On February 28, 2026, within hours of U.S. and Israeli strikes on Iran, more than 1,100 commercial vessels in the UAE, Qatari, Omani, and Iranian waters simultaneously lost reliable GPS positioning. Their navigation systems did not go blank. They continued to display confident, precise positions, positions showing vessels traveling over land, parked on the tarmac at Al Hamra Airport, moored alongside the Barakah Nuclear Power Plant, and tracing perfect geometric circles in the waters off the UAE coast (Windward AI, 2026; OCCRP, 2026). None of these positions was real. All of them were generated by GPS jamming and spoofing signals that overrode legitimate satellite transmissions across one of the world’s most congested maritime corridors. Traffic through the Strait of Hormuz, the chokepoint carrying 20% of the world’s oil and gas, slowed as vessels attempted to reconcile what their instruments displayed with what their officers could see through the bridge windows (Windward AI, 2026). In one documented incident that captured the specific physical danger at stake, the intervention of a human navigator cross-checking radar bearings against GPS data in time to prevent a collision was the only thing that separated a near-miss from a casualty. This is not a cybersecurity story in the conventional sense of compromised servers and stolen data. It is a story about a navigation vulnerability baked into the foundational design of civilian GPS signals, one that produces not data theft but physical catastrophe, and that the geopolitical escalation of 2025 and 2026 has transformed from an acknowledged theoretical weakness into a routine operational hazard affecting tens of thousands of vessels annually. More than 24,000 vessels were affected by GNSS interference globally across 2025. Since February 2026 alone, more than 1,650 disruptions have been recorded in the Gulf region (Kpler, 2026). This essay examines what spoofing and jamming actually are at the engineering level, who is doing it and why, what it means for maritime insurance liability, and why the definitive protection against a falsified digital signal is the irreplaceable human skill of dead reckoning.
The Global Positioning System was designed in the 1970s as a military navigation tool and subsequently opened to civilian use without the security architecture that military GPS signals carry. The civilian GPS L1 C/A signal, the signal that every commercial vessel’s navigation receiver, every smartphone, and every autonomous system uses, broadcasts its position data in clear text, without encryption and without any mechanism for a receiver to verify that the signal is genuine (GPS World, 2026). A legitimate GPS satellite broadcasts its signal from an orbital altitude of approximately 20,200 kilometers, and by the time that signal reaches a receiver at sea level, it has attenuated to roughly 20 watts below the noise floor, weaker than a car key fob at 10 meters (Inside GNSS, 2026). Overriding it requires only a transmitter powerful enough to broadcast a fake signal above the noise threshold, a feat achievable with commercially available hardware costing a few thousand dollars. As Dr. Ramsey Faragher of Cambridge University has characterized it with precision borne of decades of PNT research: civilian GPS signals are “easy to overpower”, a technical reality that the navigation systems industry has known for decades and that has become impossible to ignore now that state actors and their proxies are exploiting it systematically (Inside GNSS, 2026).
Jamming and spoofing are distinct threats that produce different operational signatures and different legal consequences. Jamming — broadcasting radio frequency interference that overwhelms legitimate satellite signals — is comparatively crude: receivers lose lock, display a warning or blank screen, and navigators know they have lost GPS. It is detectable, its effects are obvious, and its geographic source can be triangulated if the right monitoring infrastructure is in place. The GPSPatron and Gdynia Maritime University research team that deployed a sophisticated interference detector aboard the research vessel Imor in Baltic waters between June and October 2025 confirmed this directly, detecting Kaliningrad-origin jamming signals affecting navigation across a broad maritime zone and establishing that the interference came from “a tactically-controlled network” operating deliberately rather than accidentally (Maritime Executive, 2025). Spoofing is fundamentally more dangerous because it is invisible. A spoofing transmitter does not overwhelm the GPS signal. It replaces it with a counterfeit that the receiver accepts as genuine, displaying a confident, plausible position that is entirely fabricated. The receiver shows no warning. The bridge equipment appears to function normally. The vessel is navigating on fiction (Chaifry, 2026). The GPSPATRON cumulative analysis of 2025 maritime interference documented the characteristic spoofing signature that distinguishes it from simple jamming: multiple vessels in the same area simultaneously converging on a single false position, often inland, often at a fixed point that represents wherever the spoofing transmitter’s fake coordinates are broadcasting, a tell that is obvious in retrospect but can be ambiguous in real time aboard a vessel whose navigator trusts the instruments they were trained to rely on (GPSPATRON, 2025).
The maritime GNSS interference crisis of 2025 and 2026 has two primary geopolitical architects operating in distinct geographic theatres with distinct but related strategic motivations.
In the Baltic and North Sea, the source is Russia, operating primarily from the Kaliningrad exclave, the Russian-administered territory on the Baltic coast surrounded by NATO member states, and from installations in the St. Petersburg region (Grey Dynamics, 2026). The Springer Nature academic analysis of Baltic GNSS interference published in March 2026 documented spoofing signals detected in April through June 2025 near the Polish maritime boundary with Kaliningrad, with the same spoofed position and time broadcast continuously for multiple days, indicating a persistent, deliberately operated spoofing infrastructure rather than an incidental byproduct of military activity (Springer Nature, 2026). Latvia documented over 820 jamming incidents attributable to Russian activity by mid-2025. The European Commission announced plans to implement new anti-spoofing authentication services in September 2025. The International Telecommunication Union reviewed member state complaints, and the International Civil Aviation Organization threatened to refer Russia to its Assembly for potential violations of international law (Grey Dynamics, 2026). None of these measures stopped the interference. In January 2026, the fourteen coastal states of the Baltic Sea and North Sea — Belgium, Denmark, Estonia, Finland, France, Germany, Iceland, Latvia, Lithuania, the Netherlands, Norway, Poland, Sweden, and the United Kingdom — issued a joint open letter to the international maritime community declaring that GNSS interference and AIS manipulation were “increasing safety risks” and demanding action (Inside GNSS, 2026; Riviera Maritime Media, 2026). Safety4Sea’s analysis of the letter noted that “precise figures are not available” on the full scale of Baltic interference, but that AIS data confirmed “particularly heavy spoofing activity in areas around Kaliningrad and St. Petersburg,” and that multiple indicators suggested both the scale and persistence of such interference had “grown markedly” compared to previous years (Safety4Sea, 2026).
In the Persian Gulf, the interference environment is more complex and more immediately dangerous. The Windward AI analysis, published March 1, 2026, the morning after Operation Epic Fury began, documented the immediate impact: 1,100 vessels disrupted within 24 hours, 21 new AIS jamming clusters identified across UAE, Qatari, Omani, and Iranian waters, and vessel signals appearing at airports, a nuclear power plant, and deep within Iranian territory (Windward AI, 2026). Windward’s senior maritime intelligence analyst Michelle Wiese Bockmann described the situation in the Strait of Hormuz as “extremely dangerous for maritime navigation”, a statement that warrants no qualification given the corridor’s combination of heavy traffic, shallow and constrained channel geometry, and the precise navigation requirements for tankers of 200,000 tons or more (OCCRP, 2026). The GPSPATRON cumulative 2025 analysis had already documented the June 2025 escalation, more than 3,000 vessels disrupted in the Persian Gulf and Strait of Hormuz within less than two weeks, establishing that the Gulf interference was not a February 2026 phenomenon but an accelerating trend whose pace of escalation tracked directly with the regional military conflict tempo (GPSPATRON, 2025).
The most consequential practical dimension of the GPS/GNSS spoofing threat for maritime operators, and the one most inadequately addressed in industry guidance, is what happens to insurance coverage and legal liability when a vessel grounds or collides while navigating on falsified positioning data. The answer depends critically on a distinction that most operators, and many claims handlers, do not yet consistently apply: whether the incident was caused by active AIS manipulation by the vessel itself or by passive GNSS interference affecting all vessels in the area simultaneously.
Kpler’s April 27, 2026, analysis of marine underwriting implications, the most current and specific treatment of this question available in the industry literature, establishes the legal geometry precisely. Where a vessel has been actively manipulating its own AIS transmissions to broadcast false positions for sanctions evasion or identity concealment, and that manipulation contributes to a collision or grounding, Section 55(2)(a) of the Marine Insurance Act 1906 provides the insurer with grounds to void coverage entirely: deliberate position manipulation constitutes willful misconduct of the assured, and loss attributable to willful misconduct is excluded from cover (Kpler, 2026). The practical consequence is devastating for an operator whose vessel is actively spoofing. Not only are they potentially facing a collision claim, but they are also facing it without insurance. Kpler’s analysis of sanctions data reinforces the exposure: 80% of vessels exhibiting active AIS spoofing behavior are designated under sanctions within twelve months, meaning that an underwriter who discovers active spoofing in a vessel’s AIS history faces compounding sanctions, coverage, and reputational risk simultaneously (Kpler, 2026).
The passive GNSS interference scenario, where a vessel is navigating in good faith on GPS data corrupted by external jamming or spoofing from a third party, presents a fundamentally different and considerably more complex legal picture. The Association of Average Adjusters’ 2025 discussion paper on GPS spoofing and Hull and Machinery insurance identified the specific ambiguity that claims handlers are now confronting: where a grounding occurs because a vessel was navigating on falsified GPS coordinates in a jamming environment, is the loss covered as a traditional maritime peril — a navigational error — or excluded under the cyber exclusion clauses that have become standard in H&M policies since 2019? (RNTF, 2025). The answer turns on whether the spoofing can be characterized as a “cyber attack”, a term that cyber exclusion clauses define inconsistently across policies, and whether the navigator’s failure to detect and cross-check the spoofed position constitutes a failure of seamanship that voids cover under the due diligence obligation (RNTF, 2025). The GPS World roadmap analysis captured the regulatory dimension: ICAO, the ITU, and the IMO issued a joint warning in March 2025 specifically addressing the security risks of GNSS interference to aviation and maritime navigation, establishing that the relevant international bodies now regard this as a known, foreseeable hazard that operators are expected to account for in their navigational planning (GPS World, 2026). A vessel that grounds in a documented jamming zone while relying solely on GPS without cross-checking alternative position sources may find that the insurer argues the loss was attributable to a failure to take reasonable navigational precautions against a foreseeable and publicly documented hazard.
The solutions to GPS/GNSS spoofing fall into two categories: technological countermeasures that reduce the vulnerability of the navigation system, and procedural countermeasures that rely on human judgment to detect and reject false data before it causes physical consequences. Both are necessary. Neither is sufficient alone.
On the technology side, the primary structural response to civilian GPS signal vulnerability is multi-constellation GNSS reception, using receivers that simultaneously track signals from multiple satellite navigation systems, including the U.S. GPS, European Galileo, Russian GLONASS, and Chinese BeiDou constellations (Chaifry, 2026). A spoofing transmitter targeting GPS L1 C/A signals does not simultaneously spoof all constellations, and a receiver that compares position data across multiple constellation inputs can detect discrepancies that indicate interference. The European Union’s Galileo system introduced the Open Service Navigation Message Authentication feature in July 2025, a cryptographic mechanism that allows receivers to verify that Galileo signals are genuine, but adoption in commercial maritime receivers remains limited because the feature requires updated hardware, and the vast majority of vessels currently at sea operate legacy receivers that do not support it (Grey Dynamics, 2026; GPS World, 2026). The IMO’s MSC Circular 1371 on multi-system shipborne radio navigation and the broader PNT resilience framework being developed by international bodies represent the regulatory architecture for requiring these capabilities, but as with every maritime technology mandate, the timeline from requirement to fleet-wide implementation spans years during which the threat continues undiminished.
The fourteen-nation joint letter’s invocation of SOLAS, MARPOL, and COLREGs — the foundational instruments of international maritime law — is not merely diplomatic boilerplate (Riviera Maritime Media, 2026). It is a statement that the existing legal framework already requires navigators to maintain safe navigation using all available means, and that GPS alone does not constitute “all available means” when the navigator has reason to suspect interference. The Admiralty chart, the radar bearing, the depth sounder, the celestial observation, and the terrestrial bearing are not archaic backup systems awaiting supersession by satellite navigation. They are the cross-checking infrastructure that enables a trained navigator to detect when digital instruments lie. Dead reckoning, the technique of calculating current position from a known last position using heading, speed, and elapsed time, does not depend on satellite signals. It cannot be spoofed by a transmitter in Kaliningrad or jammed by Iranian electronic warfare assets in the Strait of Hormuz. It is the foundational navigational skill that every professional mariner is trained in and that the industry’s increasing dependence on GPS automation has progressively devalued to the point where its routine application in high-risk environments has become exceptional rather than standard practice (Inside GNSS, 2026).
The UKMTO standing advisory on GNSS disruption in the Hormuz region captures the operational requirement with precision: maintain a continuous independent plot using radar bearings and depth soundings; treat GPS positions that cannot be confirmed by radar as suspect; report discrepancies immediately; and never allow a single-source navigation picture to govern vessel movement in a congested or restricted waterway (UKMTO, 2026). These are not novel recommendations. They are the bridge watchkeeping standards that existed before GPS, and the digitization of maritime navigation has caused many operators to treat them as optional enhancements rather than mandatory professional practice. The spoofing crisis is, among other things, a professional standards crisis, a consequence of institutional dependence on a technology whose vulnerability was always known and whose limitations are now being exploited at scale by adversaries who understand the maritime industry’s navigational culture better than many maritime operators understand their own exposure.
The GPS/GNSS spoofing crisis is not a temporary problem whose solution awaits the end of the current conflicts in the Middle East and Eastern Europe. Civilian GPS signals were architecturally vulnerable to spoofing and jamming long before the Russia-Ukraine war or the Iran conflict, and they will remain vulnerable long after those conflicts resolve, because the vulnerability is inherent in the unencrypted, unauthenticated design of the L1 C/A signal on which the entire global navigation infrastructure depends. What the geopolitical escalation of 2025 and 2026 has done is demonstrate, at operational scale, the physical consequences of that vulnerability for commercial maritime navigation: vessels appearing at nuclear power plants and airports, tankers making course corrections that bring them closer to shoals rather than away from them, collision risks generated not by mechanical failure or human error but by falsified digital data that the instruments display with perfect confidence. The fourteen-nation joint warning, the Association of Average Adjusters’ insurance coverage analysis, and Kpler’s liability distinction between active AIS manipulation and passive GNSS interference all point toward the same conclusion: the industry’s legal and insurance frameworks were designed for a navigation environment in which the instruments could be trusted. That environment no longer exists in the Baltic, the Persian Gulf, or any other maritime corridor where a state actor has decided to use electronic warfare against commercial traffic. The navigator who cross-checks GPS against radar, plots a dead reckoning position, and trusts the traditional skills that satellite navigation was meant to augment rather than replace is not demonstrating technological backwardness. They are demonstrating the only form of navigational resilience that no spoofing transmitter can defeat.
References
Association of Average Adjusters / RNTF. (2025, August 8). Maritime insurance coverage uncertainty due to GPS spoofing. https://rntfnd.org/2025/08/08/maritime-insurance-coverage-uncertainty-due-to-gps-spoofing-safety4sea/
Chaifry. (2026, January 29). GPS jamming, GNSS spoofing, and the race for resilient navigation in 2026. https://www.chaifry.org/gps-jamming-gnss-spoofing-resilient-pnt-2026
GPS World. (2026, March 30). How to defeat harmful GPS/GNSS interference: A roadmap for action. https://www.gpsworld.com/how-to-defeat-harmful-gps-gnss-interference-a-roadmap-for-action/
GPSPATRON. (2025, October 24). Maritime GNSS interference worldwide: A cumulative analysis 2025. https://gpspatron.com/maritime-gnss-interference-worldwide-a-cumulative-analysis-2025/
Grey Dynamics. (2026, January 6). Russian jamming and spoofing threatens the Baltics. https://greydynamics.com/russian-jamming-spoof/
Inside GNSS. (2026, January 27). Baltic and North Sea states warn on GNSS jamming, AIS spoofing, and shadow fleet risks. https://insidegnss.com/baltic-and-north-sea-states-warn-on-gnss-jamming-ais-spoofing-and-shadow-fleet-risks/
Kpler. (2026, April 27). AIS spoofing vs GNSS interference: Why the distinction decides the claim. https://www.kpler.com/blog/ais-spoofing-vs-gnss-interference-why-the-distinction-decides-the-claim
Maritime Executive. (2025, December 23). Study: Baltic GPS disruption comes from a tactically-controlled network. https://maritime-executive.com/article/study-baltic-gps-disruption-comes-from-a-tactically-controlled-network
OCCRP. (2026, March 5). More than 1,100 ships hit by widespread GPS disruption after Iran strikes. https://www.occrp.org/en/news/more-than-1100-ships-hit-by-widespread-gps-disruption-after-iran-strikes
Riviera Maritime Media. (2026, January 27). North Sea and Baltic states highlight spoofing and jamming in warning over Russian interference. https://www.rivieramm.com/news-content-hub/coastal-states-call-for-radionavigation-systems-as-gnss-alternative-87567
Safety4Sea. (2026, January 27). Coastal states warn of safety risks increased by GNSS interference. https://safety4sea.com/coastal-states-warn-of-safety-risks-increased-by-gnss-interference/
Springer Nature / GPS Solutions. (2026, March 14). Baltic Sea GNSS jamming and spoofing emitter detection and localization in real-time using a TDOA system. https://link.springer.com/article/10.1007/s10291-026-02061-5
UK Maritime Trade Operations. (2026, April 12). Update 031 to JMIC Advisory Note: 01 March – 12 April. https://www.ukmto.org/-/media/ukmto/products/update-031—jmic-advisory-note-12-april_final.pdf
Windward AI. (2026, March). GPS jamming disrupts 1,100 ships in the Middle East Gulf. https://windward.ai/blog/gps-jamming-disrupts-1100-ships-in-the-middle-east-gulf/