Cyberattack Disrupts Operations at North Carolina Ports Authority’s Three Facilities
What Happened — On August 4 2026 the North Carolina Ports Authority detected a cyberattack that caused a systems‑wide outage across its Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The outage forced gate operations to pause until recovery began on August 5, resulting in delayed cargo movements and trucker wait times.
Why It Matters for Compliance & Audit Readiness
- The incident tests the effectiveness of SOC 2 CC6 (System Availability) controls and the organization’s documented incident‑response and business‑continuity procedures.
- Continuous evidence of control execution (e.g., incident‑response run‑books, recovery‑time‑objective tracking) is essential to demonstrate readiness during a SOC 2 audit.
- Mapping this disruption to your control framework helps prove due‑diligence and provides audit‑ready artifacts for the “Availability” and “Incident Management” criteria.
Who Is Affected – Transportation & logistics operators, maritime cargo handlers, and downstream supply‑chain partners that rely on the North Carolina ports.
Recommended Actions
- Review and update SOC 2 CC6 availability controls, ensuring documented recovery‑time‑objectives (RTO) and recovery‑point‑objectives (RPO) reflect real‑world outage scenarios.
- Collect and retain evidence of the incident‑response run‑book activation, system logs, and recovery milestones as audit artifacts.
- Conduct a tabletop exercise simulating a port‑wide outage to validate the contingency plan and identify gaps.
Source: BleepingComputer
Technical Notes – The attack’s vector and attribution remain undisclosed; no data exfiltration was reported. The outage impacted operational technology (OT) and enterprise IT systems that manage gate access and vessel scheduling. Source: same as above