A cyberattack disrupted operations Tuesday at all three North Carolina Ports facilities, causing delays and forcing the Port of Wilmington to process trucks through its gates manually.
The affected sites are deepwater ports in Wilmington and Morehead City and an inland terminal in Charlotte. They connect maritime cargo operations with manufacturing and distribution networks across the state. A 2018 study commissioned by the authority estimated that port activity directly and indirectly supported more than 87,700 jobs statewide.
North Carolina Ports said an outside actor or group breached its information technology system late Tuesday. The authority activated its cybersecurity contingency plan and contacted the North Carolina departments of Transportation and Information Technology and the U.S. Coast Guard.
Signs outside port gates Wednesday warned truck drivers to expect delays because of system issues. An alert on the authority’s website described an outage affecting all three facilities and said gates in Wilmington, Morehead City and Charlotte would open at 8 a.m. Wednesday.

The Wilmington terminal opened late and shifted to manual gate processing while the authority worked to restore its systems, a North Carolina Ports spokesperson told WECT. The authority said it had contained the intrusion and begun recovery work but did not provide a timeline for full restoration.
The authority has not identified which systems were breached or taken offline, leaving unclear which failures led to the gate delays and manual processing.
North Carolina Ports has not reported any impact to operational technology, such as cranes, industrial control systems or vessel-movement systems. Federal agencies recently warned that Iranian-affiliated actors were targeting internet-connected programmable logic controllers, but no public evidence links the port attack to that campaign.
Officials have not said whether ransomware was involved. The authority said there was no indication that sensitive information was compromised and has not reported a ransom demand. At the time of publication, DysruptionHub had found no public claim of responsibility.
The disruption has operational similarities to an August 2024 cyberattack on the Port of Seattle, where officials isolated critical systems and airport employees used manual baggage and passenger-processing procedures. Seattle later said the Rhysida ransomware group encrypted systems, obtained data and demanded a ransom. The port declined to pay. No public evidence connects the two incidents.
The delayed-gate alert remained on the authority’s website Wednesday afternoon, and officials had not announced when normal computer and gate operations would resume.