All three facilities operated by the North Carolina Ports Authority were knocked offline by a cyberattack on August 4, 2026, forcing a shift to manual operations across the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The U.S. Coast Guard has confirmed it is actively monitoring the incident and coordinating with partner agencies.
Operational Impact
The attack triggered a systems-wide outage that eliminated electronic gate processing at all three locations. Immediate effects included:
- Manual gate processing activated at all facilities
- Delayed opening at the Port of Wilmington, which handles approximately 5,000 container gate moves per week across 9 berths and ~600,000 TEUs annually
- Combined disruption across ports that collectively handle 4.4 million short tons of bulk and breakbulk cargo annually and receive approximately 1,000 ship calls per year
Normal gate schedules partially resumed on August 6, but manual processing remained in effect during the investigation and system restoration period.
Incident Response
The NC Ports Authority activated its Cybersecurity Contingency Plan immediately upon detecting the intrusion. Response actions included:
- Engagement of an outside forensics team alongside the internal IT department
- Notification of partner agencies: NC Department of Transportation, NC Department of Information Technology, and the U.S. Coast Guard
- Declaration that the breach was "contained" by August 5–6, with no confirmed sensitive data compromise or OT (operational technology) system impact announced
The U.S. Coast Guard confirmed through its IT unit that it is monitoring the aftermath and coordinating with port and state authorities.
Attribution and Attack Type
No ransomware group had claimed responsibility as of the latest available reporting. The NC Ports Authority declined to confirm or deny ransomware involvement. The absence of announced data exfiltration and the relatively rapid containment timeline are consistent with either a ransomware attack stopped before data staging or a disruptive malware deployment without exfiltration goals — but neither has been officially confirmed.
The investigation remains ongoing with no threat actor identified.
Regulatory Context
The timing is notable: U.S. Coast Guard maritime cybersecurity rules took effect in July 2025, requiring covered ports, vessels, and facilities to develop cybersecurity plans, designate responsible officers, and establish detection, response, and recovery procedures. The North Carolina ports attack is among the first major incidents to test those post-rule frameworks in a real-world operational environment.
The Coast Guard's active monitoring role reflects both those new regulatory responsibilities and the broader federal interest in protecting maritime critical infrastructure — a sector that handles the movement of goods essential to supply chains across the eastern seaboard.
What to Watch
- Forensics findings: The outside forensics engagement will determine attack vector, dwell time, and whether any data was staged for exfiltration
- Threat actor identification: No group has claimed credit; attribution may emerge from threat intelligence analysis of TTPs observed during the investigation
- Coast Guard regulatory response: How the USCG applies its new 2025 cyber rules to this incident may set precedent for enforcement posture going forward
- Restoration timeline: Full restoration of electronic gate systems has not been announced; manual processing represents a significant throughput reduction at high-volume port facilities