# North Carolina's Three Ports Went Dark at Once. That's Not an Accident.
When a cyberattack hits a single port, it's an incident. When it hits three simultaneously — a coastal shipping terminal, a bulk cargo facility, and an inland container hub hundreds of miles away — that's a coordinated campaign against shared infrastructure. The North Carolina Ports Authority confirmed this week that a cyberattack disrupted IT systems across Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port, slowing operations at all three sites.
The authority's terse confirmation left most operational details undisclosed, which is standard practice during active incident response. But the geography of this attack tells its own story.
## Three Sites, One Vulnerability Surface
The Charlotte Inland Port isn't on the coast. It's a landlocked intermodal facility in Gaston County that connects rail and trucking networks to North Carolina's oceanside terminals. For an attacker to disrupt all three simultaneously, either the assault hit shared enterprise systems administered centrally — the most likely scenario given a regional port authority's typical IT structure — or the initial intrusion moved laterally through connected networks fast enough to reach all nodes before containment kicked in.
Both possibilities should concern port authorities nationwide. Centralized IT administration is operationally sensible; it's also a single point of failure that turns one successful phishing email or one unpatched VPN appliance into a three-port outage. Maritime infrastructure has been converging IT and OT networks for years to improve efficiency, and that convergence has been expanding the attack surface faster than most security teams have been able to close it.
The good news, if there is any, is that the authority described operations as "slowed" rather than halted. That implies the attack landed on IT systems — cargo management, scheduling, communications — rather than directly on operational technology controlling cranes, vessel traffic management, or safety systems. For now.
## A Familiar Playbook in an Underdefended Sector
North Carolina Ports joins a crowded and grim list. Port of Nagoya in Japan went down for nearly three days in July 2023 after a ransomware attack disrupted Toyota's supply chain. DP World Australia suffered an attack in November 2023 that halted container movement at multiple ports for days, stranding roughly 30,000 shipping containers. Port of Lisbon fell to LockBit in December 2022. Port of Barcelona and Port of San Diego were both hit in the same two-week stretch in September 2018, which at the time looked anomalous; today it looks like a preview.
The pattern is consistent: attackers — often ransomware groups — have learned that port authorities make attractive targets precisely because the pressure to restore operations is immense and the cost of downtime is immediately quantifiable. Every hour a container terminal isn't moving boxes, someone is paying demurrage. Every delayed bulk shipment has downstream consequences for manufacturers, retailers, and agricultural supply chains. The business pressure to pay a ransom or accept a rushed, incomplete recovery is enormous.
No group has publicly claimed responsibility for the North Carolina attack at this writing. That gap is worth watching. Ransomware actors typically announce victims within days as part of their extortion strategy. Prolonged silence can mean negotiations are underway, the attacker is a nation-state actor with different objectives, or the incident is less severe than initial reporting suggested.
## What Runs Through Wilmington
Port of Wilmington handles roughly two million metric tons of cargo annually. It's also designated a Port of Embarkation by the U.S. military, meaning it serves as a strategic asset for military logistics. Morehead City moves bulk commodities — phosphate, potash, and grain — that feed agricultural supply chains across the Southeast. Charlotte Inland Port is the connective node that keeps rail containers flowing to both.
Disruption to any of these creates ripples. Disruption to all three at once, even temporarily, creates congestion and delays that compound through a supply chain for weeks after systems come back online. Ships that miss their berth windows get rescheduled. Truckers who arrive to pick up containers find yards in manual mode. Customers waiting on time-sensitive cargo reroute through other facilities, adding cost and delay throughout the network.
This is the attacker's leverage, and it's substantial.
## Why Ports Keep Losing This Fight
The structural problem in maritime cybersecurity isn't lack of awareness. After the NotPetya attack devastated Maersk in 2017 — wiping 45,000 PCs and 1,000 applications at an estimated cost of $300 million — the industry spent years talking about cybersecurity improvements. The IMO mandated that cyber risk management be incorporated into safety management systems aboard ships by 2021.
But port authority IT is a different beast. Many port authorities run on procurement cycles and budgets that look more like municipal government than like private enterprise. Legacy systems run for decades. Network segmentation between IT and OT is often incomplete or inconsistently enforced. Security staffing is thin. And unlike a shipping conglomerate that can spread security investment across a global operation, a regional port authority has limited resources and a lot of surface to defend.
The Charlotte Inland Port's inclusion in this incident is a reminder that "port security" can't be scoped only to facilities with water. The entire logistical chain — from inland container yards through rail corridors to ocean terminals — shares infrastructure and risk.
---
## HackWire Analysis
The North Carolina attack should be read alongside two broader trends that most coverage is treating separately.
First, the targeting of multi-site regional authorities rather than single high-profile ports. Attackers have gotten more sophisticated about target selection. A major global terminal operator like DP World has a dedicated security team, incident response retainers, and the resources to weather an attack. A state port authority managing three facilities with shared IT infrastructure is a harder problem with fewer resources. The attack surface is proportionally larger relative to the defensive capability. Expect more attacks structured this way.
Second, this attack lands during a period of already-elevated pressure on East Coast port operations. Any disruption compounds existing fragility in coastal shipping capacity. Attackers — particularly ransomware groups studying their targets before deploying — are aware of this context. Hitting when the business pain is already high increases the pressure to pay or recover fast and dirty.
What defenders at similar regional authorities should take from this: centralized IT administration is probably your most immediate exposure. That shared infrastructure is efficient, but it means your blast radius is "all three facilities" rather than "one." Network segmentation between sites, air-gapped OT where feasible, and offline backup for cargo management systems should be the priority list. Not "we need a better firewall."
The silence from threat actors so far also bears watching. If this was a nation-state reconnaissance operation — and East Coast port infrastructure with military logistics designation makes that at least plausible — the objectives look different than ransomware. We may never see a clear attribution.
Regional port authorities should be on the phone with CISA's maritime sector contacts this week, not next month.
— HackWire Editorial
---
## Related Coverage