```html ```
top of page

North Carolina's Ports Kept Moving Cargo by Hand for a Week. Nobody Has Claimed the Attack — and That Is the Part Worth Measuring.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 3 hours ago
  • 6 min read

North Carolina State Ports Authority was attacked on August 4. The disruption reached all three of its facilities: the deepwater terminals at Wilmington and Morehead City, and the inland terminal at Charlotte.


The response, on the public record, was fast and unglamorous. The IT team activated a Cybersecurity Contingency Plan. Wilmington ran a delayed opening and switched the truck gates to manual processing, deliberately, so that the IT side could concentrate on recovery instead of on keeping the lights on. The authority engaged the North Carolina Department of Transportation, the North Carolina Department of Information Technology, and the U.S. Coast Guard, which is the sector risk management agency for maritime.


A week later the ports are on a normal operating schedule and are still processing manually.


Nobody has said who did it. Nobody has said how they got in. Nobody has said whether commercial, employee or customer data was taken.


And — this is the part we went and checked ourselves — nobody has claimed it.



We looked for the claim. There isn't one.


We queried the public ransomware leak-site trackers on August 11, seven days after the intrusion, for North Carolina State Ports Authority and for the state generally. There are plenty of North Carolina victims in the data — a country club, a sign company, a YMCA, Ingersoll Rand posted on August 8, Commscope back in April. The ports are not among them. No group has posted them. No countdown, no sample data, no negotiation page.


That absence is a finding, and it is worth stating with a date on it because it will stop being true or it will stay true, and either outcome tells you something.


There are three explanations and they are not equally comfortable:


  1. It was never extortion. Espionage, hacktivism, a state-aligned probe of a maritime chokepoint, or a criminal intrusion that got caught before the payload landed.

  2. It is extortion and the negotiation is private. No leak-site post because the victim is still talking, or because this crew does not run a leak site.

  3. It is extortion on a channel we do not monitor. We wrote about one of those this morning: an actor that skipped the leak site entirely and published its notice on the victim's own website instead.

We cannot tell you which. What we can tell you is what it costs to assume the first one.





If you count ransomware by counting leak-site posts, you are undercounting


Nearly every ransomware statistic you have read this year — victim counts, group league tables, "the most active crew this quarter," sector breakdowns — is built by scraping dedicated leak sites and counting posts. It is the only dataset that exists at scale, our own coverage leans on it, and it is genuinely useful.


It is also a census of the victims who did not pay quickly and whose attacker runs a leak site. That is a real population. It is not the population of ransomware victims, and the gap between the two is invisible by construction.


An attack that shuts three port facilities down to manual processing for a week is not a marginal event. It is exactly the kind of incident that ought to anchor a critical-infrastructure threat model. And in the data almost everybody uses, it currently appears as nothing at all.


This matters more as extortion channels fragment. The economics of a leak site were always about publicity as leverage. If the leverage can be applied more directly — to the customers, to the operations, to the search results — the leak site becomes optional, and the moment it becomes optional our primary measuring instrument develops a blind spot the same shape as the innovation.


Say what your denominator is. If your ransomware numbers come from leak-site scraping, they measure leak-site posts. That is a fine thing to measure as long as nobody mistakes it for the thing itself.



The manual gate is the control that worked


Now the part that deserves credit, because we spend a lot of time here being hard on people and this one earned the opposite.


The ports kept moving cargo. Not because the systems held — they clearly did not — but because there was a way to run the gate without them, somebody had thought about it in advance, and the operations team was willing to take a delayed opening rather than pretend everything was fine.


That is a specific, teachable thing. Most organisations cannot do it. An IT-only business that loses its systems loses its ability to transact, full stop; there is no manual mode because there is no physical process underneath the software. A port has trucks, gates, cranes and paper, and the software sits on top of an operation that existed before the software did. Degraded-mode operations are possible because the degraded mode is a real thing somebody can still do.


The lesson is not "keep paper forms." It is: know which of your processes have a floor under them and which are suspended entirely by software, and be honest about the second category. Most incident response plans quietly assume systems come back. The ones that survive assume they might not, and specify what happens meanwhile.


The other thing they got right, and it is subtle: they used the manual fallback to buy focus. The stated reason for manual gate processing was to let the IT team concentrate on recovery. That is a resourcing decision made under pressure by people who understood that a half-recovered system consuming all your responders is worse than a slow one that runs itself.



"Contained" and "recovered" are different words


The public statements say the incident is contained. A week on, gates are still manual.


Both of those are almost certainly true, and holding them together is the correct reading. Containment means the intruder no longer has access and is not spreading. Recovery means your systems are back. Between the two sits the actual expensive part of every incident — validating that restored systems are clean, rebuilding rather than restoring where you cannot be sure, and refusing to bring something back online early because a stakeholder is impatient.


An organisation that is still manual on day seven is very likely doing that work properly. An organisation that was fully back on day two either had excellent segmentation or did not look hard enough. We are not going to criticise a port for taking its time, and neither should the people waiting on containers.


What is missing from the public record is any statement about data. Not "no data was taken" — just nothing. That is normal at this stage, and it is also the single most common thing to change later. If information was exfiltrated on August 4, the disclosure will come weeks from now, and it will land as a separate news cycle that most people will not connect back to this one.



What this means if you run something physical


Write down your degraded mode and then actually run it. Not a tabletop — a real morning where the gate is manual, the terminal operating system is assumed gone, and you find out how many people know the fallback. NC Ports could do this on August 4 because it was not the first time anyone had thought about it.


Decide in advance what you sacrifice to buy responder focus. Delayed opening, manual processing, reduced throughput. If that call has to be invented during an incident, it gets made late and badly.


If you are maritime, the Coast Guard involvement is the model, not an embarrassment. Sector risk management agencies exist so that a single port's incident becomes sector-wide knowledge. Ports talk to each other; this one will be better handled at the next facility because this facility called it in.


And do not wait for attribution to act. There is no named actor here and there may never be one. Every defensive action worth taking in the next month — segmentation between corporate IT and terminal operations, verifying that your degraded mode is real, checking whether your remote access requires phishing-resistant authentication — is worth taking regardless of whose name eventually goes on this.


We will keep watching for a claim. If one appears we will say so, and we will note how long it took, because that interval is itself data about how these operations are changing.




Timeline and response details are from North Carolina State Ports Authority's public statements and contemporaneous reporting; the intrusion is dated August 4, 2026. Our leak-site check was run against public ransomware trackers on 2026-08-11 and found no post naming the ports authority — an absence at that date, not proof that none exists or will. No actor has been named by anyone, and we are not naming one. We have no first-party telemetry on this incident and are not claiming any.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=nc-ports-manual-gates-and-the-claim-that-never-came



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page