MYS 2026/ PORT HERCULE, MONACO / 23-26 SEPTEMBER 2026

Vessel exposure assessment

Passive, outside-in screening of the fleet and the organisations behind it. The question addressed: exposed digital assets, or sensitive information on the internet, usable to attack or spear-phish an owner.

Executive summary

What this is. Every yacht on the official Monaco Yacht Show 2026 list, 129 of them, was frozen as a group and looked at from the outside using ShipCrawler, the vessel intelligence framework, adapted here for yachts. Only what is already public was used: domain records, mail settings, certificates, and the public internet index. Nothing was scanned, probed or connected to, so nothing on board was touched.

The risk in one line. The practical way to reach an owner is not through the yacht. It is by impersonating someone the owner trusts, at the moment money or instructions move.

WHAT WAS FOUND

The good news, and it is genuine. No yacht in this group is reachable from the internet. 213 searches across every hull identifier returned nothing attributable to any yacht, so the vessels themselves are not exposed. 12 of the 129 entries are clean altogether, and 33 of the 72 company domains do reject mail in their own name.

Why impersonation works so easily. 75 brokerage and management firms were assessed on their own websites. They publish 183 named staff and 292 email addresses, and for 50 of those addresses the naming pattern is confirmed against a real person on the same site. That is the material needed to make an email from a colleague look real. None of it is a breach. All of it is public, and all of it is usable.

One honest limit. Only 16 of the 128 entries assessed could be checked against a domain belonging to the owner or manager side, because an owner's own companies and domains are not published. 112 had to be assessed through the exhibiting broker, and a broker is a route to an owner, not the owner.

What to do this week. Ask your management company to confirm that mail claiming to come from their domain is rejected, not merely monitored. Confirm who can reach the published crew, payroll and owner portals, and that a second factor is required to sign in. Treat any payment, bank detail change, or charter instruction arriving by email as unverified until confirmed by voice on a known number.

The next step on our side. If you provide your entities and domains, the same method points directly at your estate, including the parts that are not published. That is the assessment this report is built to deliver.

Per-vessel detail, the sources behind each finding, and the full list of limits are on the method page. Leaked-credential exposure was not checked, because those records are commercial, so it is unassessed rather than clean.

What this found

How to read the bands

Where to go

Map

116 markers positioned from live AIS or calibrated quay medians, coloured by band, click-through per vessel.

open

Matrix

Every one of the 129 entries with its exposure classes, operator domain and screening status. Nothing omitted.

open

Findings

The exposure classes with the domain-level evidence behind each one.

open

Entities

Ownership and broker layer: who is behind the fleet, and what is published about them.

open

Red team

One constructed route from published information to an owner's money and instructions, anonymised, and the three controls that break it.

open

Method

Scope, sources, and the limits and gaps that must be read alongside every number here.

open