Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate
North Carolina Ports is in the process of restoring its systems after a cybersecurity incident forced a shift to manual operations on Tuesday.
A spokesperson for the ports, which handle more than 4 million tons of cargo each year, said the IT system was “hacked by an outside actor or group” requiring them to enact a contingency plan and contact multiple state agencies as well as the U.S. Coast Guard.
“The breach has been contained, and we are now in the recovery process,” the spokesperson told Recorded Future News, adding that the incident affected all three North Carolina Ports locations of Wilmington, Morehead City and Charlotte.
The facilities are “following a normal operating schedule today,” he said, “however, operations are still being processed manually.”
An outside forensics team is working with the IT department to assess and restore affected systems. The spokesperson did not respond to questions about whether it is dealing with a ransomware attack.
A notice on the North Carolina Ports website says the gates at all three ports will operate normally on Thursday but delays should be expected.
Local news outlets reported that since Tuesday, there were signs outside of port gates warning companies of delays “due to system issues."
No hacking group has come forward to take credit for the attack. Ports in the U.S., Europe and Asia have been repeatedly targeted by ransomware gangs over the last five years as many shift to incorporate digital operations. In 2024, the Port of Seattle refused to pay a ransom to cybercriminals that caused issues at the city’s airport and seaport ahead of the Labor Day holiday.
On Wednesday, Senator Tom Cotton (R-Ark.) sent a letter to Treasury Secretary Scott Bessent asking him to encourage investment in and modernization of American operational technology.
“This technology is underfunded and outdated, leaving vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural states like Arkansas, vulnerable to cyberattacks by our adversaries,” Cotton wrote.
“Attacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target.”
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



