MYS 2026/ PORT HERCULE, MONACO / 23-26 SEPTEMBER 2026
Vessel exposure assessment
Passive, outside-in screening of the fleet and the organisations behind it. The question addressed: exposed digital assets, or sensitive information on the internet, usable to attack or spear-phish an owner.
Executive summary
What this is. Every yacht on the official Monaco Yacht Show 2026 list, 129 of them, was frozen as a group and looked at from the outside using ShipCrawler, the vessel intelligence framework, adapted here for yachts. Only what is already public was used: domain records, mail settings, certificates, and the public internet index. Nothing was scanned, probed or connected to, so nothing on board was touched.
The risk in one line. The practical way to reach an owner is not through the yacht. It is by impersonating someone the owner trusts, at the moment money or instructions move.
WHAT WAS FOUND
- Mail that claims to come from a company is not rejected at 39 of the 72 company domains assessed. A supplier invoice, a charter instruction, or a request for payment can arrive looking genuine. This matters most, because it needs no technical skill to use.
- The two cases closest to an owner. One yacht's registered owner entity has no mail protection at all, so mail in its name is delivered without challenge. A management company overseeing four yachts in this group publishes a crew portal and a payroll system, and only monitors its mail, so a message impersonating the company is not stopped.
- 28 owner-facing pages are published across 9 company domains, including crew portals, an owner portal, a charter platform and account sign-in pages. 13 respond. Some are named after the systems behind them, such as payroll.
- 9 yachts are linked to an old file-transfer service still reachable on the company's own address. Old services are usually unpatched and unmonitored.
- 82 of the 129 entries miss basic browser protections on their company domains. That is a hardening gap rather than an open door, which is why it is listed last.
The good news, and it is genuine. No yacht in this group is reachable from the internet. 213 searches across every hull identifier returned nothing attributable to any yacht, so the vessels themselves are not exposed. 12 of the 129 entries are clean altogether, and 33 of the 72 company domains do reject mail in their own name.
What this found
How to read the bands
- Band A (E1 / E2). Either the operator's domain cannot be protected by DMARC, so mail claiming to be from them is not rejected, or internal and non-production hostnames are published in certificate transparency and resolve. This is the band that makes a targeted message possible.
- Read the band-A count with care. For entries with no IMO of their own, the band is inherited from the exhibiting broker rather than measured on the owning company, so one large broker with a spoofable domain pulls every yacht it presents into band A. It reflects the exposure of the party presenting the yacht, which is what an attacker would impersonate, but it is not 92 independently exposed owners.
- Band B (E3). End-of-life software versions, or plaintext FTP reported on the address.
- Band C (E4). Missing HSTS or content security policy. Hygiene, listed for completeness, not a vulnerability.
Where to go
Map
116 markers positioned from live AIS or calibrated quay medians, coloured by band, click-through per vessel.
openMatrix
Every one of the 129 entries with its exposure classes, operator domain and screening status. Nothing omitted.
openFindings
The exposure classes with the domain-level evidence behind each one.
openEntities
Ownership and broker layer: who is behind the fleet, and what is published about them.
openRed team
One constructed route from published information to an owner's money and instructions, anonymised, and the three controls that break it.
open