Skip to content
Rush Commerce
Commerce & Retail Tech3 min read

NC Ports cyberattack: your manual fallback is the plan

A cyberattack knocked out IT at three North Carolina ports. Gates opened manually the next morning. Continuity beat prevention — know what your manual mode looks like.

Cargo kept moving. That is the headline of the North Carolina Ports cyberattack, and it is the part worth copying. A systems-wide IT outage hit all three of the state's port facilities on August 4. The gates were shut. By 8 a.m. the next morning they were open again — run by hand, on paper, while the technology stayed down.

What actually happened

North Carolina Ports confirmed it detected an intrusion late on August 4 and activated its cybersecurity contingency plan. The outage disabled IT systems across the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, forcing gate closures and delaying truck and cargo movement.

Gates reopened manually on the morning of August 5. Normal operating schedules were back by August 7, with the authority warning that delays should still be expected while systems were restored and work continued to be processed by hand. The U.S. Coast Guard said it was monitoring the aftermath, and the authority engaged state agencies including the NC Department of Information Technology.

Still unknown: who did it, how they got in, and whether any commercial, employee or customer data was taken. The authority has not attributed the attack or estimated how much cargo traffic was affected.

Why it matters for your business

Roughly 72 hours from full IT outage to normal schedules, without stopping trade through a southeastern hub for agricultural exports and retail goods. That did not happen because someone had a better firewall. It happened because somebody had already written down how to open a gate without a computer.

Most small businesses have the opposite setup. The POS is the only way to take payment. The WMS is the only place that knows what is on the shelf. The scheduling app is the only record of who is working tomorrow. Every one of those is a single point of failure that nobody has rehearsed around, because the software has never been down long enough to force the question.

Ask it now, on a normal day. If your core system is unavailable for 48 hours, what do you do in the first hour? Not eventually — the first hour. Can you take an order, quote a price, tell a customer where their shipment is, and pay someone? For most operators the honest answers are: a paper pad, a printed price list, a phone call, and a printed roster. That is not a failure of ambition. It is a plan, and it is worth more than another security tool.

Then handle the boring half: a current export of your customer and inventory data that lives somewhere your primary system cannot reach, a printed contact list for your top vendors and carriers, and one named person who decides when to switch to manual. The switch itself is the hard part — teams lose a day waiting for the system to come back instead of declaring it down.

And the supplier side: NC Ports' outage was somebody else's stockout. Your continuity plan should include the vendors whose downtime becomes your downtime.

Key takeaways

  • A cyberattack detected August 4 knocked out IT at Wilmington, Morehead City and the Charlotte Inland Port
  • Gates reopened manually on August 5; normal schedules resumed August 7 with work still processed by hand
  • Attacker, entry point, and whether data was stolen are all still undisclosed; the Coast Guard is monitoring
  • The win here was continuity, not prevention — a written contingency plan let trade continue through a full systems outage
  • Define your own manual mode: how you take an order, quote, locate a shipment and pay people in the first hour without software

Software you can't run without is a liability, not an asset. We build commerce and ops systems with exportable data, offline fallbacks, and a documented manual mode — so an outage costs you a slow day, not a closed one. See how we build for continuity or have us pressure-test your single points of failure.

Sources: BleepingComputer, CyberScoop.

  • #supply-chain
  • #business-continuity
  • #cyberattack
  • #logistics
  • #incident-response
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.