The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.
The three facilities are all part of the port, constituting two principal commercial deepwater seaports and an inland hub.
The Port of Wilmington, which is the most significant of the three, has nine berths and a 600,000 TEU annual container capacity, handling an average of 5,000 container gate moves per week.
Wilmington and Morehead together handle 4.4 million short tons of bulk/breakbulk cargo yearly, serving as significant regional logistics hubs.
The attack was reportedly detected on August 4, and the authority responded by activating its cybersecurity contingency plan, beginning recovery on the morning of August 5.
The incident caused a systems-wide outage, forcing gates at all three facilities to open at 8 a.m. on August 5 and delaying port operations and truckers.
The authority did not attribute the attack to a known threat actor and didn’t specify whether any sensitive data had been stolen.
A notification on the port authority's website indicates that operations are gradually returning to normal, but delays should still be expected, as work to restore affected systems and services is ongoing.
“Gates at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port will follow a normal operating schedule tomorrow, August 7,” reads the latest status update.
“Vessel activity will also proceed as scheduled. As our IT team continues assessing affected systems and restoring services, delays can be expected. We appreciate your patience.”
BleepingComputer has contacted the North Carolina Ports Authority to ask for more details about the incident, but we have not received a response as of publication.
At the time of writing, no threat groups have publicly assumed responsibility for the attack.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Get the whitepaper