Menu
Browse

Cyber Incident Victim: North Carolina Ports Authority

Date

Aug 2026

Location

United States of America

Status

Ongoing

Updated

2026-08-08 06:58

Timeline
Occurred
Aug 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Aug 2026
Summary

The North Carolina Ports Authority reported a cyberattack that disrupted gate operations at its three facilities, forcing a shift to manual processing and delayed openings while the IT team activated its contingency plan. The breach was contained and recovery efforts were underway, though the authority did not disclose the specific systems affected or whether vessel movements, cargo handling, or rail services were impacted. No public attribution has been made, and the Coast Guard is monitoring the incident while coordinating with state and federal partners. The ports, which handle significant bulk and container traffic for the southeastern United States, continued to post updates and encouraged users to subscribe to email alerts for further information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On Tuesday, August 4, 2026, the North Carolina State Ports Authority detected a cyberattack on its IT system, as reported to local media. The authority immediately activated its Cybersecurity Contingency Plan and began working to contain the intrusion. By Wednesday morning, August 5, the breach had been contained and the authority noted it was entering the recovery process. A notice posted on the ports’ website announced that, due to a systems‑wide outage, gates at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port would open at 8 a.m. on August 5, with delays expected.

Cyber Incident Image

The cyberattack forced the agency to delay gate openings and shift to manual processing while it worked to contain the intrusion, affecting all three port facilities: the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. As of Friday morning, August 7, the ports website indicated a normal operating schedule was in effect while IT teams continued their investigation. The authority did not disclose the nature of the attack, which specific systems were affected, or whether vessel operations, cargo‑handling equipment, or rail services were disrupted. No estimate was provided for the amount of truck or cargo traffic impacted by the disruption.

In response to the incident, the ports authority engaged state and federal partners, including the North Carolina Department of Transportation, the North Carolina Department of Information Technology, and the U.S. Coast Guard, which said it was monitoring the aftermath of the attack. The Coast Guard’s IT unit coordinated with partner agencies while the investigation continued, and CISA was contacted but did not respond to inquiries. The authority stated it would continue posting updates on its website and directed users to its email alert service for further information. As of Friday morning, there had been no public information tying the port cyberattack to a specific actor, although the article noted that experts have expressed confidence that Iranian actors are responsible for a recent string of cyberattacks against water and wastewater systems in the United States.

Sources
Sources available to members
2 sources