Coast Guard monitors North Carolina ports cyberattack
The Ports Authority hasn't disclosed which systems were hit, what the attack vector was, or whether cargo operations were affected, three days in, the silence is the story.
TL;DR
A cyberattack disrupted gate operations at all three North Carolina port facilities this week (Wilmington, Morehead City, and Charlotte Inland Port) forcing the Ports Authority to delay gate openings and shift to manual processing. The Coast Guard and CISA are coordinating with state partners on the investigation. As of Friday morning, normal gate schedules were back in effect, but the agency hasn't disclosed the nature of the attack, which systems were compromised, or whether vessel, rail, or cargo-handling operations were affected. No attribution has been made.
The North Carolina State Ports Authority activated its cybersecurity contingency plan after discovering the intrusion early this week, but three days later the public-facing picture remains remarkably thin. We don't know the attack type, the initial access vector, whether ransomware was involved, or whether operational technology (cargo-handling equipment, vessel-loading systems) was touched at all. The Ports Authority says it's posting updates on its website and directing users to an email alert service. It hasn't offered an estimate of how much truck or cargo traffic was disrupted.
That's a conspicuous information gap for a facility class that sits squarely inside the Maritime Transportation Security Act's regulatory perimeter. The Coast Guard enforces TWIC program requirements at these facilities, and a GAO report released barely a month ago flagged the agency's shortcomings in sharing inspection data and communicating program risks to stakeholders. Now the Coast Guard is running point on an active incident investigation at three ports simultaneously, with CISA presumably in support, though CISA hadn't responded to press inquiries by deadline.
The attack lands in a year when Iranian-linked actors have been hitting U.S. water and wastewater systems with some regularity. Nobody's connecting those dots publicly yet, and the Ports Authority hasn't hinted at attribution. But maritime facilities present a different threat profile than municipal water plants, the economic disruption radius is wider, and the operational recovery surface is larger.
For the Coast Guard, the incident is a live test of coordination protocols that the GAO just told Congress need work. For port operators nationwide, it's a reminder that gate systems are IT-OT bridges worth hardening before, not after, an incident forces manual processing.
Published ·Deep Fathom