North Carolina Ports has confirmed that it is in the process of restoring its IT systems following a cyberattack that forced a shift to manual operations across all three of its locations. The incident, which began on Tuesday, August 4, 2026, affected facilities in Wilmington, Morehead City, and Charlotte.
A spokesperson for North Carolina Ports stated that an "outside actor or group" had "hacked" their IT system. In response, the organization activated its contingency plan and engaged with multiple state agencies and the U.S. Coast Guard. The breach has reportedly been contained, and recovery efforts are underway.
Despite the system issues, all three port locations maintained a normal operating schedule as of Thursday, August 6, 2026, though operations were being processed manually. Signs posted at port gates since Tuesday had warned companies of potential delays. An external forensics team is collaborating with the internal IT department to assess the damage and restore affected systems. The ports handle over 4 million tons of cargo annually.
North Carolina Ports has not disclosed whether the incident was a ransomware attack, nor has any hacking group publicly claimed responsibility.
The attack comes amid a broader trend of cyber incidents targeting critical infrastructure. Ports in various regions, including the U.S., Europe, and Asia, have been frequent targets for ransomware groups in recent years as they increasingly adopt digital operational technologies. For instance, in 2024, the Port of Seattle experienced a cyberattack that disrupted operations at its airport and seaport, though it refused to pay a ransom.
In response to such incidents, Senator Tom Cotton (R-Ark.) penned a letter on Wednesday, August 5, 2026, to Treasury Secretary Scott Bessent. Cotton urged increased investment in and modernization of American operational technology, highlighting the vulnerability of vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural areas, to cyberattacks. He emphasized that attacks on civilian infrastructure have become a common tactic in modern warfare, with American operational technology being a prime target.






