Skip to content

Cyberattack disrupts North Carolina Ports operations

Summary

North Carolina State Ports Authority logo

A cyberattack disrupted systems and delayed gate operations at North Carolina Ports facilities in Wilmington, Morehead City and Charlotte beginning August 4, 2026. Normal gate schedules returned August 6, and by August 18 the authority’s ordinary customer tools and operating pages were available without a continuing delay warning, supporting presumed resolution. NC Ports has not published a technical all-clear or confirmed ransomware, data compromise or attribution.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Degraded service

    Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Transportation operations disrupted

    Transit, aviation, rail, maritime, logistics, fleet, traffic, ticketing, or related transportation operations were materially affected.

  • Delayed opening or early closure

    The organization delayed opening, closed early, or reduced operating hours because of the incident.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that an outside actor breached the North Carolina State Ports Authority’s information technology environment August 4, 2026. WECT reported that an NC Ports spokesperson confirmed the incident, said the authority activated its Cybersecurity Contingency Plan and engaged state agencies and the U.S. Coast Guard. The spokesperson said the breach was contained and recovery was underway.

The evidence establishes malicious unauthorized access and a cyber-caused availability impact but does not identify the initial access vector, malware family, persistence mechanism or specific affected systems. Officials have not named the outside actor, and the public record does not support confirmed ransomware or extortion.

Operational significance

NC Ports’ operations alert documented a systems-wide outage that delayed gate openings at the Port of Wilmington, Port of Morehead City and Charlotte Inland Port. Wilmington shifted to manual gate processing, allowing cargo movement to continue while the IT team restored services. The public record does not establish interruption to cranes, vessel movement, industrial-control systems or other operational technology.

Normal gate schedules returned August 6, although the authority still warned customers to expect delays while affected systems were assessed and restored. This sequence documents substantial recovery followed by the end of publicly reported operational impact.

Disclosure posture

NC Ports’ operational alerts described a systems issue and systems-wide outage without naming a cyber cause. The authority separately confirmed the cyber incident through its spokesperson to WECT. The affected organization therefore supplied both the cyber characterization and direct documentation of disruption, although through different communication channels.

Current status

The material disruption is presumed resolved. By August 18, the NC Ports homepage, customer portal, current-conditions page and routine cargo tools were available, and the systems-issue alert and continuing-delay warning were no longer displayed. No newer source documented continuing gate delays or manual processing.

The authority has not published an incident-specific technical all-clear or final recovery date. The status therefore reflects the end of documented operational impact rather than a conclusion that every technical or investigative task is complete.

Confidence and uncertainty

Confidence is high that malicious cyber activity materially disrupted port operations because the authority’s spokesperson confirmed the breach and NC Ports’ alerts documented the systems outage, delayed openings and continuing recovery. Confidence is high that Wilmington used manual gate processing; the public record does not establish that Morehead City and Charlotte used identical workarounds.

Operational data was unavailable while systems were down, but confidentiality remains unresolved. The spokesperson said there was no indication sensitive information was compromised, and no public source identifies data access or removal. No stable claim of responsibility, ransom demand or other extortion indicator has emerged.

Analytic gaps

The public record does not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time, malware family, persistence, affected applications, data-access scope, exfiltration, encryption, ransom demand, restoration method or technical recovery date. It also does not explain which IT dependencies caused the gate delays and manual processing or whether any operational-technology or port-security systems were isolated.

Organizations involved

Impacted locations

Sources

Cyberattack delays North Carolina Ports operations statewide

The report documented a cyberattack against all three North Carolina Ports facilities, delayed gates, manual truck processing in Wilmington, containment and continuing recovery work. It also stated that no responsible actor, ransomware, ransom demand, sensitive-data compromise or operational-technology impact had been established.

Cyberattack disrupts operations at NC Ports in Wilmington, Morehead City and Charlotte

WECT quoted an NC Ports spokesperson confirming the August 4 cyberattack, activation of the authority’s Cybersecurity Contingency Plan, engagement with NCDOT, NCDIT and the U.S. Coast Guard, containment, continuing recovery and manual gate processing in Wilmington. No full-restoration timeline or sensitive-data compromise was identified.

Operations Alert: Systems Issue Update

By August 18, the NC Ports homepage and ordinary customer and operating-information pages were available without the prior systems-issue alert or a continuing delay warning. The authority had not posted an incident-specific technical all-clear.

See something that needs correction?

Signed-in members can report an error, update, or missing source.