Phishing on yachts is rarely just a fake bank email. It may look like an owner instruction, charter guest request, supplier invoice, marina payment link, delivery message, crew travel update, cloud-file share, QR code, WhatsApp request or urgent password reset.

The strongest attacks use yacht pressure: the owner wants it now, the charter starts tomorrow, the part is stuck in customs, the marina needs payment, the guest wants privacy, or the supplier says a remote tool must be installed before support can continue.

A good drill teaches crew to pause, verify and report. It should not embarrass people. The goal is to build a habit that protects owner privacy, crew data, supplier payments, yacht operations and management systems.

Why Yachts Are Good Targets

Yachts combine wealth signals, travel pressure, changing crew, many suppliers and high-trust communication. Attackers can exploit urgency: owner arriving, guest itinerary change, spare part needed, customs document, fuel payment, crew flight, AV fault, or captain approval.

The crew may also use personal phones for work coordination. That creates more channels for social engineering: email, SMS, WhatsApp, Signal, social media, QR codes and voice calls.

This makes yacht phishing more personal than generic corporate phishing. The attacker may copy real supplier language, refer to a cruising location, spoof a manager, imitate a captain, or use details from social media and charter movements.

Drill Objective

The drill should test three behaviours:

  1. Does the crew recognize suspicious signals?
  2. Does the crew resist clicking, paying or sharing information?
  3. Does the crew report quickly through the right channel?

CISA's public guidance uses a simple pattern: recognize, resist and report or delete. For yachts, add one more: verify through an independent route before acting on money, credentials, itinerary, owner privacy or system access.

The drill should reward reporting, not punish mistakes. A crew member who clicks and reports within two minutes gives the yacht a chance to contain the incident. A crew member who hides the mistake creates a bigger problem.

Scenario Ideas

Use realistic yacht scenarios:

  • Fake supplier invoice with changed bank details.
  • Message claiming to be from the owner asking for guest passport copies.
  • Cloud-link request for crew certificates.
  • QR code for marina Wi-Fi login.
  • WhatsApp message from a "captain" asking the purser to pay a vendor.
  • Fake package-delivery link during refit.
  • Email asking an engineer to install a remote support tool.
  • Password reset message for the yacht-management portal.
  • Charter guest request for Wi-Fi credentials.

Keep the first drill simple. The objective is not to build a military exercise; it is to make reporting normal.

Rotate scenarios by department. Interior teams may see guest, privacy and payment lures. Engineering may see remote-support and parts lures. Deck may see marina, customs, fuel and delivery lures. Senior crew may see owner, management and invoice lures.

Before The Drill

Tell crew that cyber drills will happen and that the purpose is learning. Provide a reporting route: email alias, helpdesk, captain, purser, ETO or IT provider. Make clear that fast reporting is valued, even if someone clicked.

Prepare a short checklist:

  • Do not click suspicious links.
  • Do not open unexpected attachments.
  • Do not send passwords or MFA codes.
  • Verify payment or bank changes by phone using known contacts.
  • Verify owner or management requests through established channels.
  • Report suspicious messages quickly.
  • Preserve the message if asked by IT.
During The Drill

Send one controlled test message or run a tabletop discussion using screenshots. Track what happens:

  • Who reports?
  • Which channel do they use?
  • Does anyone click?
  • Does anyone forward the message to others?
  • Does anyone verify independently?
  • Does the reporting route work?

For small crews, a tabletop may be better than a surprise test. It allows discussion of real yacht scenarios without creating distrust.

For the first run, a tabletop is often enough. Show three examples and ask the crew what they would do. That conversation may expose unclear supplier verification, weak payment controls or overreliance on personal messaging.

After The Drill

Run a short debrief:

  • What made the message suspicious?
  • What verification route should be used?
  • What would the first containment step be if someone clicked?
  • Who needs to be told?
  • Which procedure or contact list needs updating?

Record the drill in the SMS or training log. If the drill exposes weak reporting routes, unclear supplier verification or overuse of personal messaging, create corrective actions.

The debrief is where the value is created. The drill should leave the yacht with one or two better habits, such as a known payment-verification route, a clear report button, a no-blame click-report rule, or a supplier bank-detail change procedure.

What To Measure

Useful measures include:

  • Percentage of crew who reported.
  • Time from delivery to first report.
  • Number of clicks or replies.
  • Number of independent verifications.
  • Whether the captain/manager was informed correctly.
  • Whether the incident route worked.

Do not use the drill to shame people. A quiet crew is more dangerous than a crew that reports mistakes quickly.

A Simple No-Blame Script

Use plain language onboard:

"If something looks wrong, report it. If you clicked, report it faster. Nobody gets blamed for reporting quickly. The risk is staying silent."

That message is more useful than a long cyber policy that crew only see during induction.

Common Mistakes
  • Making phishing training a once-a-year video.
  • Punishing clicks so crew hide mistakes.
  • Ignoring WhatsApp, QR codes and voice calls.
  • Training only junior crew while senior crew handle money and owner requests.
  • Failing to verify supplier bank-detail changes.
  • Not recording lessons learned.
References