North Carolina Ports, the state authority operating two deepwater seaports and an inland intermodal terminal, has confirmed that its IT environment was "hacked by an outside actor or group" late on Tuesday, August 4, 2026, forcing a shift to manual operations across all three of its facilities. A ports spokesperson told Recorded Future News that "the breach has been contained, and we are now in the recovery process," with an outside forensics team working alongside the internal IT department. The incident affected the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. The U.S. Coast Guard, the North Carolina Department of Transportation and the North Carolina Department of Information Technology have all been engaged. As of Thursday, August 6, gates at all three facilities were operating on a normal schedule, but cargo was still being processed by hand and delays were still expected. No threat group has claimed the attack, and the authority declined to say whether ransomware was involved.
What Happened
The timeline across sources is consistent. The authority detected the intrusion late on Tuesday, August 4, and its IT team immediately activated a pre-existing Cybersecurity Contingency Plan, according to IndexBox's account of the authority's statements to local media. By Wednesday morning, August 5, the breach was described as contained and recovery was underway.
The first public signal was operational rather than security-branded. Port Technology International reported on August 5 that NC Ports had posted a systems-wide outage notice on its website, announcing that gates at Wilmington, Morehead City and Charlotte would open at 08:00 that day and warning customers and truck drivers to expect delays. At the time of that report the authority had not disclosed the cause, identified the affected systems, or given a restoration timetable. The Record noted that local outlets observed physical signs posted outside port gates from Tuesday onward warning of delays "due to system issues."
The attribution to a cyberattack came the following day. WXII and other regional outlets carried the authority's confirmation that the hack hit all three locations. The Record obtained the fullest on-record statement, including the spokesperson's confirmation that facilities were "following a normal operating schedule today, however, operations are still being processed manually," and that an external forensics firm had been retained.
Several material questions remain open. Port Technology noted the authority did not state whether vessel operations, cargo handling equipment or rail services were affected, and no source has confirmed whether the intrusion touched operational technology or was confined to enterprise IT. The shift to manual gate processing is consistent with either scenario, since disconnecting IT systems that feed terminal operating software produces the same visible symptom as an OT compromise.
What Was Taken
Nothing. As of publication, no source confirms any data theft, and defenders should not assume otherwise in either direction.
IndexBox, summarizing local reporting, states plainly that "it remains unclear whether any sensitive data was compromised during the incident." Undercode News frames the event as one where "no data breach is immediately confirmed." The Record reports that the spokesperson did not respond to questions about whether this was a ransomware attack, and that no hacking group has come forward to take credit. That combination, containment declared within roughly 12 hours and no leak-site posting, is more consistent with an intrusion caught during or shortly after initial access than with a completed double-extortion operation, but that is an inference, not a finding.
Cargo volume figures cited in coverage differ and are worth stating precisely, because they are being used as a proxy for the incident's scale. The Record describes the ports as handling "more than 4 million tons of cargo each year." NC Ports' own FY26 results release, published July 28, 2026, states that Wilmington and Morehead City together moved 4.4 million short tons of bulk and breakbulk cargo, a figure IndexBox repeats. The 4.4 million figure is the authority's own and covers bulk and breakbulk only, excluding containerized traffic; the 4 million figure appears to be a rounded restatement of the same underlying number rather than a competing measurement. On container throughput, Port Technology and IndexBox agree that Wilmington's container terminal has an annual capacity of 600,000 TEU and is served by seven ship-to-shore cranes, with IndexBox adding that the port typically handles more than 5,000 container gate moves per week.
Why It Matters
This is a state-owned critical infrastructure operator in the Maritime Transportation Security Act regime, which is why the Coast Guard appears in the response alongside state agencies rather than as an afterthought. Coast Guard involvement in a U.S. port cyber incident is not discretionary press-release language; it reflects the sector's regulatory reporting structure via the National Response Center and the Captain of the Port.
The economic exposure is regional and concentrated. NC Ports has publicly positioned itself, in its 2031 Strategic Plan, as the "default gateway" for bulk materials serving North Carolina, including agriculture, forestry products and building materials. Its FY26 release cites breakbulk and project cargo wins supporting state energy infrastructure, including transformers, chillers, industrial battery packs and windmill blades. Wilmington also carries heavy reefer volumes supporting agriculture, which is the least delay-tolerant cargo category in the portfolio. An outage that degrades gate throughput during harvest season imposes spoilage risk that a container terminal outage does not.
The strategic pattern is well established. The Record notes that ports across the U.S., Europe and Asia have been repeatedly hit by ransomware crews over the past five years as terminals digitize, citing the 2024 Port of Seattle incident in which the port refused to pay a ransom and absorbed disruption to both its seaport and airport ahead of Labor Day weekend. Undercode News makes the same structural argument, that ports are now "complex digital ecosystems" where operational disruption alone, absent any data loss, produces financial and supply chain consequences.
The policy backdrop moved in parallel. The Record reports that on Wednesday, August 5, Senator Tom Cotton (R-Ark.) wrote to Treasury Secretary Scott Bessent urging investment in and modernization of American operational technology, describing that technology as underfunded and outdated. The timing is coincidental rather than causal, but it indicates where legislative attention is heading.
The Attack Technique
The initial access vector is not known. No source identifies a CVE, a malware family, an initial access broker or a named threat group, and any claim to the contrary at this stage should be treated as speculation.
What the sources do establish is the defender's response pattern: rapid isolation of affected systems, activation of a written contingency plan, fallback to manual processing to preserve throughput, and engagement of external forensics. Undercode News describes this correctly as standard practice, since disconnecting compromised systems limits attacker lateral movement while manual procedures keep cargo moving, at the cost of significant efficiency loss across cargo tracking, scheduling, gate access, inventory management and partner communications.
Two other incidents in the source set are worth flagging as adjacent context, not as attribution. BleepingComputer reported on June 22, 2026 that SOCRadar had documented the "FortiBleed" campaign, in which an initial access broker targeted more than 430,000 FortiGate firewalls worldwide beginning no later than February 2026, using credential stuffing, brute force, credential harvesting and offline cracking, and deploying a Golang implant dubbed "FortigateSniffer" that abuses FortiOS's built-in diagnose sniffer packet feature to capture RADIUS, NTLM, Kerberos and LDAP authentication traffic across 24 protocols. Fortinet characterized the exposure as a collection of previously compromised credentials rather than a new vulnerability; SOCRadar's data indicated an ongoing, active compromise campaign. Separately, WataugaOnline reported that Chick-fil-A notified customers of a credential stuffing attack against its web and mobile applications between June 17 and 19, 2026, using credentials sourced from a third party. There is no evidence linking either campaign to NC Ports. They are included because both illustrate the access class most likely to be relevant here: valid credentials on internet-facing edge infrastructure, obtained elsewhere and reused.
What Organizations Should Do
-
Audit edge device credentials and configuration integrity. Given the scale of the FortiBleed campaign, treat every internet-facing VPN and firewall credential as potentially exposed. Rotate local admin and service accounts on FortiGate and equivalent appliances, verify that packet capture and diagnostic features are not running unexpectedly, and review configuration change logs for unauthorized modifications.
-
Enforce phishing-resistant MFA on all remote access. Both the FortiBleed and Chick-fil-A incidents in this source set turned on reused or stolen passwords. Password-only or SMS-backed remote access on a port, terminal or logistics network should be treated as an open door.
-
Write and rehearse the manual fallback, not just the incident response plan. NC Ports' ability to keep gates open on manual processing within 24 hours is the single clearest success in this incident, and it reflects a pre-existing contingency plan. Define which physical operations must continue without IT, document the paper procedures, and exercise them with the operations staff who would actually run them.
-
Segment enterprise IT from terminal operating and OT networks. The unanswered question in this incident is whether the intrusion could have reached cargo handling systems. Enforce hard boundaries between corporate IT, terminal operating systems and industrial control networks, with brokered, monitored, one-way access where connectivity is genuinely required.
-
Pre-establish regulator and partner notification paths. NC Ports had working channels to the Coast Guard, NCDOT and NCDIT on day one. MTSA-regulated facilities should confirm their Facility Security Officer contacts, National Response Center reporting thresholds and CISA reporting obligations before an incident, not during one.
-
Retain forensics capability in advance and preserve evidence during isolation. An external forensics team was on site quickly here. Pre-negotiated incident response retainers shorten that clock. Ensure containment procedures capture volatile memory and edge device logs before appliances are rebooted or reimaged, since firewall logs are frequently the only record of initial access.
-
Communicate operationally even before the cause is known. NC Ports published gate-time updates and drove customers to an email alert service while the cause was still undisclosed. For logistics operators, that separation of operational status from incident detail is the right default and reduces the pressure to speculate publicly.
Sources: Cyberattack on North Carolina Ports 'contained' as Coast ... | FortiBleed campaign used custom FortiGate sniffer to steal credentials | North Carolina hack affects Ports in Wilmington, Morehead City and... | Systems outage delays NC Ports gates - Port Technology International | North Carolina Ports Cyberattack: Wilmington, Morehead City, Charlo... | North Carolina Ports Cyberattack Disrupts Critical Operations, Reve... | NC Ports Strengthens Foundation for Future Growth with FY26 Results... | Chick-fil-A Notifying Customers of Data Breach; Automated Attack Hi...