North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has been hit by a cyberattack that disrupted IT systems and slowed operations at several key facilities. The attack affected the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, all major commercial deepwater seaports and an inland hub.

According to reports, the attack was detected on August 4, prompting the port authority to activate its cybersecurity contingency plan. This allowed recovery efforts to begin on August 5, but operations were severely impacted, with gates at all three facilities forced to open late, causing delays for truckers and disrupting port activities. It’s estimated that over 4.4 million short tons of bulk/breakbulk cargo handled by the Wilmington and Morehead ports each year will be affected.

The exact nature of the attack is unclear, but it appears to have been a targeted strike on the port authority’s IT systems. While no sensitive data has been confirmed stolen, the lack of attribution to a known threat actor raises concerns about the sophistication of the attackers. The situation remains fluid, with ongoing efforts to restore affected systems and services.

The impact of this cyberattack is significant, given the importance of these ports to regional logistics and trade. The Port of Wilmington alone handles over 5,000 container gate moves per week, making it a crucial hub for international commerce. Delays caused by the attack will likely have far-reaching consequences for businesses relying on these ports.

While the port authority has assured that operations are gradually returning to normal, delays should still be expected as work continues to restore affected systems and services. It’s essential for security teams and organizations handling sensitive data to take this incident as a warning sign of the ongoing threat landscape. Regular security audits, vulnerability assessments, and breach simulation tests can help identify weaknesses in IT systems before attackers exploit them.

In light of this attack, it’s crucial for businesses and organizations that rely on critical infrastructure to prioritize cybersecurity and ensure robust protection measures are in place. This includes implementing strong incident response plans, conducting regular security drills, and staying up-to-date with the latest threat intelligence to stay ahead of potential attacks. By doing so, they can minimize the impact of such incidents and prevent disruptions to their operations.


Source: Bleeping Computer — 2026-08-07