North Carolina Ports Confirms Cyberattack Slowing Cargo at Wilmington, Morehead City and Charlotte
The state authority activated its cybersecurity contingency plan on August 5 after a system-wide outage forced manual gate operations across all three facilities.

Key points
- The North Carolina State Ports Authority confirmed a cyberattack detected on August 4 that disrupted IT systems at the Port of Wilmington, Port of Morehead City and the Charlotte Inland Port.
- Recovery began on the morning of August 5, with gates at all three sites opening at 8 a.m. Under manual procedures.
- Wilmington alone has nine berths and a 600,000 TEU annual container capacity, handling around 5,000 container gate moves a week.
- The authority hasn't attributed the attack to any group and hasn't said whether data was stolen.
- Normal gate and vessel schedules were set to resume on August 7, though delays are still expected while systems are restored.
Hackers hit the computer systems running North Carolina's main seaports last week, slowing cargo containers and trucks at three state-run facilities.
The North Carolina State Ports Authority detected the intrusion on August 4 and started recovery work the next morning. Its IT systems went down across the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port, an inland freight hub connecting to the two coastal sites. Gates at all three opened at 8 a.m. On August 5 under manual procedures. Truckers faced delays. Vessel activity was also affected.
The incident was first reported by BleepingComputer.
What actually happened?
Staff pulled systems offline to contain the intrusion. That's standard practice: cut the network so the attacker can't spread, then rebuild from clean backups.
The authority activated what it calls its cybersecurity contingency plan, the pre-written playbook for keeping cargo moving when digital systems tracking container gate entries and vessel schedules go dark.
A notice on the authority's website said gates and vessel activity would return to a normal operating schedule on August 7, but warned that "delays can be expected" while the IT team continues "assessing affected systems and restoring services."
Why do these three ports matter?
They handle a large share of freight moving in and out of the Carolinas. Wilmington and Morehead City together move 4.4 million short tons of bulk and breakbulk cargo each year. Wilmington alone has nine berths and a 600,000 TEU annual container capacity, TEU being the shipping industry's standard unit for a single container slot.
When container gates slow, the effect ripples outward. Retailers wait longer for stock. Manufacturers wait for parts.
The Charlotte Inland Port acts as a rail-connected staging yard, letting shippers move containers inland without clogging the coastal terminals. A stall at any one of the three creates knock-on delays at the others.
Who did it, and was data stolen?
No one knows yet, at least publicly. The authority hasn't named a suspect and hasn't said whether sensitive information was taken. No ransomware gang has claimed the attack on its leak site.
That silence isn't unusual this early. In similar incidents involving US logistics operators, forensic reviews have taken weeks before officials could say with confidence how attackers got in or what they touched.
What does this mean for people using the ports?
Fright forwarders and shipping lines should check the authority's status updates before dispatching drivers and expect intermittent gate slowdowns for the next several days. Ordinary consumers are unlikely to see direct impact from a short outage, though prolonged disruption at a major East Coast port can eventually feed into delivery times for imported goods.
The regulatory angle
US ports fall under the Transportation Security Administration's maritime cybersecurity directives and, for facilities regulated under the Maritime Transportation Security Act, Coast Guard reporting requirements for significant cyber incidents. Operators are expected to report to the Coast Guard's National Response Center. Whether this incident meets that threshold, and what the authority has filed, hasn't been disclosed.
This is a pattern worth watching. Critical infrastructure with physical chokepoints, ports, water utilities, mobile networks, keeps appearing in incident reports this summer. Our August 4 look at a decade of Iranian cyberattacks on American infrastructure showed how attackers probe exactly these kinds of nodes. Nobody has linked this incident to that activity, but the timing and target type are consistent with a broader season of disruption.



