RED TEAM/ CONSTRUCTED SCENARIO / NOT A TEST
How the pieces fit together
An attacker does not need the yacht. Everything required to reach the people behind it is already published: 72 brokerage and management firms, 183 named staff, 288 work addresses, and 39 of the 72 company domains assessed do not reject mail sent in their own name. This is that route, walked step by step, from the published name to the owner's money and instructions. No vessel, company or person is named, and nothing in it was executed.
- This is a reconstruction, not a finding. Every ingredient is a class of exposure the survey verified, but the sequence is assembled to explain why those classes matter. It is never counted as evidence and it adds no entry to any band.
- Nothing was contacted. The survey is passive throughout, and this scenario adds no step that was performed against any system.
- Anonymised deliberately. Where the survey found a specific case, it appears here by shape alone. Naming the yacht would name its owner, and this page is about method, not about a victim.
- The purpose is the opposite of an attack plan. Six phases are described so that the three controls at the end can be shown to be sufficient. A step with no countermeasure is stated as having none.
The chain, as an attacker would walk it
Choose a target, for free
A list of who is at the show and the organisations behind them.
Both are published. The survey froze 129 entries from the official list, and every one of them names an exhibiting broker.
Nothing. This is public by design, which is why the scenario starts here rather than with a technical step.
Aim at the intermediary, not the yacht
Someone the owner trusts, positioned to send an invoice or an instruction.
112 of the 128 entries assessed could only be reached through the exhibiting broker, and 72 brokerage and management firms were assessed on their own websites. The intermediary is the exposed face of the transaction.
Nothing at this step. The point is that the owner is reached through the firms around them, not through the hull.
Make the sender look internal
A name and an address that look like they belong inside the firm.
Those 72 firms publish 183 named staff and 288 addresses, and for 50 of those addresses the naming pattern is confirmed against a real person on the same site, so a plausible address can be constructed for someone whose address is not published.
Mail policy that rejects unauthenticated mail. 33 of the 72 company domains already do this, and for those the constructed sender does not deliver.
Send the instruction
Delivery from the firm's own domain, so the message survives a glance at the sender.
39 of the 72 company domains do not reject mail in their own name, either publishing no policy or one that only monitors. A supplier invoice, a charter instruction, or a change of bank details arrives looking genuine.
A reject policy, plus a rule that no change of bank details is acted on without voice confirmation on a known number.
Or use the portals instead of email
A sign-in page that leads into something worth having.
28 owner-facing pages are published across 9 company domains and 13 respond, including crew portals, an owner portal, a charter platform and account sign-in pages. Some are named after the system behind them, such as payroll, which tells an attacker where to spend effort.
A second factor on every published portal, and internal systems not named in publicly resolvable hostnames.
Take the vessel
Anything on board: a satellite terminal, a bridge system, a receiver.
Nothing was found. 213 searches across every hull identifier returned nothing attributable to any yacht. The chain stops here, at the company and the people, not at the bridge.
This boundary is a real result of the survey, not a reassurance. It is also the one part of the chain that cannot be fixed by the owner, because there is nothing to fix.
The three controls that break it
- Reject unauthenticated mail on every domain in the group, and enforce it rather than monitor it. This closes phase 3 and phase 4 together. 33 of the 72 company domains assessed already do this.
- Put a second factor on every published portal, and stop naming internal systems in hostnames that resolve. This closes phase 5. It addresses the 13 owner-facing pages that respond today.
- Act on no change of bank details or instructions without voice confirmation on a known number. This is the control that survives the other two failing, and it costs nothing.
12 of the 129 entries produced nothing at all in this survey. That is the target state, and the three controls above are what it looks like in practice.