GLP-1 drugs turned pharmaceutical cargo into a consumer product. Organized crime noticed. Here’s what that means for every stakeholder between the manufacturer and the patient.

Verisk CargoNet put estimated cargo theft losses at nearly $725 million in 2025, up 60 percent from the year before, according to CargoNet’s annual analysis published January 21, 2026. The incident count barely moved. CargoNet recorded 3,594 supply chain crime events across the United States and Canada in 2025, essentially the same as the 3,607 recorded in 2024. That’s the tell. Thieves aren’t grabbing more loads. They’re grabbing better ones, and in pharmaceuticals, ‘better’ now means a temperature-sensitive injectable that a gray-market buyer will pay somewhere between $936 and $1,023 a month to get, with or without a prescription.

The pharmaceutical supply chain has spent decades earning its reputation for security. The industry knows it has lower risk tolerance and higher liability exposure than almost any other sector, so it’s typically the first mover on layered technology and the first to write internal controls. That discipline has held: despite being one of the most aggressively targeted commodity classes by organized cargo thieves, pharma consistently posts one of the lowest actual theft rates in the mix. That’s a real achievement. It’s also becoming harder to hold, because the commodity itself is changing faster than the security framework around it.

GLP-1 weight-loss drugs, semaglutide, sold as Ozempic and Wegovy; tirzepatide, sold as Mounjaro and Zepbound, have turned a regulated pharmaceutical into something that looks and behaves like a consumer product. The average monthly list price in the United States runs between $936 and $1,023, insurance coverage for weight-loss indications remains spotty, and the telehealth channel has built a direct pipeline from prescriber to patient that bypasses the traditional pharmacy entirely. That combination creates a predictable gray market, and organized crime filled it. When a product commands a thousand dollars a month retail, has a documented shortage history that trained consumers to seek it outside the licensed channel, and ships in a standard refrigerated truck on a predictable interstate route, it stops being a pharmaceutical and starts being a target.

In February 2026, armed thieves stole more than 1,600 units of tirzepatide from a truck in Paraguay, according to BSI Connect Screen data reported by BSI Group. That single incident prompted warnings from authorities that the shipment would move quickly across neighboring markets. It wasn’t an outlier. BSI tracked 166 pharmaceutical cargo theft incidents globally from 2024 through the first half of 2026, with 78 percent of that activity concentrated in North and South America. South America is now the fastest-rising hotspot, accounting for more than half of recorded pharmaceutical cargo thefts so far in 2026, up from under a quarter the year before, according to BSI’s data. Brazil and Mexico represented nearly two-thirds of H1 2026 incidents alone.

The theft method matters as much as the geography. BSI’s Connect Screen data shows that up to 31 percent of pharmaceutical cargo theft incidents between 2024 and 2026 occurred while products were in transit, with trucks accounting for nearly 70 percent of reported thefts. Fictitious pickups — where a criminal impersonates a legitimate carrier, accepts the load at the shipper’s dock, and disappears into the network — have become a dominant vector. Verisk CargoNet warned in its Q1 2026 analysis, published April 23, 2026, that impersonation-based fraud and the exploitation of legitimate carrier identities will remain central to cargo theft through the coming quarters, with organized groups expanding their focus to vulnerabilities across the full shipment lifecycle rather than just the point of tender. The industry term for the move is strategic freight fraud, and Munich Re Specialty’s 2026 Cargo Theft Tactics and Trends report, produced in partnership with BSI, confirmed that fraud has overtaken force as the defining feature of cargo crime in the U.S. market.

The patient safety problem sits inside the cold chain. GLP-1 injectables require strict temperature-controlled storage and transportation throughout their lifecycle. Once the cold chain breaks, which it does the moment a trailer is diverted to an unsecured location, the product degrades. The degradation isn’t visible. The lot number, serial number, and packaging all look authentic because they are authentic. What’s gone is the integrity of the product inside. According to BSI’s analysis of the counterfeit GLP-1 market, these diverted products can reach patients without triggering recalls or verification alerts, and counterfeit producers use stolen product, packaging, and delivery devices as intelligence for manufacturing convincing fakes. One Brazilian physician cited in CNN’s September 2026 reporting told the outlet he treated a patient who developed lactic acidosis after using a product sold as tirzepatide sourced from Paraguay. The patient bought the product without a prescription. The patient ended up in intensive care.

The federal traceability architecture is supposed to close this gap. The Drug Supply Chain Security Act, the DSCSA, enacted in 2013 under Title II of the Drug Quality and Security Act, preempts a 50-state patchwork of pedigree requirements and creates one federal framework for tracking prescription medicines from manufacturer to dispenser. The law built its requirements in phases. Phase I, beginning in January 2015, required supply chain participants to share chain-of-ownership documentation at the lot-level and work only with authorized trading partners. Phase II, which began November 27, 2023, stepped up to interoperable, electronic tracing at the individual package level: every unit gets a serialized product identifier encoding the National Drug Code, serial number, lot number, and expiration date, and every trading partner must exchange that data electronically and be able to verify it. That’s the system as designed. The plain version of what DSCSA Phase II requires is this: when a package of semaglutide changes hands, every party in the chain has to be able to prove electronically where it came from and that the identifier checks out. A stolen unit re-entering the licensed distribution channel should trigger a verification failure. The gray market is a gray market precisely because it runs outside the licensed channel, where none of those checks apply.

Implementation is messier than the statute. The FDA announced a one-year stabilization period in August 2023 because much of the industry wasn’t ready to meet the enhanced requirements. In June 2024, FDA announced exemptions for small dispensers and their trading partners until November 27, 2026. In October 2024, after the stabilization period expired, the agency issued a second round of phased exemptions for “eligible trading partners” defined as trading partners who made documented efforts to complete data connections but still faced challenges exchanging data. The system is live, and compliance is advancing. It’s not universal, and gray-market operators don’t file for exemptions.

What Overhaul’s Danny Ramon argued in Pharmaceutical Commerce on September 8, 2026, is that the industry has treated this as a logistics problem when it’s actually a quality and regulatory problem. The stolen or compromised product that matters isn’t the product that gets reported missing. It’s the product that re-enters a supply channel, compounding pharmacy, online fulfillment, cross-border import, where the stability data doesn’t follow it, where no one has run the DSCSA verification check because no one in that channel is required to, and where the patient has no way to know the cold chain broke somewhere between a Paraguay truck and a Brooklyn dispatch address. Ramon’s argument is that quality teams and regulatory teams need faster internal protocols and more accessible stability data at the point of a theft event, not just at the point of manufacture. That’s right, and it extends beyond the quality function: brokers and third-party logistics providers who tender pharmaceutical loads also select carriers and, in doing so, select the risk.

Overhaul recorded 574 cargo theft incidents in the United States in Q1 2026 alone, with 36 percent taking place in California, according to its Q1 2026 US Cargo Theft Report. CargoNet’s Q1 2026 data, published April 23, 2026, recorded 767 supply chain crime events across the U.S. and Canada for the same period, with estimated losses reaching $131.58 million despite the modest dip in incident volume. Confirmed cargo theft reports rose by 41 incidents quarter-over-quarter. Fewer events, same dollars lost. The average per-theft value is rising because targets are increasing. CargoNet’s 2025 annual analysis put the average theft value at $273,990, up 36 percent from $202,364 in 2024. A pharmaceutical full-truckload containing a pallet of GLP-1 product can easily clear that average. The median pharma theft value, per earlier BSI data, runs at $100,000, and that’s for smaller incidents.

Carrier vetting is where logistics meets liability, and it’s the part the industry least likes to discuss plainly. A fictitious pickup doesn’t happen because a building’s physical security failed. It happens because someone accepted a load tender from an entity claiming to be a licensed carrier without verifying that the carrier at the dock matched the carrier on the confirmation. That’s a process failure, and it shows up in litigation. If your pharmaceutical load moves to an unsecured location on a credential that didn’t belong to the truck that picked it up, the question of who selected that risk and how they selected it becomes a legal question, not just an operational one. CargoNet noted in its 2025 annual analysis that many complex cargo theft schemes rely on acquiring existing motor carriers with strong load histories, the same authority-reincarnation dynamic that shows up in every other sector of freight fraud. A pharmaceutical logistics provider that checks the MC number and stops there hasn’t done carrier vetting. It has done carrier lookup. Those aren’t the same thing.

The operator directive is short. If you move pharmaceutical freight, including GLP-1 products, specialty injectables, or any cold-chain drug with documented gray-market demand, your carrier-vetting standard needs to match the commodity value and theft patterns, not the general freight standard. Verify that the carrier picking up the load is the carrier confirmed on the load. Run the DSCSA transaction verification on every change of custody. Know where your stability data lives and how fast your quality team can access it when a load goes dark, because the clock on cold-chain degradation doesn’t wait for a claims investigation. The theft trend isn’t reversing. CargoNet’s Keith Lewis said it plainly in the 2025 annual report: criminal enterprises are becoming more selective and sophisticated, targeting high-value shipments rather than relying on opportunistic theft. GLP-1 drugs are high-value, consumerized, gray-market-accessible, and cold-chain-dependent. That combination won’t attract less attention from organized crime next quarter. It’s going to attract more.