North Carolina Ports is recovering from a cyberattack that disrupted operations at the Port of Wilmington, Port of Morehead City and the Charlotte Inland Port.
The organization said it detected the attack on August 4 and immediately activated its Cybersecurity Contingency Plan to contain the incident. As a result, gates at all three facilities opened late on August 5, and officials warned customers and truck drivers to expect operational delays.
North Carolina Ports said the breach has been contained and recovery efforts are underway with support from the North Carolina Department of Transportation, the North Carolina Department of Information Technology and the U.S. Coast Guard.
Denis Calderone, CTO, Suzu Labs:
“We’ve been tracking port cyberattacks over the last few years. Nagoya went down for two days in July 2023. DP World stranded 30,000 containers in Australia for three days in November 2023. The Port of Seattle lost administrative systems for weeks after an attack in August 2024. It’s good to see in this case that NC Ports’ incident preparedness seems to have paid off. They activated their contingency plan the very same night of the attack and were processing manually by the next morning.
“That said, the attack itself is the signal every port operator in the country should be paying attention to. This is the fourth significant port cyberattack globally in three years. Port terminal operating systems, automated gate processing, crane control networks, these are all systems that have been rapidly digitized over the last decade, and attackers have clearly noticed. NC Ports handles 4.4 million tons of cargo annually and supports nearly 90,000 jobs across the state. A longer outage at a facility like that doesn’t just delay trucks, it backs up supply chains across the Southeast and beyond.
“The Coast Guard’s maritime cybersecurity rule went into effect in July 2025, and what we’re seeing in NC Ports’ response maps directly to what that regulation is trying to produce: a designated cybersecurity contingency plan, rapid detection, coordinated response with federal partners. The problem is that most MTSA-regulated port facilities don’t have to submit their full Cybersecurity Plans until July 2027. We’re in the gap period right now, and attacks are not waiting for compliance deadlines.
“For any port operator watching this: the playbook hasn’t changed but the urgency has. Segment your OT networks from your IT environment. Make sure your terminal operating system can’t be reached from the same network segment as your email. Test your manual gate processing procedures with actual crews, not just on paper. Inventory every communication path into your control systems, including the cellular links and the vendor remote access channels. And don’t wait for the 2027 Cybersecurity Plan deadline to do the work. NC Ports has been investing in this kind of preparedness for years and it paid off this week. If your port can’t replicate that response tomorrow, you’re already behind.”
This is going to be more of a thing given the state of play. By that I mean Iran or other cyber threats as it is a safe assupmtion that if you are not under attack now, you will be.
Related
This entry was posted on August 6, 2026 at 4:14 pm and is filed under Commentary with tags Cyberattack. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Cyberattack disrupts operations at North Carolina Ports
North Carolina Ports is recovering from a cyberattack that disrupted operations at the Port of Wilmington, Port of Morehead City and the Charlotte Inland Port.
The organization said it detected the attack on August 4 and immediately activated its Cybersecurity Contingency Plan to contain the incident. As a result, gates at all three facilities opened late on August 5, and officials warned customers and truck drivers to expect operational delays.
North Carolina Ports said the breach has been contained and recovery efforts are underway with support from the North Carolina Department of Transportation, the North Carolina Department of Information Technology and the U.S. Coast Guard.
Denis Calderone, CTO, Suzu Labs:
“We’ve been tracking port cyberattacks over the last few years. Nagoya went down for two days in July 2023. DP World stranded 30,000 containers in Australia for three days in November 2023. The Port of Seattle lost administrative systems for weeks after an attack in August 2024. It’s good to see in this case that NC Ports’ incident preparedness seems to have paid off. They activated their contingency plan the very same night of the attack and were processing manually by the next morning.
“That said, the attack itself is the signal every port operator in the country should be paying attention to. This is the fourth significant port cyberattack globally in three years. Port terminal operating systems, automated gate processing, crane control networks, these are all systems that have been rapidly digitized over the last decade, and attackers have clearly noticed. NC Ports handles 4.4 million tons of cargo annually and supports nearly 90,000 jobs across the state. A longer outage at a facility like that doesn’t just delay trucks, it backs up supply chains across the Southeast and beyond.
“The Coast Guard’s maritime cybersecurity rule went into effect in July 2025, and what we’re seeing in NC Ports’ response maps directly to what that regulation is trying to produce: a designated cybersecurity contingency plan, rapid detection, coordinated response with federal partners. The problem is that most MTSA-regulated port facilities don’t have to submit their full Cybersecurity Plans until July 2027. We’re in the gap period right now, and attacks are not waiting for compliance deadlines.
“For any port operator watching this: the playbook hasn’t changed but the urgency has. Segment your OT networks from your IT environment. Make sure your terminal operating system can’t be reached from the same network segment as your email. Test your manual gate processing procedures with actual crews, not just on paper. Inventory every communication path into your control systems, including the cellular links and the vendor remote access channels. And don’t wait for the 2027 Cybersecurity Plan deadline to do the work. NC Ports has been investing in this kind of preparedness for years and it paid off this week. If your port can’t replicate that response tomorrow, you’re already behind.”
This is going to be more of a thing given the state of play. By that I mean Iran or other cyber threats as it is a safe assupmtion that if you are not under attack now, you will be.
Share this:
Like this:
Related
This entry was posted on August 6, 2026 at 4:14 pm and is filed under Commentary with tags Cyberattack. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.