What happened?
FMCSA replaced its legacy registration process with Motus, the new USDOT Registration System, on May 19, 2026. Motus exists in large part to make carrier and broker identity fraud harder.
In September 2026, FMCSA issued a fraud alert warning that bad actors are now impersonating Motus itself. The agency named four fraudulent websites built to look like the federal registration portal.
The timing is not accidental. On September 10, 2026, FMCSA temporarily suspended enforcement action against carriers who missed biennial update deadlines, to reduce disruption during the Motus transition. That is exactly the kind of churn that makes an unexpected "your registration needs updating" email look plausible.
The four fake sites, and the only real one
There is one legitimate Motus address:
motus.dot.gov
FMCSA has identified these four as fraudulent:
- dot.motusdatasboard.com
- dot.motusdatadesk.com
- dot.motuswebdeck.com
- dot.motusfunction.com
Look at what these have in common. Each one front-loads official-sounding words β dot, motus β so a quick glance reads as government. But the actual registered domain is the part immediately before the ending, and every one of them ends in .com. A real federal registration system ends in .gov. Nothing else does.
Read domains from the right, not the left.
The email that carries it
Carriers have reported messages with the subject line:
"Notice of Required Off-Cycle Update- Motus email"
The body claims your carrier profile requires an out-of-cycle update and pushes you toward a button labelled "New MOTUS Portal".
That capitalisation is itself a tell. FMCSA writes the system name as Motus, not MOTUS. It is a small thing, and small things are usually what give these away.
What the fake sites are actually after
These are credential-harvesting pages. What they collect is the set of things needed to take over your FMCSA registration:
- Motus login credentials
- Company identifying details
- Officer and principal names
- DOT PINs
With those, someone can alter your registration record β change the address, change the officers, redirect where your authority points. That is the mechanism behind carrier identity theft and double-brokering fraud, and it is far more damaging than a stolen password on an ordinary account. Cleaning up a hijacked DOT registration takes months.
Small fleets are the softest target, because the person processing a compliance-flagged email is often the same person dispatching trucks that morning.
How to verify any registration request
Four checks, in order:
- Do not click the link in the email. Type motus.dot.gov into the browser yourself, or use a bookmark you made previously.
- Check the sender domain. Official FMCSA correspondence comes from an address ending in .gov.
- Check the link destination before clicking anything. Hover over it and read the end of the domain, not the beginning.
- Call and confirm. FMCSA registration support is 1-800-832-5660. A genuine deadline will survive a phone call.
And the rule that covers everything else: FMCSA will never ask for payment or sensitive information β UCR, PIN, SSN, EIN or bank details β through an unsolicited message. An unsolicited email also does not override an official notice you received through proper channels.
What to do if someone already clicked
Move quickly; this is recoverable if you get ahead of it.
- Change the Motus password immediately, and change it anywhere that password was reused.
- Request a new DOT PIN if a PIN was entered.
- Log in at motus.dot.gov directly and check your registration record for changes you did not make β address, officers, contacts, authority status.
- Report it. FMCSA at 1-800-832-5660 or ask.fmcsa.dot.gov; the FTC at reportfraud.ftc.gov; the FBI at ic3.gov. Local police and your state attorney general if money moved.
- Tell your insurer and your factoring company if you use one. They are downstream of your registration data.
The wider point for carriers
Every time FMCSA changes a system, a window opens. Carriers are expecting unfamiliar notices, deadlines are genuinely moving, and the normal instinct β this looks official, handle it now β is exactly the instinct the scam needs.
The defensive habit worth building is simple and it is not technical: nobody on your team ever reaches a federal system by clicking a link in an email. Bookmark motus.dot.gov. Go there directly. Every time.