Skip to main content

Do I need to change my Yacht Week password?

Yacht Week account passwords were not among the data copied. Why some notices still advised a change, and the one case where it matters.

Yacht Week account passwords were not among the data copied. The table holding them was never accessed.

This is the one point where the Yacht Week answer differs from the Ski Week answer. If you hold accounts with both, this page applies to your Yacht Week account — Ski Week passwords were copied, and that answer is in its own help centre at help.theskiweek.com.

Why some notices recommended changing it anyway

Some Yacht Week notices said your password was not involved and left it there. Others added that changing it would be a sensible precaution. Both statements rest on the same fact, and if you received the shorter version nothing has been withheld from you.

The precaution is worth taking for one reason: if you reuse the same password on other services, those services are the risk, not this one. Whoever holds the data taken here knows your email address and real details of your travel, which is exactly what makes a credential-stuffing attempt or a convincing scam message possible elsewhere.

If you were a Yacht Week skipper or crew member

This is the case that catches people out.

When Quarterdeck was set up to manage the people working our trips, existing Yacht Week skipper accounts were moved across to it. If you skippered or crewed for Yacht Week — particularly some years ago — your record is likely to be a Quarterdeck one, and the Quarterdeck position on passwords is different from the Yacht Week position above.

If that applies to you, write to us and say so, and we will check your specific record rather than give you the general answer.

How we will never contact you

We will never email you an unsolicited password reset link, and we will never ask you for your password, card details or bank details. If a message claiming to be from us does either of those things, it is not from us. Do not reply to it and do not click anything in it.

We are also not making outbound phone calls about this incident, so any call claiming to be us about it is not us.

Did this answer your question?