RED TEAM/ CONSTRUCTED SCENARIO / NOT A TEST

How the pieces fit together

An attacker does not need the yacht. Everything required to reach the people behind it is already published: 72 brokerage and management firms, 183 named staff, 288 work addresses, and 39 of the 72 company domains assessed do not reject mail sent in their own name. This is that route, walked step by step, from the published name to the owner's money and instructions. No vessel, company or person is named, and nothing in it was executed.

The chain, as an attacker would walk it

01

Choose a target, for free

Needs

A list of who is at the show and the organisations behind them.

Found

Both are published. The survey froze 129 entries from the official list, and every one of them names an exhibiting broker.

Stops it

Nothing. This is public by design, which is why the scenario starts here rather than with a technical step.

02

Aim at the intermediary, not the yacht

Needs

Someone the owner trusts, positioned to send an invoice or an instruction.

Found

112 of the 128 entries assessed could only be reached through the exhibiting broker, and 72 brokerage and management firms were assessed on their own websites. The intermediary is the exposed face of the transaction.

Stops it

Nothing at this step. The point is that the owner is reached through the firms around them, not through the hull.

03

Make the sender look internal

Needs

A name and an address that look like they belong inside the firm.

Found

Those 72 firms publish 183 named staff and 288 addresses, and for 50 of those addresses the naming pattern is confirmed against a real person on the same site, so a plausible address can be constructed for someone whose address is not published.

Stops it

Mail policy that rejects unauthenticated mail. 33 of the 72 company domains already do this, and for those the constructed sender does not deliver.

04

Send the instruction

Needs

Delivery from the firm's own domain, so the message survives a glance at the sender.

Found

39 of the 72 company domains do not reject mail in their own name, either publishing no policy or one that only monitors. A supplier invoice, a charter instruction, or a change of bank details arrives looking genuine.

Stops it

A reject policy, plus a rule that no change of bank details is acted on without voice confirmation on a known number.

05

Or use the portals instead of email

Needs

A sign-in page that leads into something worth having.

Found

28 owner-facing pages are published across 9 company domains and 13 respond, including crew portals, an owner portal, a charter platform and account sign-in pages. Some are named after the system behind them, such as payroll, which tells an attacker where to spend effort.

Stops it

A second factor on every published portal, and internal systems not named in publicly resolvable hostnames.

06

Take the vessel

Needs

Anything on board: a satellite terminal, a bridge system, a receiver.

Found

Nothing was found. 213 searches across every hull identifier returned nothing attributable to any yacht. The chain stops here, at the company and the people, not at the bridge.

Stops it

This boundary is a real result of the survey, not a reassurance. It is also the one part of the chain that cannot be fixed by the owner, because there is nothing to fix.

The three controls that break it

12 of the 129 entries produced nothing at all in this survey. That is the target state, and the three controls above are what it looks like in practice.