North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.

The three facilities are all part of the port, constituting two principal commercial deepwater seaports and an inland hub.

The Port of Wilmington, which is the most significant of the three, has nine berths and a 600,000 TEU annual container capacity, handling an average of 5,000 container gate moves per week.

Wilmington and Morehead together handle 4.4 million short tons of bulk/breakbulk cargo yearly, serving as significant regional logistics hubs.

The attack was reportedly detected on August 4, and the authority responded by activating its cybersecurity contingency plan, beginning recovery on the morning of August 5.

The incident caused a systems-wide outage, forcing gates at all three facilities to open at 8 a.m. on August 5 and delaying port operations and truckers.

The authority did not attribute the attack to a known threat actor and didn’t specify whether any sensitive data had been stolen.

A notification on the port authority’s website indicates that operations are gradually returning to normal, but delays should still be expected, as work to restore affected systems and services is ongoing.

“Gates at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port will follow a normal operating schedule tomorrow, August 7,” reads the latest status update.

“Vessel activity will also proceed as scheduled. As our IT team continues assessing affected systems and restoring services, delays can be expected. We appreciate your patience.”

BleepingComputer has contacted the North Carolina Ports Authority to ask for more details about the incident, but we have not received a response as of publication.

At the time of writing, no threat groups have publicly assumed responsibility for the attack.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

CISA shares advice on isolating vital systems during cyberattacks

CISA warns of cyberattacks disrupting U.S. water utilities

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Coca-Cola says Fairlife ransomware attack halts US dairy production

Hackers run khunt post-exploitation toolkit from Oracle database

Ransom Cartel ransomware creator sentenced to 16 years in prison

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

AI is a data-breach time bomb: Read the new report

Webinar: Shadow AI in 2026 (and how attackers are taking advantage)

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Spend four hours inside a fully-simulated underground with DARKROOM.

See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.