"Gates at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port will follow a normal operating schedule tomorrow, August 7," reads the latest status update from the North Carolina Ports Authority.
North Carolina Ports Authority confirms systems-wide outage after cyberattack
The North Carolina Ports Authority has publicly confirmed a cyberattack that disrupted IT systems and slowed operations across its three facilities: the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The authority said the incident produced a systems-wide outage that forced gates at all three locations to open at 8 a.m. on August 5 and produced delays for port operations and truckers.
Operational impact at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port
The three sites together form the authority’s primary commercial deepwater seaports and an inland hub. The Port of Wilmington is the largest of the three; the authority lists it as having nine berths and a 600,000 TEU annual container capacity and handling an average of 5,000 container gate moves per week. Wilmington and Morehead City together handle 4.4 million short tons of bulk and breakbulk cargo annually, underscoring their importance as regional logistics hubs.
The authority’s public statements say vessel activity will proceed as scheduled and that gates will follow a normal operating schedule beginning August 7, but they caution that delays should still be expected while affected systems and services are restored.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTimeline: detection on August 4 and recovery starting August 5
According to the authority, the attack was detected on August 4. In response, the organization activated its cybersecurity contingency plan and began recovery efforts on the morning of August 5. Those actions coincided with the temporary gates procedure and the initial, visible slowdown of on-dock and gate operations as teams worked to restore systems.
The authority’s status update on August 7 reports that operations are "gradually returning to normal" and that IT teams continue to assess systems and restore services.
Data, attribution, and external outreach
The North Carolina Ports Authority did not attribute the attack to any known threat actor in its public statements and declined to specify whether any sensitive data had been stolen. At the time of writing, no threat groups have publicly assumed responsibility for the incident.
BleepingComputer contacted the North Carolina Ports Authority to request additional details about the incident but had not received a response as of publication.
What this means for truckers, port operators, and regional shippers
- Truckers: Expect continued, intermittent delays. The authority has warned that delays can be expected while IT teams restore affected systems and services, even as gates return to normal hours and vessel activity proceeds.
- Port operators and terminal staff: The contingency plan was activated and recovery began quickly the morning after detection. Operational teams will remain focused on system restoration and coordination with vessel schedules to limit backlog.
- Regional shippers and bulk/breakbulk customers: Given that Wilmington and Morehead City together handle 4.4 million short tons annually, shippers should monitor port notices and prepare for potential schedule shifts or slower gate processing while IT systems come back online.
The North Carolina Ports Authority’s public updates show an incident response sequence that moved from detection (August 4) to contingency activation and recovery (August 5) to a cautious return toward normal operations by August 7. Absent further disclosures from the authority, the key outstanding facts remain whether any sensitive data were exposed and whether investigators can identify a responsible party. The authority’s next public updates and any formal incident report will be the primary source for resolving those questions.
Source: BleepingComputer — North Carolina Ports confirms cyberattack disrupting operations



