The Nike indictment and trucking’s identity problem
Nobody cut a lock. Nobody pulled a gun. Nobody hijacked a truck. They printed 3,119 shipping labels.
A federal grand jury in the Western District of Tennessee returned a 12-defendant indictment on May 21. It was filed under seal and unsealed on July 21. Case number 2:26-cr-20217. The charge is conspiracy to transport stolen goods in interstate commerce under 18 U.S.C. 371, with a substantive count under 18 U.S.C. 2314 against the lead defendant. The government is seeking a forfeiture money judgment of at least $2 million.
The target was Nike’s North American Logistics Center in Memphis. NALC is where imported Nike product lands before it goes out to sellers. It is one of the highest-value concentrations of consumer goods in the American distribution network.
Here is how the government says it worked.
Mechanics
Somebody on the outside decided which product they wanted. Somebody on the inside found it in the building and put a shipping label on the carton addressed to a location the outside group controlled. UPS picked it up as ordinary outbound freight. Nobody stopped it because, from the system’s point of view, nothing unusual happened. A carton got scanned, and it went where the label said it was going.
Roy Harvey Jr., 39, of Los Angeles, is named as the lead. He set up a business called RHJ Global in 2020 using his parents’ address in Memphis. He created UPS labels for predetermined destinations and got them to employees inside NALC. He kept some of the shoes and resold the rest.
Michael Perkins was a floor manager at NALC. According to the indictment, he brought labels into the facility and handed them to four other employees, Julian Baker, Cortez Spencer, Roderico McClellan and Damon Johnson, who applied them to the specified cartons.
Keith Cannon opened a UPS account using the business information of a company called Valid Kixx, created labels, and directed shipments to Racine, Wisconsin, and to an address in Charlestown, Indiana, associated with Marquesio Robinson, who had previously worked at the Nike Employee Store. Robinson registered an LLC called Timetrav3lers to open a bank account and move money to Cannon and Harvey. Cadarian Mack listed shoes for sale on StockX and GOAT and took payment through PayPal.
On the buy side, three resellers. Joel Deluna owned Chicago Emporium. Bereket Abraham co-owns Cool Kicks on Melrose Avenue in Los Angeles, a shop known for selling high-end sneakers to celebrities. Jorge Cuellar owned Horhead Investments, another Los Angeles reseller.
The label counts in the overt acts are the part I keep going back to. Harvey received 149 labels from Cool Kicks between July 23, 2021, and May 5, 2022. Harvey and his co-conspirators successfully used 1,860 labels between May 22, 2022, and Jan. 27, 2024. Cannon created 459 that were used between April 2023 and the end of January 2024. After a pause, Cannon started printing again around March 26, 2024, and roughly 800 more of his labels moved product between April 23 and June 19 of that year. 3,100 labels.
The money moved: Horhead Investments wired $696,700 to a Memphis food truck called R&Beef Dawgz, owned by Cannon, between April 2023 and January 2024. Chicago Emporium paid Cannon approximately $492,000 between April and June 2024. Cool Kicks paid Cannon $127,000 and Harvey $88,275 between April and November 2023. LAPD and the FBI say the buyers paid the inside group more than $900,000 in total. In September 2022, Harvey asked Abraham to create a fake invoice so he could take delivery of cartons from UPS, and the indictment says Abraham created it and sent it.
On Jan. 27, 2024, LAPD arrested Harvey in Los Angeles after he took delivery of 27 cartons of Nike shoes bearing his labels. Nike interviewed Perkins and placed him on administrative leave.
Perkins then quit, and according to the indictment, he kept distributing labels to Baker, Spencer, McClellan and Johnson at least through the end of the indictment period in June 2024.
The company identified the insider, pulled him off the floor, and he continued to feed labels into the building for months afterward. The theft did not stop when the manager left. It stopped when federal agents made it stop. The control that mattered was not badge access or camera coverage. It was whether anyone in the chain could tell an authentic label from a fabricated one, and nobody could, because a label is just a barcode and a barcode is just an assertion.
The LAPD Commercial Crimes Division Cargo Theft Task Force and the Memphis FBI ran this jointly. Harvey, Abraham and Cuellar were arrested on federal warrants June 22 and 23 and appeared in federal court in Los Angeles.
All 12 defendants are presumed innocent. These are allegations in a charging document, not proven facts.
The wider picture
Cargo theft is not what it was five years ago, and the numbers show the shift.
Verisk CargoNet recorded 3,594 supply chain crime events across the United States and Canada in 2025, essentially flat against 3,607 in 2024. Estimated losses jumped roughly 60% to nearly $725 million, and average value per theft rose 36% to $273,990. Confirmed cargo theft incidents inside that total rose 18%, from 2,243 to 2,646.
Flat volume, exploding value. That is not opportunistic crime getting luckier. That is targeting.
The 2026 data continues the trend. First quarter events were down 5.3% year over year at 767, with $131.58 million in estimated losses. By the end of June, first-half losses had already passed $359 million, with average stolen commodity value climbing to about $341,518.
What is getting stolen has changed too. Copper, molybdenum, antimony, tungsten and zinc on the metals side. RAM modules, storage drives, fiber-optic transceivers, and enterprise server blades on the electronics side. Not televisions. Not consumer goods. Components with deep, anonymous secondary markets and no serial-number tracing that anyone bothers to run.
The geography moved. Among the top eight states, most declined year over year in Q1 2026. Two did not. California went from 255 incidents to 277. New Jersey went from 27 to 59, a 119% jump. CargoNet’s read is that domestic groups in Texas and the Southeast pulled back while organized networks tied to California and the New York metro grew.
Strategic theft is now the main event
The category that matters is what the FBI calls strategic cargo theft: using deception rather than force to get freight handed over voluntarily. Identity theft, fictitious pickups, account takeovers, double brokering, fraudulent carriers.
Travelers put the growth of strategic theft at nearly 1,500% between 2022 and 2024. Fictitious pickups went from an average of about 66 a year between 2012 and 2022 to 576 in 2023 alone.
The prosecutions have started catching up.
On June 3, Manhattan District Attorney Alvin Bragg announced an eight-defendant indictment, case IND-71638-26, charging a ring that allegedly operated from October 2025 through April 2026 and stole nearly $5 million in goods from logistics sites in Pennsylvania, Virginia and New Jersey. The method was straightforward. Hacker groups obtained winning bid information for real freight tenders. The ring leased tractors, affixed the name and registration number of the legitimate carrier that was supposed to make the pickup, drove to the facility and took the load. In February, they allegedly took 43,100 pounds of copper rod out of a Newark logistics center while impersonating a real carrier, drove it to the Bronx and sold most of it to a Brooklyn scrap yard. The tally across six thefts: $3.3 million in cigarettes, $432,000 in cheese, $295,000 in beef, more than $266,000 in copper, $165,000 in lamb.
On June 30, the Southern District of New York unsealed charges against eight more people in what prosecutors called an international network, alleging $10 million in cargo stolen from commercial shippers since March 2023, coordinated by at least one dispatcher located overseas with facilitators, drivers and warehouse workers in the United States.
In the Northern District of Illinois, Aivaras Zigmantas was sentenced to five years after pleading guilty to wire fraud in December 2025. Prosecutors said he used multiple aliases between 2020 and 2023 to impersonate real and fictitious carriers and brokers, intending to steal at least $14.6 million in freight and successfully took more than $10.1 million. Liquor and commercial-grade copper.
Amazon, which has more visibility into this than most, participates in 14 state organized retail crime task forces and says one of its investigations produced a federal indictment on 13 counts of wire fraud specifically for stealing carrier identities and submitting fraudulent invoices. Highway, a carrier identity platform, reported blocking nearly 2 million fraudulent email attempts and 8.5 million spoofed phone numbers in 2025.
The new vectors
Two developments from this year deserve more attention than they are getting.
The first is phone system compromise. CargoNet has observed criminal groups compromising software-based business phone systems, which allows a remote actor to place and receive calls from a motor carrier’s verified phone numbers and, in some cases, monitor active calls. Think about what that defeats. Every carrier vetting workflow in the industry includes a callback to a verified number. That control is now beatable. The same groups are using remote access tools, credential compromise, and social engineering to get themselves added as authorized users on a legitimate carrier’s own accounts. At the moment, a broker is deciding whether to tender a load; everything checks out, because the fraud actor is operating from inside the carrier’s real infrastructure.
The second is that criminal networks have stopped bothering to impersonate carriers and started buying them. CargoNet reports networks purchasing legitimate motor carrier businesses through social media, peer-to-peer marketplaces, and specialized brokerage services. The sales are frequent and essentially unregulated. If you own an authority and somebody offers you money for it, understand what you may be selling and what liability may follow you.
Anti-fraud tooling in this industry actually worked. That is why the criminals moved upstream. They stopped attacking the load and started attacking the identity.
Clones and chameleons
Which brings me back to cloned trucks and identity theft. A cloned truck is a tractor running another carrier’s DOT number and name. A chameleon carrier is a company that re-registers under a new DOT number with substantially the same people, equipment, and phone numbers, so the crashes, out-of-service orders, and enforcement history stay attached to the corpse of the old entity. Both are identity attacks. Both work because verification happens once, badly, at a moment when there is nothing to verify against.
GAO’s 2012 report on this, GAO-12-364, found that applicants with chameleon attributes were three times more likely than other new applicants to be involved in a severe crash, 18% against 6%. GAO recommended that FMCSA expand risk-based vetting beyond passenger and household goods carriers. FMCSA submitted a report to Congress in June 2013 describing a proof of concept for automated application screening, to be expanded with the Unified Registration System, resources permitting.
That was thirteen years ago. USR became MOTUS. MOTUS is rolling out through 2026 with identity verification and business verification at registration. FMCSA is also tightening principal place of business enforcement, which matters because a mailbox cannot be audited. Under 49 CFR 386.73, the agency can issue out-of-service orders and record consolidation orders against reincarnated entities and affiliates. Rep. Harriet Hageman introduced the SAFE Act in February to go after the same problem legislatively.
Better late is still better, but there are more than two million registered motor carriers, and the throughput problem GAO flagged in 2012 has not changed. You cannot manually investigate tens of thousands of new applicants a year, and if the screening is automated, it is only as good as the entity resolution behind it.
The through line
I have written three pieces this week about what look like three different crimes.
Somebody drives a Malibu into the side of a tractor-trailer on I-10, and a law firm turns it into a seven-figure settlement. Somebody declares one truck on an instant-issue policy and runs 600 VINs across 40 states until the policy lapses at day 92. Somebody leases a day cab, tapes a real carrier’s name and DOT number to the door, and drives 43,000 pounds of copper out of a gate in New Jersey.
Different crimes. Same hole. At every one of those points, a system took somebody’s word about who they were. The responding officer took the passengers’ word about who was driving. The insurer took the applicant’s word about how many trucks it ran. The shipping clerk took the label’s word about where the carton was going, and the dock guard took the placard’s word about which carrier had shown up.
We built a national freight network on identity assertions and then spent twenty years automating away the humans who used to check them. Every fraud in this business now runs through that gap, whether the payload is a fake soft-tissue injury, an unscheduled 80,000-pound truck, or a trailer of enterprise server blades.
The Nike case will end with verdicts, but the ceiling on what enforcement can accomplish is set by how long it takes to notice. Roy Harvey Jr. got arrested in January 2024, and the labels kept flowing through June. Operation Sideswipe took seven years and a murdered witness. The one-truck carriers cycle to a new authority in 90 days.
Prosecution is what happens after the loss. Verification is what happens instead of it. We keep funding the first one and arguing about the second.


