CURepossession

Where the repossession industry gets its news

The Yerevan Connection: Following the Transport Fraud Trail to Repossession Lots

The Yerevan Connection: Following the Transport Fraud Trail to Repossession Lots

Armenian-linked cybercriminals targeted Central Dispatch as strikingly similar fraud schemes began reaching American repo lots

 

A police raid thousands of miles away in Yerevan, Armenia may have just provided another piece of a puzzle the U.S. repossession industry has been trying to solve for years.

On July 23, Armenian authorities raided commercial premises inside a Yerevan hotel following an investigation into an alleged organized criminal operation targeting the American transportation industry.

According to Armenia’s Ministry of Internal Affairs, members of the organization allegedly used specialized computer equipment and software to pose as employees of companies transporting freight inside the United States.

The alleged objective was not simply to steal money.

Investigators say the suspects gained the trust of businesses arranging freight transportation, caused cargo to be delivered somewhere other than its intended destination, sold the stolen goods and moved the proceeds through financial accounts before converting them into cryptocurrency.

The FreightWaves report on the Armenian investigation described Armenian authorities as cooperating with U.S. law enforcement not only to identify victims, but also to identify other groups in Armenia engaged in similar criminal activity.

At first glance, this appears to be another cargo theft story.

It may be much more relevant to repossession than that.

Because when the Yerevan investigation is placed beside a separate cybercrime investigation, federal transportation fraud cases and a series of transporter theft warnings previously reported by CURepossession, several lines begin crossing in a very interesting place.

The American vehicle transportation system.

And specifically, Central Dispatch.


CURepossession Readers Have Seen This Movie Before

In July 2025, the American Recovery Association issued an alert warning repossession agencies about a growing transporter fraud problem.

As CURepossession reported at the time, vehicles were being released through what appeared to be legitimate transportation arrangements, yet somewhere in the chain between client, auction, transport broker, transporter and repossession lot, release information was apparently being intercepted or manipulated.

The person arriving at the agency could possess documentation that appeared legitimate.

The vehicle was released.

Then it disappeared.

A subsequent CURepossession investigation, “Auto Transport Theft Scheme Exposed,” examined how criminals could exploit transportation systems to steal vehicles, including a reported scheme involving a Lamborghini valued at approximately $700,000.

The mechanics were particularly concerning.

A criminal did not necessarily need to personally arrive at the lot pretending to be a truck driver.

A fraudulent carrier or broker could obtain the load, manipulate transportation information, repost or redispatch it and use an innocent legitimate transporter to physically pick up the vehicle.

The driver himself might have no idea that he was participating in a theft.

That created a troubling question.

How does a repossession agency identify a fraudulent transporter when the transporter standing at its gate might actually be legitimate?

At the time, there were pieces missing from the puzzle.

There aren’t as many missing today.


Enter Diesel Vortex

In February 2026, cybersecurity researchers exposed a sophisticated phishing operation known as Diesel Vortex.

According to The Record’s reporting on the investigation, the operation compromised more than 1,600 logistics credentials during a five-month campaign targeting transportation companies in the United States and Europe.

The operation wasn’t simply harvesting passwords for financial theft.

Those credentials could be used to intercept and divert physical freight shipments.

Investigators reportedly uncovered internal communications, source code, victim databases and organizational information after discovering an exposed development repository.

What emerged looked less like an individual hacker and more like a business.

The operation reportedly included personnel responsible for call-center activity, programming, email support and finding drivers, carriers and transportation contacts.

Researchers also uncovered Armenian-language communications and Armenian IP addresses. One participant reportedly identified his location as Yerevan.

The Yerevan Connection: Following the Transport Fraud Trail to Repossession Lots
Click to enlarge – Source Wikipedia

That alone would make Diesel Vortex interesting in light of the recent Armenian raid.

But then comes the connection to automobiles.

Central Dispatch was among the transportation platforms targeted by Diesel Vortex.

Central Dispatch isn’t simply another general freight load board. It is one of America’s largest marketplaces connecting vehicle shippers and auto transport carriers.

The cybercriminals weren’t merely knocking on the door of American freight transportation.

They were already knocking on the door of American automobile transportation.


They Weren’t Just Stealing Passwords

The internal communications uncovered by researchers make the operation even more relevant.

Diesel Vortex operators reportedly discussed acquiring the complete carrier information necessary to convincingly assume transportation identities.

That included carrier credentials, broker information, email access, telephone communications and other information necessary to make a fraudulent transportation transaction appear legitimate.

Operators reportedly used spoofed or virtual telephone numbers and techniques intended to defeat ordinary verification.

Then researchers uncovered a particularly revealing discussion.

Members of the operation reportedly asked whether they had access to a motor carrier identity carrying $250,000 in cargo insurance.

Why would a cybercriminal care how much cargo insurance a stolen carrier identity had?

Because credentials aren’t all equally valuable.

A transportation identity with stronger credentials and higher insurance limits can potentially gain access to more valuable cargo.

For the repossession industry, the implication is difficult to miss.

They weren’t necessarily just looking for passwords.

They were looking for transportation identities strong enough to be trusted with expensive property.

And among the platforms being targeted was Central Dispatch.


Two Ways to Become an American Carrier Without Being One

Diesel Vortex isn’t the only Armenian connection to American carrier fraud.

In January 2025, federal prosecutors charged Serj “Seryozha” Gevorgyan in an alleged international double-brokering operation.

According to the U.S. Department of Transportation Office of Inspector General, Gevorgyan allegedly submitted fraudulent FMCSA registrations to obtain legitimate U.S. operating authority for motor carriers and freight brokerages.

The filings allegedly falsely represented who controlled the companies, where they operated and their relationships with other FMCSA-regulated entities.

The alleged operation included call centers in Armenia.

In other words, one alleged Armenian operation demonstrated how criminals could create an apparently legitimate American carrier identity.

Diesel Vortex demonstrated something potentially even more dangerous.

Why create one when you can steal one?

Compromise the credentials of an established carrier and many of the conventional verification points can suddenly become less effective.

Company name?

Legitimate.

DOT number?

Legitimate.

MC authority?

Legitimate.

Insurance?

Legitimate.

Transportation marketplace account?

Potentially legitimate.

The person controlling them isn’t.

That distinction could fundamentally change how repossession agencies think about transporter verification.


Then Another Yerevan Name Appeared

On June 30, 2026, federal prosecutors in New York announced charges against eight defendants in an alleged international cargo theft organization accused of stealing millions of dollars in commercial goods.

According to the federal indictment, members allegedly impersonated legitimate participants in the transportation chain, fraudulently obtained loads, manipulated shipping information and redirected merchandise.

One defendant was Edgar Bezhanian, an Armenian citizen believed to have resided in Eastern Europe, including Armenia.

Prosecutors allege Bezhanian altered shipping paperwork and communicated with members of the enterprise about where fraudulently obtained loads should be picked up and delivered.

There is currently no evidence establishing that Bezhanian, Gevorgyan, Diesel Vortex or the organization targeted in the July Yerevan raid are part of the same criminal organization.

They should not be presented as one.

But they do demonstrate something larger.

Armenia, and repeatedly Yerevan, has surfaced in multiple investigations involving the exploitation of American transportation identities and systems.


And Then Armenian Police Raided Yerevan

That brings the timeline back to July 23.

Armenian authorities say they discovered an organization operating from commercial space inside a Yerevan hotel using computer equipment and software to pose as employees of American transportation companies.

Video: Armenia’s Ministry of Internal Affairs details the Yerevan operation discussed above. Narration is in Armenian.”

The alleged criminals gained control of freight movements.

Cargo went somewhere it wasn’t supposed to go.

The property was sold.

The money moved.

The proceeds ultimately entered cryptocurrency.

And Armenian authorities are now reportedly working with U.S. law enforcement to identify additional victims and other groups in Armenia allegedly engaged in similar activity.

That last detail may prove important.

This may not be one operation.

It may be an ecosystem.


The Automotive Connection Is No Longer Theoretical

None of the available evidence establishes that the organization raided in Yerevan on July 23 stole a repossessed automobile.

That distinction matters.

CURepossession has found no evidence connecting that organization to any specific vehicle stolen from a repossession agency.

Nor is there evidence currently establishing that Diesel Vortex was responsible for the specific transporter thefts previously reported by this publication.

But the broader automotive connection is established.

Diesel Vortex targeted Central Dispatch.

And Central Dispatch’s own current fraud guidance describes precisely the threat facing the vehicle transportation industry.

The company warns that criminals can pose as legitimate logistics companies using either legitimate stolen credentials or fraudulent documents to steal vehicles. It warns carriers about requests to reroute vehicles and shippers about identity theft and double brokering.

Central Dispatch also warns that fraudulent websites are being used to steal FMCSA credentials from carriers.

The Federal Motor Carrier Safety Administration has been issuing similar warnings.

Its Broker and Carrier Fraud and Identity Theft guidance specifically warns about criminals using another carrier’s USDOT number and cautions that websites, telephone numbers and even insurance documentation can be fraudulent.

FMCSA recommends independently confirming carrier information, matching the truck arriving for the load to the carrier contracted for it, recording tractor and trailer plates and stopping suspicious transactions.

The agency even warns that the legitimate carrier hauling a fraudulent load may itself be a victim.

That point should sound particularly familiar to repossession agencies.


The Driver at Your Gate May Not Be the Criminal

This is perhaps the most troubling evolution of transporter fraud.

For decades, physical security at a repossession agency was relatively straightforward.

Fence.

Gate.

Cameras.

Locks.

Control who enters.

But what happens when the person asking you to open the gate is a legitimate truck driver?

Suppose a criminal compromises the digital identity of ABC Transport.

The criminal obtains a vehicle assignment and hires XYZ Auto Transport to perform the physical move.

XYZ’s driver arrives at the repossession agency.

His driver’s license is real.

His truck is real.

His company is real.

His insurance is real.

He may genuinely believe he has been hired to transport that vehicle.

The problem exists above him in the digital transportation chain.

The repossession agency releases the vehicle.

Hours later, the driver receives revised delivery instructions.

The destination changes.

And everyone involved in physically releasing and moving the automobile may have believed they were participating in a legitimate transaction.

That is not traditional auto theft.

It is identity theft converted into physical asset theft.


Why the New Verification Demands Suddenly Make More Sense

In a recent guest editorial, “Transport Fraud Pressure Begins Shifting Toward Repossession Agencies,” CURepossession reported on expanded transporter verification procedures being required of recovery agencies.

Agencies were being asked to verify driver identity, DOT information, digital load information, app-based credentials, carrier information, equipment and the vehicle itself before releasing collateral.

Some recovery operators understandably questioned why a transportation fraud problem originating upstream was becoming the operational and potentially financial responsibility of the repossession agency.

The Yerevan and Diesel Vortex investigations don’t resolve that liability question.

But they help explain the threat those procedures are attempting to address.

The weakness isn’t necessarily a fake truck driver carrying a poorly forged release order anymore.

The weakness may be the identity behind the entire transaction.


Checking the DOT Number May No Longer Be Enough

That may be the biggest lesson for the repossession industry.

For years, verifying the carrier meant verifying the carrier.

DOT number.

Operating authority.

Insurance.

Dispatch.

Driver.

Those remain essential.

But stolen credentials introduce an entirely different problem.

If the criminal has successfully assumed the identity of a legitimate transportation company, checking the legitimacy of the company may only confirm that the victim whose identity was stolen is legitimate.

The better question becomes:

Is this specific driver, driving this specific equipment, operating under this specific dispatch, authorized by the actual carrier to pick up this specific VIN and deliver it to this specific destination right now?

That is transaction authentication rather than carrier verification.

There is a huge difference.


The Repo Lot May Be the Last Place This Theft Can Be Stopped

Ironically, that leaves the repossession agency in a potentially powerful position.

By the time the transporter arrives, the digital fraud may already have succeeded.

A broker account may have been compromised.

A carrier identity may have been stolen.

A release may have been intercepted.

A legitimate driver may have been dispatched.

But the vehicle hasn’t moved yet.

The repossession lot may be the last controlled physical checkpoint in the entire transaction.

That makes several defensive principles increasingly important.

The arriving transporter should confirm information the repossession agency already possesses through a trusted channel, rather than supplying the information the agency then uses to authenticate him.

A changed driver, changed carrier, changed truck or changed destination should trigger renewed verification.

For particularly valuable vehicles or suspicious transactions, an independent callback to an established contact at the originating client, auction, broker or carrier may be worth far more than the minutes it consumes.

Driver identity, truck and trailer plates, vehicle condition, VIN and release information should be documented at pickup.

And the industry may eventually need something stronger.

A one-time vehicle release credential tied to the VIN, carrier, driver and transaction could operate much like multifactor authentication does in banking.

Once used, it dies.

A stolen screenshot or intercepted release from yesterday would no longer open tomorrow’s gate.


The Industry Saw Part of This Coming in 2021

There is an interesting historical footnote to all of this.

Five years ago, repossession associations were already fighting over control of third-party transporter access to recovery lots.

As CURepossession reported in 2021, a coalition of repossession associations supported agency requirements governing third-party transporters entering recovery facilities.

At the time, the dispute largely involved insurance, liability, property access and chain-of-custody concerns.

Five years later, those same gates sit at the intersection of physical security and cybersecurity.

The question is no longer merely:

Is this transporter insured to enter my property?

It is becoming:

Is this transporter actually who the digital transportation system says he is?


The Gate Has Become a Cybersecurity Control

There is still much we don’t know.

We don’t know whether the July 23 Yerevan organization stole automobiles.

We don’t know whether it accessed Central Dispatch.

We don’t know whether Diesel Vortex was responsible for any of the specific vehicle thefts reported by repossession agencies.

And we don’t know whether the separate Armenian-linked transportation fraud investigations are connected to one another.

Those lines should not be crossed without evidence.

But we now know something we didn’t know when the first transporter fraud warnings began reaching the repossession industry.

An Armenian-linked cybercrime operation with personnel connected to Yerevan was systematically attacking transportation identities.

It targeted Central Dispatch.

It stole logistics credentials.

Its operators understood American motor carrier identities.

They reportedly sought credentials associated with higher cargo insurance limits.

Separately, federal investigators have documented Armenian call-center operations allegedly manipulating U.S. motor carrier identities, while another federal cargo-theft case includes an Armenian defendant accused of altering shipping information and directing fraudulently obtained loads.

Then Armenian police raided an alleged Yerevan operation accused of impersonating American transportation companies, diverting U.S. freight, selling it and converting the proceeds to cryptocurrency.

Meanwhile, American repossession agencies have been reporting vehicles disappearing through transportation chains involving manipulated releases, fraudulent carrier identities, double brokering and unsuspecting drivers.

There is not yet evidence proving those are the same crimes.

There is enough evidence to recognize that they exploit the same door.

For more than a century, repossession agencies have protected collateral with fences, cameras, gates, locks and people.

The international criminal sitting behind a computer thousands of miles away doesn’t necessarily need to defeat any of them.

He doesn’t need to cut the fence.

He doesn’t need to pick the lock.

He doesn’t even need to steal the tow truck.

He only needs to convince someone that the person standing at the gate is authorized to take the car.

And then the gate opens.

The next security perimeter for the repossession industry may not be a taller fence.

It’s identity.

The Yerevan Connection: Following the Transport Fraud Trail to Repossession Lots – The Yerevan Connection: Following the Transport Fraud Trail to Repossession Lots – The Yerevan Connection: Following the Transport Fraud Trail to Repossession Lots

The Yerevan Connection: Following the Transport Fraud Trail to Repossession Lots – RepossessRepossessionRepossession AgencyRepossessorRepossessionRepossession NewsTransportFraudFraud