Electronic Warfare

How GPS Spoofing Walks a Receiver Off Its True Position

GPS spoofing broadcasts counterfeit satellite signals a receiver trusts over the real ones. How the capture and detection work, and what the law says.

GPS spoofing is the broadcast of fake satellite navigation signals that a receiver trusts as real. The device then reports a position or a time the transmitter picked, and shows no sign that anything went wrong. Ships have been steered off track this way, and aircraft crossing eastern Europe and the Middle East have logged false positions that also corrupted their onboard inertial navigation.

Jamming is the opposite attack. A jammer floods the same frequency with noise until the receiver loses its fix and says so, which how GPS jamming works covers in full. Spoofing hands the receiver a confident wrong answer instead.

How GPS Spoofing Captures a Receiver

A spoofer captures a receiver by transmitting a counterfeit copy of the satellite signal, aligned in time with the real one and slightly stronger. It then pulls that copy away from the truth. Nothing is broken along the way. The receiver keeps doing exactly what it was designed to do.

The capture works because the genuine signal is faint. Global Positioning System (GPS) satellites sit roughly 20,000 kilometers up in medium Earth orbit. By the time their broadcast reaches the ground it is weaker than the background radio noise around it, a distance effect covered in how satellites work. A receiver recovers that signal by matching the incoming radio against the exact code each satellite transmits and locking onto the best match. Whichever copy of that code matches most strongly is the one it tracks.

A spoofer exploits that rule in two stages:

  • Alignment. The counterfeit signal starts out matched to the real one, at almost the same power and the same arrival time. The receiver sees no change in its position, its clock, or its signal quality, because at this point the fake answer and the true answer agree.
  • Walk-off. The transmitter then shifts the timing of its copy by small amounts. Each shift moves the calculated position a short distance. The receiver follows, because it is tracking the strongest match and the strongest match is now moving.

The speed of the walk-off decides whether anyone notices. A fix that jumped hundreds of kilometers at once would look wrong to any crew watching it, so a patient spoofer moves the position no faster than the vehicle could plausibly travel. Researchers at the University of Texas at Austin demonstrated the technique at sea in 2013. From a yacht in the Mediterranean they broadcast faint counterfeit signals and gradually overpowered the authentic ones until the navigation system followed. The vessel physically turned, the crew felt the turn, and the chart display drew a straight line.

If the timing math is new to you, our explainer on how GPS finds your position covers it first.

Why a Spoofed Receiver Shows No Error

A standard civil GPS receiver cannot tell an authentic signal from a forged one, because the civil GPS signal carries no cryptographic signature for it to check. The receiver has only one test available: whether the signals it is tracking agree with each other. A spoofer that generates a full, self-consistent set of satellites passes that test every time.

That gap is why the usual integrity tools give false comfort. Receiver autonomous integrity monitoring (RAIM) compares the satellites in view and flags one that disagrees with the rest, which catches a failing satellite or a bad ephemeris. It does not catch a coherent spoof, since a coherent spoof has no outlier to find. The receiver is not being fooled by a bug. It is being handed a well-formed answer to the question it asked.

Electronic attacks of this kind sit at the reversible end of the counterspace range described in space warfare, a long way from anti-satellite weapons that destroy hardware. Nothing in orbit is touched. The satellites keep broadcasting normally, and the damage is done entirely on the ground, to the receiver.

The Documented Incident Record

The public record of GPS spoofing runs from thousands of logged merchant-ship incidents around Russia to a standing aviation advisory covering eastern Europe and the Middle East. Two organizations hold most of the primary evidence. Reports from crews go to the U.S. Coast Guard Navigation Center, and aviation guidance comes from the European Union Aviation Safety Agency (EASA).

Ships Reporting Positions They Were Not In

Research group C4ADS documented the maritime pattern in its 2019 report Above Us Only Stars. It identified 9,883 suspected spoofing instances across 10 locations, affecting 1,311 civilian vessel navigation systems since February 2016. The affected ships were logged in the Black Sea, the Gulf of Finland, the Mediterranean and the waters off Vladivostok. C4ADS traced the transmissions using publicly available vessel-tracking data alongside readings from a scientific GPS receiver aboard the International Space Station.

An electronic chart that places the vessel somewhere it is not will show clear water where there is a bank. It does so with the same confidence as a correct fix. That chart is the primary position reference on most bridges.

The Circle Pattern Reported at Chinese Ports

C4ADS also documented an unusual variant near the Port of Shanghai, in which affected vessels reported positions arranged in tight rings rather than at a single false point. Those reported tracks ran at speeds no ship in a harbor could reach. The pattern was reported in November 2019 by MIT Technology Review. Devices other than ship transponders were affected in the same area, which points to interference with the GPS signal itself rather than tampering with vessel reporting.

Aircraft Over Eastern Europe and the Middle East

EASA has kept a standing safety bulletin on GNSS interference since 2022. It issued Revision 4 on 3 July 2026, after a joint task force with EUROCONTROL analyzed recent occurrences. The bulletin lists the symptoms crews report when GNSS spoofing affects an aircraft:

  • Discrepancies between navigation positions from different sources.
  • Abnormal differences between ground speed and true airspeed.
  • Time and date shifts on board.
  • Spurious terrain awareness and warning system (TAWS) alerts, which pull crew attention to a terrain threat that is not there.
  • Deviations in hybrid inertial reference system and GNSS positions, meaning the aircraft’s inertial solution is dragged off by the corrupted satellite input it was blending in.

The inertial deviation outlasts the interference itself. An inertial reference system fed a false position stays wrong after the transmission stops, so an aircraft can leave the affected area still carrying the error. EASA names the Baltic, eastern Europe, the Mediterranean, the Black Sea and the Middle East as the affected regions in its bulletin on GNSS outages and alterations.

Anyone looking for a GPS jamming map of current conditions should treat the public heatmaps carefully. The Navigation Center states plainly that reports submitted to its GPS problem report status tool are user submissions it does not validate against the constellation. Its heatmap is representative rather than a survey of the areas actually affected.

How GPS Spoofing Detection Works

GPS spoofing detection works by comparing the GPS answer against something the transmitter does not control. Each available check catches a different class of attack, and each has a gap:

  • Signal strength and noise floor. A receiver that logs the power of what it is tracking can flag a jump above what a satellite 20,000 kilometers away could deliver. The check catches a crude transmitter running hot. It misses one that matches real signal power, which is the whole point of the alignment stage.
  • Timing and clock consistency. Comparing GPS time against a local oscillator catches a clock that jumps, which matters most for the timing customers that depend on GPS, such as power grids and financial networks. It misses a slow walk-off, because a drift of microseconds looks like ordinary oscillator error.
  • Angle of arrival. Two or more antennas a fixed distance apart can work out which direction each signal came from. Real satellites arrive from many bearings across the sky, and a single spoofing transmitter puts them all on one. Angle-of-arrival checking is the most decisive single test, and it costs an extra antenna, a rigid mounting baseline, and a receiver that can process both feeds.
  • Inertial cross-check. An inertial navigation unit measures acceleration and rotation without any radio input, so its error grows in a known way over time. When the GPS position and the inertial position diverge faster than that error budget allows, the GPS position is the suspect one. It misses a spoof slow enough to hide inside the drift.
  • Multi-constellation comparison. A receiver tracking Galileo, GLONASS and BeiDou alongside GPS can compare four independent solutions. Forging one constellation convincingly is far easier than forging four. The catch is that many receivers blend all constellations into a single fix rather than holding them apart, so a partial spoof can pull the blended answer without ever showing a disagreement.

One criterion runs through all five, and it decides whether a given defense is worth buying. Every check that reliably works compares GPS against a source that is not GPS. Anything that only inspects the satellite signals themselves can be satisfied by a transmitter willing to be patient and consistent.

What Operators Do to Blunt a Spoof

Operators reduce spoofing risk by adding an independent check on the GPS answer rather than by hardening the receiver alone. Five approaches are in service or in trial as of 2026.

DefenseWhat it checksWho can use itWhat it does not stop
Galileo OSNMACryptographic authenticity of the Galileo navigation messageAny civil user with a supporting receiverA replay of genuine signals, and any attack on other constellations
GPS M-codeEncrypted military signal with unpredictable spreading codesU.S. and allied military receivers onlyAny receiver without the keys, which means all civil aviation, shipping and industry
Multi-constellation receiverAgreement between four separate satellite systemsAnyone buying a modern receiverA spoof of several constellations, or a blended fix that hides the disagreement
Inertial navigation backupPosition drift against a radio-free referenceAircraft, ships and vehicles that can carry the hardwareA walk-off slow enough to stay inside the inertial error budget
Terrestrial systems such as eLoranA ground-transmitted position and time at far higher powerUsers inside a national transmitter network, where one existsAnywhere the network does not reach, which is most of the world
VerdictAuthentication verifies the data. Only an independent sensor verifies the position.Civil operators get the most from multi-constellation plus inertial.No single measure removes the risk on its own.

Signal authentication is the newest of the five. The European Union Agency for the Space Programme declared Galileo Open Service Navigation Message Authentication (OSNMA) operational in July 2025. Galileo became the first satellite navigation system to offer spoofing protection free of charge in its open service worldwide. A receiver that supports it can confirm that the navigation data it is using genuinely came from Galileo and was not altered. One limit is worth knowing before buying on the strength of it. OSNMA authenticates the message content, so a receiver still needs its own timing and consistency checks to resist a transmitter that simply rebroadcasts real signals with a delay.

Military users have had encrypted signals for longer. The U.S. Space Force, which operates GPS, is fielding M-code as part of the GPS modernization program, using encrypted spreading codes that a transmitter cannot generate without the keys. Equipped military receivers therefore cannot be walked off by a forged signal. The airline, the container ship and the power utility get nothing from it, because none of them can hold those keys.

Terrestrial backup covers the remaining gap differently. The U.S. Department of Transportation tested eLoran and other candidates in its complementary PNT and GPS backup technologies demonstration report to Congress. A high-power ground transmitter is far harder to overpower than a signal that has traveled from medium Earth orbit. Deployment remains limited, so eLoran helps only crews operating inside a national network that has actually been built.

Who These Defenses Do Not Serve

None of the five reaches a driver, a hiker or a small delivery fleet, because each assumes hardware or keys a consumer device does not carry. For that group the practical response is behavioral. Three habits cover most of it:

  • Treat a position that jumps, a clock that shifts, or a route instruction that contradicts what is visible through the windshield as a fault rather than a fact.
  • Navigate by road signs and landmarks until the fix settles again.
  • File what happened through the Navigation Center’s GPS problem report status tool, which is how a private oddity enters the public record.

What Would Change This Picture

Two developments would change the answer above. The first is authenticated civil signals reaching mass-market chipsets by default, which would move OSNMA-style protection from a specialist purchase into ordinary phones and car navigation. The second is a spoofing capability that routinely forges several constellations at once. That would strip most of the value from the multi-constellation check and push operators back onto inertial and terrestrial references. Tracking who is transmitting, and from where, is part of the sensing work covered in space domain awareness.

Is GPS Spoofing Illegal

Transmitting counterfeit GPS signals is illegal in the United States, and the equipment used to do it cannot be authorized for sale or operation at all. The Federal Communications Commission (FCC) bases that on three sections of the Communications Act, set out on its jammer enforcement page:

  • Section 301 requires anyone operating a radio transmitter to hold a license or authorization, which a spoofing transmitter cannot obtain.
  • Section 302(b) bars the manufacture, importation, marketing, sale and operation of signal jamming devices inside the United States.
  • Section 333 prohibits willful or malicious interference with any radio station licensed or authorized under the Act, or operated by the U.S. government, which covers GPS directly.

The FCC’s stated reasoning is that jamming and spoofing equipment cannot be certified the way ordinary transmitters are, because interfering with radio communications is the entire function of the device. Enforcement runs to monetary forfeitures and, under Section 501, criminal sanctions. The offense attaches to transmitting rather than to receiving, so a mariner whose chart plotter was fooled has broken nothing.

Outside the United States the rules come from each country’s own spectrum regulator, and they differ in detail rather than in direction. Military use in an armed conflict sits under a separate legal frame again, which is why interference around conflict zones persists while civilian jammer sales are prosecuted. For a specific national rule, the ITU’s directory of national spectrum regulators lists the authority that licenses radio transmitters in each country.

Crews and operators who suspect GPS spoofing should compare the satellite position against an inertial or ground-based fix before acting on it. Then file the event through the Navigation Center’s GPS problem report status tool, which turns a single odd reading into the record everyone else navigates by.

Frequently asked questions

What is GPS spoofing?

GPS spoofing is the broadcast of counterfeit satellite navigation signals that a receiver accepts as genuine, so it reports a position or a time chosen by whoever is transmitting. The forged signals copy the structure of the real ones and arrive slightly stronger, so the receiver locks onto them without flagging a problem. It is the deceptive half of satellite navigation attack. The denial half is GPS jamming, which floods the frequency with noise until the receiver reports no fix at all.

Is GPS spoofing illegal?

Yes, in the United States. The Federal Communications Commission does not certify equipment whose purpose is to interfere with radio communications, and its jammer enforcement page cites Sections 301, 302(b) and 333 of the Communications Act, which cover unlicensed transmission, the manufacture and sale of jamming gear, and willful interference with licensed or government radio. Penalties run to monetary forfeitures and criminal sanctions. Other countries set their own rules through their own spectrum regulators, and military use in conflict falls under a separate legal frame.

Can GPS spoofing be detected?

Yes, though no single check catches every case. Detection works by comparing the GPS answer against a source the transmitter does not control: an inertial navigation unit, a second antenna that measures which direction a signal arrived from, an independent clock, or another satellite constellation. A crude spoof that runs too hot or jumps the clock is caught quickly. A patient one that starts matched to the real signal and drifts slowly is the hardest to spot, because every reading stays internally consistent.

How to avoid GPS spoofing?

Keep at least one position or time source that does not come from GPS. For aircraft and ships that means inertial navigation, ground-based aids and radar fixes, plus a habit of comparing the satellite position against them rather than trusting it. Crews can check advisories before entering affected airspace or water through the EASA bulletin on GNSS outages and alterations and the GPS problem report status tool. A receiver that tracks several constellations and supports Galileo signal authentication raises the effort a spoofer has to spend.

Will aluminum foil block a GPS tracker?

Wrapping a receiver in metal foil can stop it getting a fix, because foil is a shield that blocks the incoming signal rather than a transmitter that fakes one. That is blocking, and it is the opposite of spoofing: the device reports nothing instead of reporting a convincing lie. Foil is also unreliable in practice, since a small gap lets enough signal through. A tracker that reports over a mobile network needs that link blocked too, and any obligation attached to a court-ordered or employer-issued tracker is a separate matter from radio physics.

How to tell if someone is spoofing their location on Google Maps?

There is no reliable way to confirm it from the receiving end, because Google Maps shows the position a phone's software reports rather than a signal you can inspect yourself. Location spoofing on a phone is a software substitution rather than a radio broadcast, so no counterfeit satellite signal is involved at all. The usual signs are a position that jumps a long distance instantly, one that sits perfectly still for hours, or a reported accuracy that stays implausibly tight. Treat shared phone location as a convenience rather than proof of where someone is.