Another DOT IG investigation: FMCSA Needs to Improve Oversight of CDL Disqualifications
IG: FMCSA IT Infrastructure at Risk of Compromise
The DOT inspector general's office wanted to find out if the Federal Motor Carrier Safety Administration's IT infrastructure contains security weaknesses.

Is the FMCSA vulnerable to hacking?
Photo: Public Domain
Three years after the Federal Motor Carrier Safety Administration’s new medical examiner’s registry was hacked, the agency’s information technology infrastructure is still at risk of being compromised, according to a new report from the Department of Transportation’s Inspector General’s office.
The FMCSA uses 13 web-based applications to aid vehicle registration, inspections, and other activities. Many of FMCSA’s information systems contain sensitive data, including personally identifiable information.
Although the IG’s report doesn’t cite a specific reason for its investigation, which began two years ago, the late 2017 hack of the registry is still causing delays in full implementation of the certified medical examiner program. While FMCSA said the hack was unsuccessful in that no personal information was exposed, the incident caused the agency to go back to the drawing board to develop a more secure portal.
According to its announcement, the inspector general's audit of FMCSA’s IT infrastructure was conducted because of the importance of FMCSA’s programs to the transportation system and sensitivity of some agency information. Its objective was to determine whether FMCSA’s IT infrastructure contains security weaknesses that could compromise the agency’s systems and data.
And it found them.
“We found vulnerabilities in several agency web servers that allowed us to gain unauthorized access to FMCSA’s network,” notes the IG’s report. “FMCSA did not detect our access or placement of malware on the network in part because it did not use required automated detection tools and malicious code protections. We also gained access to 13.6 million unencrypted [personally identifiable information] records. Had malicious hackers obtained this PII, it could have cost FMCSA up to $570 million in credit monitoring fees.”
The report also said FMCSA “does not always remediate vulnerabilities as quickly as DOT policy requires. These weaknesses put FMCSA’s network and data at risk for unauthorized access and compromise.”
The office made 13 recommendations, which it said the FMCSA concurred with. However, because publicizing the recommendations could constitute a security risk, the IG’s office did not disclose what those recommendations were.
More Safety & Compliance

Brake Safety Week to Focus on Drums and Rotors
Commercial vehicle inspectors will be focusing on brakes during CVSA's Brake Safety Week, August 23-29.
Read More →
Trump Administration Looks to Put More Veterans Behind the Wheel
The Freedom Haulers program pulls together existing and expanded programs at several federal agencies to recruit veterans to drive commercial heavy-duty trucks and cut the red tape for them to get a CDL, training, and employment.
Read More →
$604 Million Verdict Tests Broker Liability After Supreme Court Ruling
C.H. Robinson plans to appeal after a Texas jury found it bore the largest share of responsibility for a fatal 2021 crash, in a case that follows the Supreme Court's Montgomery decision allowing negligent hiring claims against freight brokers.
Read More →
How Fraley & Schilling Improved Logbook Compliance by Over 50%
Fraley & Schilling needed a way to close a compliance workflow gap in its ELD system without adding more work from driver training, reminders, and back-office follow-ups. It found the answer in a custom driver app.
Read More →
Farewell, CDL: Why I'm Giving Up My Commercial Driver's License
After more than 20 years as a CDL holder, HDT Executive Editor Jack Roberts is letting his commercial license expire. Not because he wants to — but because trucking's nuclear verdict crisis has made the risks of public-road test drives too great for editors, manufacturers, and everyone involved.
Read More →
Enhance Fleet Performance with High-Efficiency Auxiliary Power Units
Drive sustainable cost savings while increasing driver comfort during short- and long-haul logistics operations.
Read More →
Wabash Trailers Recalled for Improperly Installed Underride Guards
More than 900 Wabash dry van trailers may not comply with the Federal Motor Vehicle Safety Standard for rear impact guards.
Read More →
Why K&B Trucking Is Embracing AI and Driver Safety Technology
Crunching data and embracing artificial intelligence are key in K&B Trucking's safety efforts, says the company's safety director.
Read More →
The Hidden Problem Behind FMCSA's ELD Revocations
NMFTA researchers say dozens of registered ELDs may be built on the same software platforms, allowing compliance and security concerns to persist even after individual devices are removed from the market.
Read More →
ATRI Wants Motor Carriers for Driver-Facing Camera Study
In this new study, the American Transportation Research Institute will explore how driver-facing cameras can impact safety and operational metrics in trucking fleets.
Read More →
