Infosecurity

North Carolina Ports cyberattack ‘contained’ as recovery begins, Coast Guard investigates

Published

on

What happened at North Carolina Ports

North Carolina Ports is picking up the pieces after a cyberattack forced its three facilities to abandon digital systems and fall back on pen-and-paper operations Tuesday. The breach hit Wilmington, Morehead City, and Charlotte — the state’s main cargo gateways, which together move more than 4 million tons of freight annually.

A spokesperson told Recorded Future News that the IT system was “hacked by an outside actor or group,” triggering an immediate contingency plan. The U.S. Coast Guard and multiple state agencies were notified, and an outside forensics team is now working alongside the port’s IT department to assess the damage and restore systems.

“The breach has been contained, and we are now in the recovery process,” the spokesperson said.

Manual operations and expected delays

Don’t expect business as usual just yet. While the ports are “following a normal operating schedule today,” the spokesperson confirmed that “operations are still being processed manually.” A notice on the North Carolina Ports website warns that gates at all three locations will operate normally Thursday but delays are likely.

Local news outlets spotted signs outside port gates Tuesday warning trucking companies about delays “due to system issues.” The spokesperson declined to answer whether this is a ransomware attack, and no hacking group has stepped forward to claim responsibility.

Why ports keep getting hit

This isn’t an isolated incident. Ports across the U.S., Europe, and Asia have become prime targets for ransomware gangs over the past five years as maritime operations lean harder into digital systems. The Port of Seattle cyberattack in 2024 is a case in point — criminals disrupted both the city’s airport and seaport ahead of the Labor Day holiday, and the port refused to pay the ransom.

The pattern is clear: critical infrastructure is exposed, and attackers know it.

Senator calls for operational technology upgrades

The timing of Wednesday’s political pushback is no coincidence. Senator Tom Cotton (R-Ark.) sent a letter to Treasury Secretary Scott Bessent urging investment in American operational technology — the hardware and software that runs everything from water systems to power plants.

“This technology is underfunded and outdated, leaving vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural states like Arkansas, vulnerable to cyberattacks by our adversaries,” Cotton wrote.

He added: “Attacks on civilian infrastructure have become a routine instrument of modern warfare, and American operational technology is a target.”

What recovery looks like

For now, the focus is on getting systems back online safely. The forensics team is assessing which systems were compromised and how. Until then, expect slower turnaround times at port gates and a lot of manual paperwork.

The ransomware attack on ports trend shows no signs of slowing, and this incident is a stark reminder that even contained breaches can disrupt supply chains for days. Truckers and shipping companies should plan for delays and stay in touch with port officials for updates.

We’ll keep you posted as more details emerge — including whether a ransom demand was made and who’s behind the attack.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version