North Carolina State Ports Authority
Incident posture
Linked entities
- Victim
- North Carolina State Ports Authority
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. The incident caused a systems‑wide outage that forced gate openings to be delayed and prompted a shift to manual processing while the authority activated its cybersecurity contingency plan and coordinated with state and federal partners including the U.S. Coast Guard. As recovery efforts continue, normal schedules are gradually being restored but residual delays are expected as affected systems and services are brought back online.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 4, 2026, the North Carolina Ports Authority detected a cyberattack on its IT systems affecting the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The authority immediately activated its cybersecurity contingency plan and began recovery efforts the morning of August 5. As a result of a systems‑wide outage, gates at all three facilities were scheduled to open at 8 a.m. on August 5, forcing the agency to shift to manual processing while it worked to contain the intrusion. The Port of Wilmington, which has nine berths and an annual container capacity of 600,000 TEU, normally handles about 5,000 container gate moves per week. Together, the Ports of Wilmington and Morehead City move approximately 4.4 million short tons of bulk and breakbulk cargo each year, serving as key regional logistics hubs. The Charlotte Inland Port functions as an inland hub supporting the same cargo flows.
By the morning of August 5, the authority reported that the breach had been contained and that it was in the recovery process, though it noted that delays could be expected as work to restore affected systems and services continued. On August 6, a notice posted on the ports authority website indicated that a normal operating schedule was in effect while IT teams continued their investigation, but it cautioned that delays might still be experienced. The authority’s latest status update on August 7 stated that gates at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port would follow a normal operating schedule on August 7 and that vessel activity would proceed as scheduled, while acknowledging that delays could still be expected as assessments and restorations continued. The authority did not attribute the attack to a known threat actor and did not disclose whether any sensitive data had been stolen. It also refrained from providing an estimate of how much truck or cargo traffic had been affected by the disruption.
The North Carolina Ports Authority engaged state and federal partners after discovering the attack, including the North Carolina Department of Transportation, the North Carolina Department of Information Technology, and the U.S. Coast Guard, which said it was monitoring the aftermath and coordinating with partner agencies while the investigation proceeded. A Coast Guard spokesperson told CyberScoop that the branch’s IT unit was working with other agencies, and a CISA spokesperson did not respond to requests for comment. While the authority noted that the incident adds to a recent string of cyberattacks against water and wastewater systems in the United States, it emphasized that there had been no public information tying the port cyberattack to a specific actor, and experts’ confidence in Iranian responsibility for the water‑system attacks did not extend to this incident. The authority said it would continue posting updates on its website and directed users to its email alert service for further information.
Sources
Sources available to members: 3 sources.