MYS 2026/ PORT HERCULE, MONACO / 23-26 SEPTEMBER 2026
Vessel exposure assessment
Passive, outside-in screening of the fleet and the organisations behind it. The question addressed: exposed digital assets, or sensitive information on the internet, usable to attack or spear-phish an owner.
Executive summary
What this is. Every yacht on the official Monaco Yacht Show 2026 list, 129 of them, was frozen as a group and looked at from the outside using ShipCrawler, the vessel intelligence framework, adapted here for yachts. Only what is already public was used: domain records, mail settings, certificates, and the public internet index. Nothing was scanned, probed or connected to, so nothing on board was touched.
The risk in one line. The practical way to reach an owner is not through the yacht. It is by impersonating someone the owner trusts, at the moment money or instructions move.
WHAT WAS FOUND
- Mail that claims to come from a company is not rejected at 39 of the 72 company domains assessed. A supplier invoice, a charter instruction, or a request for payment can arrive looking genuine. This matters most, because it needs no technical skill to use.
- The two cases closest to an owner. One yacht's registered owner entity has no mail protection at all, so mail in its name is delivered without challenge. A management company overseeing four yachts in this group publishes a crew portal and a payroll system, and only monitors its mail, so a message impersonating the company is not stopped.
- 28 owner-facing pages are published across 9 company domains, including crew portals, an owner portal, a charter platform and account sign-in pages. 13 respond. Some are named after the systems behind them, such as payroll.
- 9 yachts are linked to an old file-transfer service still reachable on the company's own address. Old services are usually unpatched and unmonitored.
- 82 of the 129 entries miss basic browser protections on their company domains. That is a hardening gap rather than an open door, which is why it is listed last.
The good news, and it is genuine. No yacht in this group is reachable from the internet. 213 searches across every hull identifier returned nothing attributable to any yacht, so the vessels themselves are not exposed. 12 of the 129 entries are clean altogether, and 33 of the 72 company domains do reject mail in their own name.
Why impersonation works so easily. 75 brokerage and management firms were assessed on their own websites. They publish 183 named staff and 292 email addresses, and for 50 of those addresses the naming pattern is confirmed against a real person on the same site. That is the material needed to make an email from a colleague look real. None of it is a breach. All of it is public, and all of it is usable.
One honest limit. Only 16 of the 128 entries assessed could be checked against a domain belonging to the owner or manager side, because an owner's own companies and domains are not published. 112 had to be assessed through the exhibiting broker, and a broker is a route to an owner, not the owner.
What to do this week. Ask your management company to confirm that mail claiming to come from their domain is rejected, not merely monitored. Confirm who can reach the published crew, payroll and owner portals, and that a second factor is required to sign in. Treat any payment, bank detail change, or charter instruction arriving by email as unverified until confirmed by voice on a known number.
The next step on our side. If you provide your entities and domains, the same method points directly at your estate, including the parts that are not published. That is the assessment this report is built to deliver.
Per-vessel detail, the sources behind each finding, and the full list of limits are on the method page. Leaked-credential exposure was not checked, because those records are commercial, so it is unassessed rather than clean.
What this found
How to read the bands
- Band A (E1 / E2). Either the operator's domain cannot be protected by DMARC, so mail claiming to be from them is not rejected, or internal and non-production hostnames are published in certificate transparency and resolve. This is the band that makes a targeted message possible.
- Read the band-A count with care. For entries with no IMO of their own, the band is inherited from the exhibiting broker rather than measured on the owning company, so one large broker with a spoofable domain pulls every yacht it presents into band A. It reflects the exposure of the party presenting the yacht, which is what an attacker would impersonate, but it is not 92 independently exposed owners.
- Band B (E3). End-of-life software versions, or plaintext FTP reported on the address.
- Band C (E4). Missing HSTS or content security policy. Hygiene, listed for completeness, not a vulnerability.
Where to go
Map
116 markers positioned from live AIS or calibrated quay medians, coloured by band, click-through per vessel.
openMatrix
Every one of the 129 entries with its exposure classes, operator domain and screening status. Nothing omitted.
openFindings
The exposure classes with the domain-level evidence behind each one.
openEntities
Ownership and broker layer: who is behind the fleet, and what is published about them.
openRed team
One constructed route from published information to an owner's money and instructions, anonymised, and the three controls that break it.
openMethod
Scope, sources, and the limits and gaps that must be read alongside every number here.
open