Cyberattack hits North Carolina ports, raising supply chain risks
Attackers don’t need to steal data to cause widespread economic disruption.

Port of Wilmington, North Carolina. Image by Frame Craft 8 | Shutterstock
- A cyberattack disrupted IT systems at North Carolina’s three port facilities, delaying gates and forcing manual cargo processing.
- Officials brought in outside forensic experts; they have not disclosed the attackers, access method, ransomware, or data theft.
- Experts warn port cyberattacks can disrupt supply chains because ports support millions of tons of cargo and key industries.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
North Carolina State Ports Authority is still recovering after a cyberattack disrupted IT systems across its three port facilities last week, forcing manual operations and delaying cargo processing.
An “operations alert” warning that a “systems-wide outage” would delay gate openings at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port was first posted on the North Carolina Ports website on August 4th.
The ports, which immediately launched an incident response plan, said terminal operations and vessel activity continued as scheduled, although some cargo processing was shifted to manual operations.
“In keeping with our Cybersecurity Contingency Plan, an outside forensics team is actively working alongside our IT department to assess and restore affected systems as safely and as quickly as possible,” a Ports Authority spokesperson told local news outlet WNCT 9.
Besides stating that the IT systems were hacked by an outside group, the spokesperson did not reveal how the threat actor gained access, which systems were compromised, whether ransomware was involved, or if any data was exfiltrated from its systems.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The incident did not affect maritime safety, a spokesperson for the US Coast Guard told CyberScoop over the weekend, adding that it was monitoring the situation and coordinating with state authorities and other federal partners.
Cybernews has reached out to the North Carolina State Ports Authority for clarification.
Ports keep cargo moving, but risks still remain
For critical infrastructure operators, resilience increasingly depends on keeping physical operations running even when the digital systems behind essential services come under attack, said Michael Centrella, Head of Public Policy at SecurityScorecard.
"Ports are critical hubs for commerce and supply chains, meaning an attack can create downstream impacts for businesses, logistics providers, and communities that depend on the movement of goods,"Centrella told Cybernews.
North Carolina Ports officials said normal gate schedules had resumed by the end of the week, although it remains unclear whether the attack impacted shipments or cargo tracking, or resulted in any broader supply chain backups across the US.
The North Carolina port system handles more than 4 million tons of general cargo annually and about 1,000 ship calls each year, supporting agriculture, forestry, construction, and infrastructure across the state.
The system encompasses two deep-water ports in Wilmington and Morehead City, along with the Charlotte Inland Port, connecting cargo to major highway and rail networks across the Southeast and Midwest.
“Disrupting availability, creating operational uncertainty, or slowing essential services can be enough to create widespread economic consequences,” Centrella said.
Cyberattack reaches beyond the ports
Warnings from the Department of Homeland Security about threats to the maritime industry have increased in recent years, as fallout from a major port attack can ripple through the wider supply chain.
The Port of Morehead City is also a breakbulk and bulk facility and is one of the deepest on the US East Coast, while the Port of Wilmington alone handles the equivalent of roughly 320,000 twenty-foot shipping containers and sits within 700 miles of more than 70% of the US industrial base.
What’s more, the North Carolina attack comes just weeks after another major US maritime organization was targeted by hackers.
In June, the Qilin ransomware gang claimed to have breached the Shipping Association of New York & New Jersey (SANYNJ), which represents terminal operators, ocean carriers, stevedores, and other businesses responsible for moving cargo through one of North America’s busiest ports.
At the time, Qilin claimed to have stolen and published data from the organization, although Cybernews was unable to independently verify the extent of the alleged breach.
Still, Centrella, who spent more than 25 years with the US Secret Service and served as an Assistant Director, said attackers don’t necessarily have to steal sensitive information to cause significant damage.
“Modern ports depend on a complex ecosystem of systems, technology providers, and partners to manage everything from logistics to daily operations," he said.
“A single weakness in a connected system, third-party provider, or external-facing asset can create an opportunity for attackers to impact critical operations,” Centrella said.
Check if your data has been leaked