EPCYBER

EPCYBER - The Security Gap Between Luxury and Liability

Why Charter Brokers and Fleet Managers Are the New Frontline in Yacht Cybersecurity

A few months ago, we ran an exposure assessment on a charter yacht before the Med season. Within a few hours, we'd found the vessel's satellite panel, and two crew members' phone numbers and passwords sitting in breach databases — traced back to CVs they'd uploaded to crew agencies years ago. Findings like these prove once again that cybersecurity is not a priority in this industry, and people (crew) remain the weakest link in the chain, from social engineering to more technical attacks.

We see this regularly. Modern yachts are floating networks — VSAT terminals, CCTV, navigation, crew Wi-Fi, entertainment systems — yet most are managed with little attention to security. During one of our reconnaissance works, we identified over 50 live dashboards exposing crew information, voyage histories, and administrative panels not protected.

The industry is learning the hard way. In 2023, Lürssen shut down shipyard operations after a ransomware attack. Brunswick Corporation lost $85 million and nine days of global operations. In 2024, MarineMax disclosed that attackers stole data from over 123,000 customers and employees. 

Earlier this year, a coordinated attack took down satellite communications on 116 tankers belonging to a single state-owned fleet. Ship-to-shore links went dark. Internal crew communications failed. The attackers exploited vulnerabilities in VSAT terminals — the same systems found on yachts worldwide. One compromised service provider, and an entire fleet went silent. These aren't distant threats — they're hitting the builders, dealers, and infrastructure yacht owners depend on.

We're now hearing it directly from some clients. High-net-worth individuals and their security teams are asking questions like: Are the onboard cameras accessible from outside? What happens to our data after the charter? Brokers and managers who can't answer will start losing bookings to those who can. 

Traditional IT security firms often struggle here. Satellite communications, proprietary equipment, legacy controls, maritime frameworks — none of it fits standard corporate frameworks. This is why we built in our services offering a unique maritime practice around vessel-specific methods of exploitation and intelligence. Our assessments start across every connected system, technology and people. Looking ahead into 2026-2027 the vessels that stand out will be the ones that can show clients their privacy is protected, not just a promised luxury on paper.

Complimentary Digital Exposure Check Club Vivanova partners can request a confidential assessment of their personal or corporate digital footprint.

Explore maritime cybersecurity offerings

Email contact

LinkedIn

EPCYBER — founded in 2022 — is a recognized global leader in cyber intelligence training and services. Trusted by EU & U.S. government agencies and professionals from global firms across 50+ countries. We help intelligence teams gather and act on information from hard-to-access regions. We deliver services across industries — defense, oil & gas, banking, maritime — including penetration testing, cyber intelligence, and security assessments.

EPCYBER – The Digital Trails Executives Leave

EPCYBER – The Digital Trails Executives Leave

Executives and entrepreneurs today operate in a hyper-connected world where visibility is power — and exposure is the hidden cost. Yet most high-profile individuals aren’t compromised because their data was stolen; they’re compromised because their and their team's awareness was absent.

Luxury and leadership attract attention. But the same openness that builds reputation also creates opportunity — for those watching from the shadows. it’s not what’s already online that’s most dangerous — it’s what you and your tech unknowingly reveals.

Digital compromise starts with routine. With a predictable login, a repeated password, a shared calendar invite, or a photo that geotags your presence before you’ve left the room. These are the small, invisible exposures that adversaries weaponize.

At EPCYBER, we help leaders quietly audit their digital behavior. Our discreet assessments identify weak points that undermine even the best technology.

EPCYBER founded in 2022 – is a recognized global leader in cyber intelligence training and services. Trusted by world's largest Governments and employees of global firms in more than 50 countries. Helping government and intelligence teams gather and act on information from hard-to-access regions like China. Read more

Now we are finalizing the launch of RedRadar – World's first and only China-focused OSINT platform, exposing intelligence beyond any known scale or depth. RedRadar changes the intelligence gathering game, it surfaces hard-to-find intelligence artifacts using proprietary discovery methods. Investigations unfold automatically, revealing connections between obscure digital traces and internal documents that were never meant to be searchable. Read more

Our previous article: Hidden Digital Risks in Luxury Yachts  

Maritime Cybersecurity Services

➔ Discreet security checks available upon request  
➔ Complimentary digital exposure checks available for Club partners

Contact