North Carolina Ports Confirms Cyberattack Slowing Cargo at Wilmington, Morehead City and Charlotte
The state authority activated its cybersecurity contingency plan on August 5 after a system-wide outage forced manual gate operations across all three facilities.

Key points
- The North Carolina State Ports Authority confirmed a cyberattack detected on August 4 that disrupted IT systems at the Port of Wilmington, Port of Morehead City and the Charlotte Inland Port.
- Recovery began on the morning of August 5, with gates at all three sites opening at 8 a.m. under manual procedures.
- The Port of Wilmington handles roughly 5,000 container gate moves per week and has a 600,000 TEU annual container capacity.
- The authority has not attributed the attack to any group and has not said whether data was stolen.
- Normal gate and vessel schedules were set to resume on August 7, though delays are still expected while systems are restored.
Hackers hit the computer systems running North Carolina's main seaports last week, slowing the movement of cargo containers and trucks at three state-run facilities.
The North Carolina State Ports Authority says it detected the intrusion on August 4 and started recovery work the next morning. The outage knocked out IT systems across the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port, an inland freight hub that connects to the two coastal ports.
Gates at all three sites opened at 8 a.m. on August 5 under manual procedures. Truckers faced delays. Vessel activity was also affected.
The incident was first reported by BleepingComputer.
What actually happened?
Someone broke into the ports authority's computer network, and staff pulled systems offline to contain it. That is standard practice during a suspected cyberattack: cut the network so the intruder cannot spread further, then rebuild from clean backups.
The authority activated what it calls its cybersecurity contingency plan, meaning the pre-written playbook for keeping cargo moving when the digital systems that track containers, gate entries and vessel schedules go dark.
A notice on the authority's website said gates and vessel activity would return to a normal operating schedule on August 7, but warned that "delays can be expected" while the IT team continues "assessing affected systems and restoring services."
Why do these three ports matter?
They handle a large share of freight moving in and out of the Carolinas. Wilmington and Morehead City together move 4.4 million short tons of bulk and breakbulk cargo each year, according to the authority. Wilmington alone has nine berths and can process 600,000 TEUs, the standard shipping-industry measure for a 20-foot container, in a year.
When container gates slow down, the effect ripples outward. Trucking companies miss slots. Retailers wait longer for stock. Manufacturers wait for parts.
The Charlotte Inland Port acts as a rail-connected staging yard, letting shippers move containers inland without clogging the coastal terminals. A stall at any of the three creates knock-on delays at the others.
Who did it, and was data stolen?
No one knows yet, at least publicly. The authority has not named a suspect and has not said whether any sensitive information was taken. No ransomware gang has claimed the attack on its leak site.
That silence is not unusual this early. In similar incidents involving US logistics operators, forensic reviews have taken weeks before officials could say with confidence how the attackers got in or what they touched.
What does this mean for people using the ports?
Truckers, freight forwarders and shipping lines should expect intermittent slowdowns at the gates for the next several days and check the authority's status updates before dispatching drivers.
Ordinary consumers are unlikely to see direct impact from a short outage of this kind, though prolonged disruption at a major East Coast port can eventually feed into delivery times for imported goods.
The regulatory angle
US ports fall under the Transportation Security Administration's maritime cybersecurity directives and, for facilities regulated under the Maritime Transportation Security Act, US Coast Guard reporting requirements for reportable cyber incidents. Operators are expected to report significant cyber incidents to the Coast Guard's National Response Center. Whether this incident meets that threshold, and what the authority has filed, has not been disclosed.



