Full Report
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]
Analysis Summary
# Incident Report: North Carolina Ports Authority Cyberattack
## Executive Summary
On August 4, 2026, the North Carolina Ports Authority detected a cyberattack that caused a widespread IT systems outage across its three major facilities. The incident significantly slowed logistics operations and gate movements at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. While operations are gradually returning to normal through the activation of contingency plans, the full extent of data compromise and the identity of the threat actor remain unconfirmed.
## Incident Details
- **Discovery Date:** August 4, 2026
- **Incident Date:** August 4, 2026 (ongoing recovery through August 7)
- **Affected Organization:** North Carolina Ports Authority
- **Sector:** Critical Infrastructure / Transportation & Logistics
- **Geography:** North Carolina, USA (Wilmington, Morehead City, Charlotte)
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-August 4, 2026 (Specific time undisclosed)
- **Vector:** Undisclosed (Investigation ongoing)
- **Details:** Attackers gained sufficient access to trigger a systems-wide outage by August 4.
### Lateral Movement
- **Details:** Not specifically disclosed; however, the impact reached three geographically separated facilities (Wilmington, Morehead City, and Charlotte), suggesting movement across the enterprise network or centralized management systems.
### Data Exfiltration/Impact
- **Details:** The primary impact was a systems-wide IT outage. The Authority has not yet confirmed if sensitive data was exfiltrated.
### Detection & Response
- **August 4:** Attack detected; cybersecurity contingency plans activated.
- **August 5 (08:00):** Ports forced to delay gate openings; recovery efforts officially began.
- **August 6:** Ongoing restoration of affected systems and services.
- **August 7:** Scheduled return to normal operating hours for gates and vessel activity, though IT restoration continues.
## Attack Methodology
*Note: Due to the early stage of the report, specific TTPs (Tactics, Techniques, and Procedures) have not been fully disclosed by the victim.*
- **Initial Access:** Unknown.
- **Persistence:** Undisclosed.
- **Privilege Escalation:** Undisclosed.
- **Defense Evasion:** Undisclosed.
- **Credential Access:** Undisclosed.
- **Discovery:** Undisclosed.
- **Lateral Movement:** Demonstrated via multi-site impact.
- **Collection:** Undisclosed.
- **Exfiltration:** Under investigation.
- **Impact:** System disruption and availability loss (Denial of Service to operational IT).
## Impact Assessment
- **Financial:** High (indirect); delays in 5,000+ weekly container moves and 4.4 million tons of annual cargo throughput incur significant secondary costs for logistics partners.
- **Data Breach:** Unconfirmed.
- **Operational:** High; complete shutdown of IT systems governing gate operations and vessel activity for approximately 24–48 hours.
- **Reputational:** Moderate; the Authority has been transparent with updates, mitigating some reputational risk through active communication.
## Indicators of Compromise
- **Network indicators:** None disclosed at this time.
- **File indicators:** None disclosed at this time.
- **Behavioral indicators:** Unexpected IT system outages and inability to process gate transactions.
## Response Actions
- **Containment measures:** Activation of cybersecurity contingency plans and isolation of affected systems.
- **Eradication steps:** IT teams are currently assessing systems to remove any remaining threats.
- **Recovery actions:** Gradual restoration of services; phased reopening of gates at 08:00 on August 5 and resumption of vessel activity by August 7.
## Lessons Learned
- **Redundancy is Critical:** The ability to transition to "contingency operations" allowed the ports to resume manual or degraded operations within 24 hours.
- **Regional Hub Sensitivity:** A single point of failure in the port's IT infrastructure can impact the entire regional supply chain, highlighting the need for segmented network architecture between facilities.
## Recommendations
- **Network Segmentation:** Ensure that the IT environments for different port facilities are segmented to prevent a single compromise from causing a total state-wide port outage.
- **Enhance Logging and Monitoring:** Implement behavioral-based detection to identify "living off the land" techniques that often precede major outages.
- **Tabletop Exercises:** Conduct regular drills focusing on manual workarounds for gate and vessel operations when IT systems are unavailable.