Skip to main content

North Carolina Ports: When IT Alone Is Enough to Force Manual Operations

SUBJECT: Ongoing STATUS: 6/10 Severity AUDIENCE: Government, Critical Infrastructure, Transportation and Logistics Security Leads

Aug 10, 2026

·

Blog

·

Secure Communications

A systems-wide IT outage at North Carolina's two deepwater seaports and inland hub forced three days of manual gate processing, without any confirmed compromise of operational technology, extending the isolation-and-manual-operations pattern from the July water utility attacks into a second critical infrastructure sector. 

What Happened — and Why It Is Different

On the evening of August 4, 2026, the North Carolina State Ports Authority detected an unauthorized cyber intrusion that triggered a systems-wide IT outage. The authority activated its Cybersecurity Contingency Plan immediately and brought in an outside forensics team to work alongside its internal IT department.1 

The outage forced all three facilities, the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, to shift gate and cargo processing to manual operations. The authority reported the intrusion contained by the morning of August 5, with normal gate schedules resuming August 6, though delays continued as IT restoration work went on.2,3 

The U.S. Coast Guard confirmed it is monitoring the incident. As of this writing, North Carolina Ports has not disclosed how access was gained, named a threat actor, or confirmed whether commercial, employee, or customer data was compromised. No group has publicly claimed responsibility.4 

Notably, there is no public evidence the intrusion reached operational technology, industrial control systems, vessel traffic systems, or gantry cranes. The disruption appears contained to IT and gate-processing systems, yet it was still sufficient to force a full manual fallback across three physical sites and delay cargo movement for days.5 

What the Disruption Revealed

What Was Disrupted 
What It Forced 
Operational Consequence 
Structural Risk 
Core IT and gate-processing systems, not OT 
Simultaneous shift to manual truck and cargo processing at three separate facilities 
Gate delays and cargo backlogs rippling into regional trucking schedules for days 
No OT compromise was required to force a multi-site, multi-day manual fallback 
Internal visibility into affected systems 
Engagement of an external forensics team working alongside internal IT staff 
Two teams needing to coordinate investigation and recovery in real time 
Coordination between internal and external responders depends on a channel independent of the system under investigation 

Why This Matters 

Old Assumption 
Current Reality 
BlackBerry Response 
OT compromise is what turns a cyberattack into physical-world disruption 
An IT-only outage, with no confirmed OT compromise, was enough to force three ports into manual fallback for days 
Communications architecture built to keep coordination running independent of whichever system, IT or OT, fails first 
Water and wastewater is this year's leading-edge critical infrastructure risk 
A second, unrelated sector, maritime logistics, was forced into the same isolate-then-operate-manually posture within the same news cycle 
Sector-agnostic resilience: the coordination layer works the same way for a port, a utility, or any physically distributed operator 
Attribution determines whether an incident is actionable 
This incident remains unattributed and still forced a multi-day, multi-site manual fallback 
Continuity planning that does not wait on attribution to be useful 
Action
What It Means in Practice
IMMEDIATE 
Confirm whether your organization's manual-fallback plan assumes IT and OT fail together or separately. This incident shows IT alone can be enough to force a full manual fallback. 
IMMEDIATE 
Identify how staff across physically separate sites would coordinate a synchronized manual fallback if core IT systems were unavailable for 24 to 48 hours. 
SHORT-TERM 
Establish an out-of-band channel connecting internal IT and any external forensics or incident-response partner, independent of the systems under investigation. 
SHORT-TERM 
Extend incident coordination planning beyond OT-focused sectors. Ports, rail, aviation ground operations, and other physically distributed critical infrastructure face the same exposure. 
ONGOING 
Treat unattributed, IT-only disruptions as equally actionable as attributed OT compromises. Don't wait for attribution to update continuity plans. 

BlackBerry Secure Communications Perspective

An unattributed IT outage forced three port facilities into a multi-day manual fallback without ever touching operational technology. That is the same lesson the water sector has been learning since July: coordination, not isolation alone, is what determines whether critical infrastructure keeps functioning.  

Citations:

  1. North Carolina Ports confirms cyberattack disrupting operations (BleepingComputer, August 2026). 

  2. Cyberattack disrupts operations at NC Ports in Wilmington, Morehead City and Charlotte (WECT, August 5, 2026). 

  3. Cyberattack disrupts North Carolina port operations (Splash247, August 6, 2026). 

  4. Coast Guard says it is monitoring cyberattack that disrupted North Carolina's ports (CyberScoop, August 7, 2026). 

  5. North Carolina Ports cyberattack: What happened, what we know and what we still don't (Shieldworkz, August 2026). 

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now