North Carolina Ports: When IT Alone Is Enough to Force Manual Operations
SUBJECT: Ongoing STATUS: 6/10 Severity AUDIENCE: Government, Critical Infrastructure, Transportation and Logistics Security Leads
Aug 10, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
A systems-wide IT outage at North Carolina's two deepwater seaports and inland hub forced three days of manual gate processing, without any confirmed compromise of operational technology, extending the isolation-and-manual-operations pattern from the July water utility attacks into a second critical infrastructure sector.
What Happened — and Why It Is Different
On the evening of August 4, 2026, the North Carolina State Ports Authority detected an unauthorized cyber intrusion that triggered a systems-wide IT outage. The authority activated its Cybersecurity Contingency Plan immediately and brought in an outside forensics team to work alongside its internal IT department.1
The outage forced all three facilities, the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, to shift gate and cargo processing to manual operations. The authority reported the intrusion contained by the morning of August 5, with normal gate schedules resuming August 6, though delays continued as IT restoration work went on.2,3
The U.S. Coast Guard confirmed it is monitoring the incident. As of this writing, North Carolina Ports has not disclosed how access was gained, named a threat actor, or confirmed whether commercial, employee, or customer data was compromised. No group has publicly claimed responsibility.4
Notably, there is no public evidence the intrusion reached operational technology, industrial control systems, vessel traffic systems, or gantry cranes. The disruption appears contained to IT and gate-processing systems, yet it was still sufficient to force a full manual fallback across three physical sites and delay cargo movement for days.5
What the Disruption Revealed
What Was Disrupted | What It Forced | Operational Consequence | Structural Risk |
Core IT and gate-processing systems, not OT | Simultaneous shift to manual truck and cargo processing at three separate facilities | Gate delays and cargo backlogs rippling into regional trucking schedules for days | No OT compromise was required to force a multi-site, multi-day manual fallback |
Internal visibility into affected systems | Engagement of an external forensics team working alongside internal IT staff | Two teams needing to coordinate investigation and recovery in real time | Coordination between internal and external responders depends on a channel independent of the system under investigation |
Why This Matters
Old Assumption | Current Reality | BlackBerry Response |
OT compromise is what turns a cyberattack into physical-world disruption | An IT-only outage, with no confirmed OT compromise, was enough to force three ports into manual fallback for days | Communications architecture built to keep coordination running independent of whichever system, IT or OT, fails first |
Water and wastewater is this year's leading-edge critical infrastructure risk | A second, unrelated sector, maritime logistics, was forced into the same isolate-then-operate-manually posture within the same news cycle | Sector-agnostic resilience: the coordination layer works the same way for a port, a utility, or any physically distributed operator |
Attribution determines whether an incident is actionable | This incident remains unattributed and still forced a multi-day, multi-site manual fallback | Continuity planning that does not wait on attribution to be useful |
Recommended Actions
Action | What It Means in Practice |
IMMEDIATE | Confirm whether your organization's manual-fallback plan assumes IT and OT fail together or separately. This incident shows IT alone can be enough to force a full manual fallback. |
IMMEDIATE | Identify how staff across physically separate sites would coordinate a synchronized manual fallback if core IT systems were unavailable for 24 to 48 hours. |
SHORT-TERM | Establish an out-of-band channel connecting internal IT and any external forensics or incident-response partner, independent of the systems under investigation. |
SHORT-TERM | Extend incident coordination planning beyond OT-focused sectors. Ports, rail, aviation ground operations, and other physically distributed critical infrastructure face the same exposure. |
ONGOING | Treat unattributed, IT-only disruptions as equally actionable as attributed OT compromises. Don't wait for attribution to update continuity plans. |
BlackBerry Secure Communications Perspective
An unattributed IT outage forced three port facilities into a multi-day manual fallback without ever touching operational technology. That is the same lesson the water sector has been learning since July: coordination, not isolation alone, is what determines whether critical infrastructure keeps functioning.
Citations:
North Carolina Ports confirms cyberattack disrupting operations (BleepingComputer, August 2026).
Cyberattack disrupts operations at NC Ports in Wilmington, Morehead City and Charlotte (WECT, August 5, 2026).
Cyberattack disrupts North Carolina port operations (Splash247, August 6, 2026).
Coast Guard says it is monitoring cyberattack that disrupted North Carolina's ports (CyberScoop, August 7, 2026).
North Carolina Ports cyberattack: What happened, what we know and what we still don't (Shieldworkz, August 2026).
%3Aquality(100)&w=3840&q=75)