Cyberattack forces North Carolina Ports onto manual operations
A cyberattack detected on 4 August 2026 disrupted IT systems at the North Carolina State Ports Authority, forcing manual gate processing at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port.
- Victim
- North Carolina State Ports Authority
On 5 August 2026, the North Carolina State Ports Authority disclosed that a cyberattack detected the previous day had disrupted its IT systems and slowed operations at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. The authority activated its cybersecurity contingency plan and began recovery on the morning of 5 August.
The systems-wide outage forced crews to switch to manual gate processing at all three facilities, delaying the trucking companies and shippers that depend on them. Gates opened at 8 a.m. on 5 August, and by 7 August normal schedules had resumed, although the authority warned that delays could continue while systems were restored. The U.S. Coast Guard said it was monitoring the incident.
What is known
The ports authority did not name a threat actor, did not describe the type of attack and said it had found no evidence that sensitive data had been compromised. No ransomware or extortion group publicly claimed the incident in initial reporting. The Port of Wilmington alone has a container capacity of about 600,000 TEU a year, and the two seaports together handle roughly 4.4 million short tons of bulk and breakbulk cargo annually.
Why it matters
Ports are critical links in national supply chains, and even a short IT outage at gate and terminal systems ripples out to trucking, rail and shipping customers. The incident adds to a series of attacks on maritime and logistics operators and shows the value of rehearsed manual fallback procedures that let cargo keep moving while systems are rebuilt.
Timeline
The North Carolina State Ports Authority detects a cyberattack and activates its cybersecurity contingency plan.
After a systems-wide outage, gates at all three facilities open at 8 a.m. with manual processing as recovery begins.
Normal operating schedules resume, though the authority warns of delays while IT restoration continues.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberattack-disrupting-operations/
- wect.comhttps://www.wect.com/2026/08/05/cyberattack-disrupts-operations-nc-ports-wilmington-morehead-city-charlotte/
- wect.comhttps://www.wect.com/2026/08/06/nc-ports-operating-manually-after-cyberattack-disrupts-statewide-systems/
- cyberscoop.comhttps://cyberscoop.com/north-carolina-ports-cyberattack-coast-guard/