Thu 06 Aug 2026 / 17:29 ET
Kernel
Security 3 min read

North Carolina Ports cyberattack contained, recovery continues

North Carolina Ports says an Aug. 4 IT-system breach affected three facilities, causing gate delays as recovery work continues.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

North Carolina Ports cyberattack contained, recovery continues
img: The Record

The North Carolina Ports cyberattack disrupted operations at facilities in Wilmington, Morehead City and Charlotte after an outside actor or group breached the authority’s IT system late Tuesday, Aug. 4, according to North Carolina Ports. The authority says it has contained the breach, but affected systems remain in recovery and it has not given a timetable for full restoration.

The incident affected the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. North Carolina Ports activated its Cybersecurity Contingency Plan and engaged the state departments of Transportation and Information Technology, as well as the U.S. Coast Guard, according to local reports citing the authority.

That means those agencies were brought into the response. The available reports do not establish what investigative work they performed or any conclusions they reached.

What did the North Carolina Ports cyberattack disrupt?

North Carolina Ports reported a system-wide outage and warned that gates at all three sites would open at 8 a.m. on Wednesday, Aug. 5, with delays expected. In Wilmington, the port had a delayed opening and moved to manual gate processing while recovery work proceeded, WECT reported.

The authority later said facilities were following a normal operating schedule, though operations were still being processed manually, Recorded Future News reported. A notice cited by that outlet said all three ports’ gates would operate normally Thursday, while warning of delays.

One same-day report from Queen City News said operations had returned to normal Wednesday. That is best read as a snapshot of changing conditions, not proof that every affected IT system had been restored: the authority did not provide a full-restoration deadline, and other reporting from the same period described ongoing recovery and manual processing.

What remains unknown?

The authority has not identified the intruder or group it says accessed its IT system. It also has not publicly specified which systems were breached or taken offline, according to DysruptionHub.

There is no confirmed indication that ransomware was involved. A North Carolina Ports spokesperson did not answer a question about ransomware posed by Recorded Future News, and the authority had not reported a ransom demand or public claim of responsibility.

The status of sensitive data is also unresolved. WECT reported that a spokesperson said there was no indication at the time that sensitive data had been compromised. Other contemporaneous reports described that question as unknown. None of the reporting establishes that data was taken.

An outside forensics team is working with the authority’s IT department to assess and restore affected systems, Recorded Future News reported. The public record so far identifies an IT-system compromise and operational disruption, not the entry method, the attacker or the full scope of the incident.

This story draws on original reporting from The Record.

More Security/

view all ↗