In the other, from March 20, 2024, a carrier-side account insists a driver’s chat be labeled under a name that is not the driver’s real name. The driver pushes back in plain words: “I’m hired under that name. The ELD says my real name.” The desk holds the line: “No sir, it will be Cedric Jenkins because this is internal communication.” A driver is telling the vendor, in writing, that he is employed under an alias and that the device shows his real identity, and the vendor’s answer is to keep the alias. That is identity fraud sitting inside the safety record, maintained by the vendor on purpose.
Two networks, one product line
Bolt ELD looks like another orphan brand until you find the owner, and the owner is documented. Bolt ELD LLC is a Wyoming entity formed July 2024 whose public filing discloses no human being at all, only the formation attorney listed as organizer with a Wyoming LLC-mill email. The beneficial owner is kept off the paper by design. He is not hard to find anyway. On the RingCentral account for Dragos Sprinceana’s Gold Coast trucking operation sit three extensions labeled Bolt ELD, Bolt technical support, and Bolt accounting, on the same account as an extension carrying Sprinceana’s own name and one labeled GoldCoast Administrator. Sprinceana claims Bolt himself in two published profiles, one describing it as his hours-of-service app, another listing him as a major stockholder. The nominee filing hides on paper what the phone company’s own records show in plain labels.
Sprinceana’s operation is not Murzac’s. They are two separate ELD-fraud networks, both rooted in Chisinau, both selling the same kind of product, that got swept into the same subpoena and look alike from a distance. I tested the link and it fails: no shared phone numbers, no shared devices, no Sprinceana entity in the Murzac banking network, and not one name appearing on both RingCentral accounts. Same playbook, same region, different owners. Saying they are one enterprise would be easier and it would be wrong. What the record shows is a market: more than one crew, working the same self-certification loophole, selling the same edits to different fleets.
How far the product reached
The Murzac operation didn’t only serve small independents who wandered in off a Telegram search. Floyd Inc., one of the carriers in the Super Ego network that CBS 60 Minutes and a federal class action have scrutinized for running trucks under interchangeable names, is named in public litigation as a customer of the provider that operated as ELD ONE, later Phoenix ELD. That is the same product line this whole piece has been describing, the one with the desk that resets a clock on request and migrates the customer to a new brand the day the old one is revoked. The compliance layer under one of the most heavily litigated chameleon-carrier networks in the country was a device built to defeat compliance.
That is a customer relationship, documented in a court filing, and I am careful to say it is only that. It does not prove Super Ego and Murzac share an owner, and I’m not claiming they do. What it measures is reach. When the tool that erases a driver’s hours is the same tool sitting under a fleet already accused of swapping the names on its trucks, the two frauds compound: one hides who is driving, the other hides how long he’s been awake. The driver on the other end of both is the one who doesn’t get to decide.
What actually stops it
Revoking devices one at a time is the wrong tool, and the migration script proves it. The enforcement has to reach the parent, not the badge. Four registry controls would change the math, and none of them require new law: require the beneficial owner to be disclosed at registration, so a Wyoming shell can’t self-certify a federal safety device with nobody’s name on it; verify the registrant’s address and flag virtual offices and mass registered agents; automatically review any new device registered at an address tied to a revoked one, which alone would have caught ELD 88 sitting at the flagship’s suite; and check the brand name against the legal entity, because right now a provider can register “!A1 ELD” specifically so it sorts to the top of the alphabetical list a carrier scrolls when picking a device.
The safety theory of the ELD was that the truck’s own motion would write a log the driver couldn’t fake. What these records show is a service that took that promise and inverted it: the motion still gets recorded, and then a person in a chat window edits what it said, certifies the edit as required by the agency whose rule they’re breaking, and moves the customer to a fresh brand the day the old one gets caught. The device was never the safeguard. The person holding the admin password was, and on this platform that person worked for the fleet.



DOT has to go after trucking companies that buy and use services like this.