CSIDB logo
Incident

North Carolina State Ports Authority

Incident posture

Attack window
Aug 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-22 00:12

Linked entities

Victim
North Carolina State Ports Authority
Threat actors
0 actors
Sources
3 sources

Timeline

Occurred
Undetermined
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. The incident caused a systems‑wide outage that forced gate openings to be delayed and prompted a shift to manual processing while the authority activated its cybersecurity contingency plan and coordinated with state and federal partners including the U.S. Coast Guard. As recovery efforts continue, normal schedules are gradually being restored but residual delays are expected as affected systems and services are brought back online.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 4, 2026, the North Carolina Ports Authority detected a cyberattack on its IT systems affecting the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The authority immediately activated its cybersecurity contingency plan and began recovery efforts the morning of August 5. As a result of a systems‑wide outage, gates at all three facilities were scheduled to open at 8 a.m. on August 5, forcing the agency to shift to manual processing while it worked to contain the intrusion. The Port of Wilmington, which has nine berths and an annual container capacity of 600,000 TEU, normally handles about 5,000 container gate moves per week. Together, the Ports of Wilmington and Morehead City move approximately 4.4 million short tons of bulk and breakbulk cargo each year, serving as key regional logistics hubs. The Charlotte Inland Port functions as an inland hub supporting the same cargo flows.

By the morning of August 5, the authority reported that the breach had been contained and that it was in the recovery process, though it noted that delays could be expected as work to restore affected systems and services continued. On August 6, a notice posted on the ports authority website indicated that a normal operating schedule was in effect while IT teams continued their investigation, but it cautioned that delays might still be experienced. The authority’s latest status update on August 7 stated that gates at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port would follow a normal operating schedule on August 7 and that vessel activity would proceed as scheduled, while acknowledging that delays could still be expected as assessments and restorations continued. The authority did not attribute the attack to a known threat actor and did not disclose whether any sensitive data had been stolen. It also refrained from providing an estimate of how much truck or cargo traffic had been affected by the disruption.

The North Carolina Ports Authority engaged state and federal partners after discovering the attack, including the North Carolina Department of Transportation, the North Carolina Department of Information Technology, and the U.S. Coast Guard, which said it was monitoring the aftermath and coordinating with partner agencies while the investigation proceeded. A Coast Guard spokesperson told CyberScoop that the branch’s IT unit was working with other agencies, and a CISA spokesperson did not respond to requests for comment. While the authority noted that the incident adds to a recent string of cyberattacks against water and wastewater systems in the United States, it emphasized that there had been no public information tying the port cyberattack to a specific actor, and experts’ confidence in Iranian responsibility for the water‑system attacks did not extend to this incident. The authority said it would continue posting updates on its website and directed users to its email alert service for further information.

Sources

Sources available to members: 3 sources.

CSIDB