A cyberattack against the North Carolina Ports Authority disrupted IT systems and slowed container operations at three facilities — Wilmington, Morehead City and the Charlotte Inland Port — after the intrusion was detected on August 4. Wilmington, which handles roughly 600,000 TEU of annual container capacity and processes about 5,000 container gate moves a week, saw gate operations delayed by a systems-wide outage.
Port authorities activated their contingency plan and began recovery efforts the day after detection, while the U.S. Coast Guard monitored the investigation given ports' status as critical infrastructure. Officials have not publicly detailed the nature of the intrusion, whether data was stolen, or which threat actor, if any, has claimed responsibility.
The incident adds to a string of cyberattacks against U.S. logistics and transportation infrastructure over the past year, which security researchers say increasingly target the software systems that coordinate freight movement rather than more heavily defended financial or government networks. Port operators nationwide have faced pressure to modernize aging IT systems that in some cases predate modern cybersecurity practices.