Cyber Incident Victim: North Carolina Ports Authority
Timeline
Summary
The North Carolina Ports Authority reported a cyberattack that disrupted gate operations at its three facilities, forcing a shift to manual processing and delayed openings while the IT team activated its contingency plan. The breach was contained and recovery efforts were underway, though the authority did not disclose the specific systems affected or whether vessel movements, cargo handling, or rail services were impacted. No public attribution has been made, and the Coast Guard is monitoring the incident while coordinating with state and federal partners. The ports, which handle significant bulk and container traffic for the southeastern United States, continued to post updates and encouraged users to subscribe to email alerts for further information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Tuesday, August 4, 2026, the North Carolina State Ports Authority detected a cyberattack on its IT system, as reported to local media. The authority immediately activated its Cybersecurity Contingency Plan and began working to contain the intrusion. By Wednesday morning, August 5, the breach had been contained and the authority noted it was entering the recovery process. A notice posted on the ports’ website announced that, due to a systems‑wide outage, gates at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port would open at 8 a.m. on August 5, with delays expected.

The cyberattack forced the agency to delay gate openings and shift to manual processing while it worked to contain the intrusion, affecting all three port facilities: the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. As of Friday morning, August 7, the ports website indicated a normal operating schedule was in effect while IT teams continued their investigation. The authority did not disclose the nature of the attack, which specific systems were affected, or whether vessel operations, cargo‑handling equipment, or rail services were disrupted. No estimate was provided for the amount of truck or cargo traffic impacted by the disruption.
In response to the incident, the ports authority engaged state and federal partners, including the North Carolina Department of Transportation, the North Carolina Department of Information Technology, and the U.S. Coast Guard, which said it was monitoring the aftermath of the attack. The Coast Guard’s IT unit coordinated with partner agencies while the investigation continued, and CISA was contacted but did not respond to inquiries. The authority stated it would continue posting updates on its website and directed users to its email alert service for further information. As of Friday morning, there had been no public information tying the port cyberattack to a specific actor, although the article noted that experts have expressed confidence that Iranian actors are responsible for a recent string of cyberattacks against water and wastewater systems in the United States.
