North Carolina Ports said a cyberattack by an outside actor disrupted IT systems and gate operations across the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, forcing the authority to activate its cybersecurity contingency plan and process operations manually. The incident was detected on August 4, with recovery efforts beginning the next morning, and officials said the outage slowed truck traffic and broader port activity while gates remained open under manual procedures.
The North Carolina State Ports Authority said the breach has been contained and that an external forensics team is assisting the investigation and restoration effort. The U.S. Coast Guard and multiple state agencies are monitoring and coordinating the response, while the ports authority has not disclosed the attack's nature, whether data was stolen, or whether ransomware was involved. By Friday, normal gate and vessel schedules had resumed, but delays were still expected as IT teams continued system recovery.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
North Carolina Ports began recovery efforts and brought in an external forensics team while contacting multiple state agencies and the U.S. Coast Guard for support. The breach was described as contained as restoration work got underway.
After discovering the intrusion, North Carolina Ports activated its cybersecurity contingency plan and shifted operations to manual processing to contain the attack. The disruption delayed gate operations across all three facilities.
The North Carolina Ports Authority reportedly detected a cyberattack affecting its IT systems. The incident impacted the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port.
North Carolina Ports said gates at Wilmington, Morehead City, and Charlotte Inland Port would operate on a normal schedule, and vessel activity was also proceeding as scheduled. The authority warned that delays could still occur while IT teams continued assessing and restoring affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcecyberveille.ch
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcewect.com
Open sourcedysruptionhub.com
Open sourcemaritime-executive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.