North Carolina Ports Cyberattack: When a Partner Goes Dark

On August 4 a cyberattack shut down IT at all three North Carolina ports. What it teaches NC manufacturers and distributors about resilience. (336) 886-3282.

Cover Image for North Carolina Ports Cyberattack: When a Partner Goes Dark

A cyberattack took down the IT systems that run North Carolina's three seaports, and the ports kept moving freight anyway. That second half is the part every plant manager and controller in the Piedmont Triad should study, because the ports had something most 70-person shops do not: a written plan for running the gate when the computers are gone. If a supplier, a carrier, or your own ERP went dark tomorrow, forget whether you would get hacked. Ask whether you could still ship by hand.

What happened at the North Carolina ports?

North Carolina Ports discovered unauthorized activity on its network late on Tuesday, August 4, 2026, and its IT team immediately activated the agency's Cybersecurity Contingency Plan, engaging the NC Department of Transportation, the NC Department of Information Technology, and the U.S. Coast Guard. (WECT) The intrusion hit gate operations at all three facilities: the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. (Maritime Executive)

Rather than halt entirely, Wilmington posted "System Issues. Expect Delays" at the gate, ran a delayed opening, and switched to manual gate processing so the IT team could focus on recovery. (WECT) That matters at volume: Wilmington alone handles more than 5,000 container gate moves a week and 600,000 TEU of container capacity a year, and together with Morehead City it moves roughly 4.4 million short tons of bulk and breakbulk cargo annually. (BleepingComputer) By Wednesday, the ports said the breach had been contained and they had moved into recovery. (WECT) The authority posted a normal operating schedule for Friday, August 7, with vessel activity proceeding as scheduled, even as parts of the operation kept running manually while the investigation continued. (BleepingComputer) (CyberScoop)

North Carolina Ports has not named the attacker, has not disclosed a ransom demand, and said there is "no indication at this time that sensitive data was compromised." (WECT) The Coast Guard confirmed it was monitoring the aftermath and coordinating the investigation with partner agencies. (CyberScoop) Attribution is still pending, so treat any name you see attached to this as unconfirmed.

Is your operation exposed the same way the ports were? Preferred Data Corporation maps where a single system outage would stop your business and builds the fallback before you need it. Call (336) 886-3282 or talk to our team about a continuity review.

Attribution will not save your shipping dock. A fallback plan will.

Every headline chases the attacker: which group, what malware, was it ransomware. For a shop in Kernersville or Thomasville, that is the least useful thing to know, because you cannot control who goes after your carrier or your bank. You can control what your dock does on the morning their systems, or yours, do not come up.

The ports handled it well, and there was nothing clever about how. They had a contingency plan that told a gate clerk exactly what to do when the screens went dark, so nobody had to invent a workaround under pressure. Here is the uncomfortable part for a smaller shop: that plan is exactly what almost nobody in the 20-to-250-employee range actually has on paper. When we walk a Triad plant floor, the "manual fallback" usually lives in one veteran's head in the shipping office. The day-shift lead knows the trick; the night shift does not. That single-person gap is what turns a one-day outage into a one-week one, and no firewall on earth closes it.

This was not really a security failure. It was a continuity win, and the continuity half is the part nobody copies.

Your exposure is also wider than your own network. The ports were somebody's supplier that week. Every NC manufacturer that trucks containers through Wilmington and every distributor waiting on breakbulk through Morehead City absorbed the delay without being breached themselves. A partner's bad Tuesday lands on you as a late shipment and an idle line, which is why a supplier's uptime belongs in your own plan. We wrote a separate guide to third-party and supply-chain breach defense for NC small business for exactly this reason.

How exposed is your plant to one system going down?

List every system that, dead for one shift, would stop you shipping or producing, and write the manual step that keeps freight moving next to each one. Most shops have never put that on paper, which is why the outage, rather than the breach, is what ends up costing them.

The point of the exercise is to separate "annoying" from "stops the money." A down email server is annoying. A down ERP that holds your pick tickets, your BOLs, and your customer pricing is a stopped dock. Rank by that, not by how technical the system sounds.

System that goes darkWhat actually stopsManual fallback most shops lack
ERP / order-and-shipping systemPick tickets, bills of lading, invoicingPrinted daily order sheet, offline price list
A key carrier or 3PL (like the ports)Inbound parts, outbound freightSecond carrier on standby, will-call pickup plan
Plant-floor network / MESLine scheduling, machine dataPaper travelers, a known-good last schedule
Payment or banking accessPayroll, vendor paymentsSignatory list, a backup payment channel
Internet / primary ISPEverything cloud-basedCellular failover, a documented offline mode

If a row in that table has no fallback, that is an operations gap, not a security one, and it is fixable without buying a single new tool. The plant-floor row is the one manufacturers underestimate most, because a flat network lets an office outage reach the machines that run production. Keeping IT and the plant floor properly segmented is what stops a front-office incident from becoming a line-down incident.

Want the table filled in for your actual operation, not a generic one? That is a standard managed IT and continuity assessment from Preferred Data. We are based in High Point and go on-site within 200 miles of it, and we have run networks for North Carolina manufacturers since 1987. Call (336) 886-3282.

What the ports did right, translated for a 70-person shop

The ports gave a clean template, and none of it required a government budget. Four moves did the work, and each one has a small-business version.

  1. They detected it fast. Their monitoring flagged unauthorized activity the same day, which is the difference between a contained incident and a month-long one. (WECT) The small-shop version is managed detection on your endpoints and servers so someone is actually watching at 2 a.m., not reading logs after the fact.
  2. They had a plan they could execute. The contingency plan named a manual mode and who runs it, so the response was a checklist, not a scramble. (Maritime Executive) Yours can be two pages: which systems, what the manual step is, who owns it on every shift.
  3. They kept operating in manual mode. Wilmington chose delayed-but-moving over closed. (BleepingComputer) If you can cut and ship off paper travelers for a day, your IT team gets to restore the systems properly instead of racing the clock while the line sits idle.
  4. They brought in help and partners early. They engaged state agencies, the Coast Guard, and outside forensics at once. (The Record) Your equivalent is knowing, before the bad day, who you call and whether your backup and disaster recovery has actually been restored from, rather than merely configured.

You do not write a recovery plan during the outage. The ports were back on schedule within the week because the plan already existed, and that speed was decided months earlier.

The timeline is the proof. Detected Tuesday, contained by mid-week, back on a normal posted schedule by Friday. (WECT) (CyberScoop) Set that against the ransomware cases that keep a manufacturer down for weeks, which we covered when industrial ransomware halted production at NC plants. The gap between one bad week and one lost month is rarely the skill of the attacker. It is whether the target had backups it had actually restored from and a way to keep working while it did.

What to do this week

You do not need a consultant to start. Block an hour with your shipping lead and your controller and do the first three of these; call us for the rest.

  • Build the outage table above for your top five systems. If any row has no manual fallback, that row is this quarter's project.
  • Confirm your backups are tested, not merely running. Ask your IT lead when the last full test restore actually happened; if the answer is a shrug or "never," that is the finding, and it is more urgent than any new tool.
  • Write the two-page incident card: who detects, who decides, who runs manual mode, who you call. Put a copy where the night shift can find it.
  • Check whether an office network problem can reach your plant-floor or logistics systems. If it can, segmentation is the next conversation.
  • Pressure-test one third-party dependency. If your primary carrier had the ports' week, what is your Tuesday-morning move? Distributors especially should read the logistics cybersecurity and supply-chain guide for NC.

Here is a concrete first step, with no obligation: book a 30-minute call with Preferred Data and we will help you fill in that top-five outage table for your actual shop, so you walk away with it even if you never hire us. We run managed IT, cybersecurity, and disaster recovery for North Carolina manufacturers and distributors. Call (336) 886-3282 or reach us at 1208 Eastchester Drive, Suite 131, High Point, NC 27265.

Questions NC shippers are asking now

Was the North Carolina ports cyberattack ransomware?

North Carolina Ports has not confirmed the attack type. Its spokesperson declined to confirm whether ransomware was involved, the authority disclosed no ransom demand, and it said there was no indication sensitive data was compromised, with no group claiming responsibility as of early reporting. (The Record) (CyberScoop) Attribution is still pending, so any specific actor named for it should be treated as unconfirmed.

Did the ports shut down completely?

No. The Port of Wilmington ran a delayed opening and moved to manual gate processing rather than closing, keeping freight moving while the IT team worked on recovery. (WECT) That choice, operating in a degraded manual mode instead of stopping, is the part smaller operations should copy.

How long did recovery take?

Gate operations were back on a normal posted schedule within the same business week, though the ports did not declare full recovery complete at that point. North Carolina Ports detected the activity on Tuesday, August 4, said the breach was contained by mid-week, and posted a normal operating schedule for Friday, August 7, with some processing still manual and the investigation ongoing. (WECT) (CyberScoop) Getting the gates moving again that quickly reflects preparation rather than luck; a fully verified restore is a separate milestone the ports had not publicly confirmed as of that reporting.

We move freight through Wilmington but were not breached. Does this reach us?

Yes, through the delay. The ports are a supplier to thousands of NC firms, so every manufacturer moving containers through Wilmington and every distributor waiting on cargo through Morehead City absorbed the disruption without being breached themselves. (Maritime Executive) A partner's outage lands on your dock as a late shipment, which is why a supplier's resilience belongs in your own continuity plan.

What is the single most valuable thing to do first?

Test a full restore from your backups. A backup that has never been restored is the most common false sense of security we find in NC shops. If you cannot say when your last successful test restore happened, that gap is your first project, ahead of any new tool.

Does Preferred Data only serve High Point?

No. Preferred Data is headquartered in High Point and serves manufacturers, distributors, and industrial firms on-site within 200 miles of High Point, which covers Greensboro, Winston-Salem, Charlotte, Raleigh, the wider Piedmont Triad, and the ports region. We have done this for North Carolina businesses since 1987.

Support