The breach affected the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port, forcing delays and manual processing at all three North Carolina facilities earlier this week.
U.S. Coast Guard: monitoring and coordinating the response
The U.S. Coast Guard said it is monitoring the aftermath of a cyberattack that disrupted gate operations at North Carolina’s port facilities, but offered few public details as the investigation continues. A Coast Guard spokesperson told CyberScoop that the branch’s IT unit was coordinating with partner agencies while conducting the investigation. The Coast Guard is one of several state and federal partners the North Carolina State Ports Authority brought in after discovering the intrusion.
North Carolina State Ports Authority: contingency plan and manual processing
According to local reporting relayed by CyberScoop, the North Carolina State Ports Authority discovered the attack earlier this week and its IT team activated the agency’s cybersecurity contingency plan upon discovery. The breach forced the authority to delay gate openings and shift to manual processing while it worked to contain the intrusion. The ports authority also reached out to state authorities for further support.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOperational status: normal schedule restored while investigation continues
As of Friday morning, a notice on the ports’ website said a normal operating schedule was in effect while IT teams continued their investigation. The authority has not disclosed the nature of the attack, which specific systems were affected, or whether vessel operations, cargo-handling equipment or rail services were disrupted. The ports authority said it would continue posting updates on its website and pointed users toward its email alert service for further information. It did not provide an estimate of how much truck or cargo traffic was affected by the disruption.
Context: connection to recent attacks on water and wastewater systems
CyberScoop noted the incident adds to a recent string of cyberattacks against water and wastewater systems in the U.S., which—like ports—are considered critical infrastructure. While there has been no official attribution for those water-system incidents, experts have expressed confidence that Iranian actors are responsible for the attacks on water systems. As of Friday morning, there was no public information tying the North Carolina port cyberattack to any specific actor. A spokesperson for CISA did not respond to CyberScoop’s inquiry by press time.
What this means for the North Carolina State Ports Authority, the U.S. Coast Guard, and shippers
- North Carolina State Ports Authority: The authority has activated its cybersecurity contingency plan, shifted to manual gate processing and is continuing an investigation while posting updates to its website and email alert service.
- U.S. Coast Guard: The branch’s IT unit is coordinating with partner agencies as part of the investigation, while the Coast Guard continues to monitor the situation alongside other federal and state partners invited by the ports authority.
- Shippers, truckers and port users: Gate delays and the move to manual processing caused operational disruption earlier in the week; although a normal operating schedule was posted as of Friday morning, the ports authority did not quantify how much cargo or truck traffic was affected.
North Carolina’s ports serve as a regional trade hub, with Wilmington described in reporting as a gateway for agricultural exports, retail goods and raw materials. The immediate public record shows gate operations restored to their regular schedule, but key technical details remain undisclosed publicly as IT teams and federal partners continue their investigation.
Source: https://cyberscoop.com/north-carolina-ports-cyberattack-coast-guard/




