What is GNSS spoofing?

17 July 2026 | John van Lopik

GNSS spoofing is a cyberattack in which a malicious party transmits false satellite signals to deceive a receiver about its actual location or time. The system believes it is receiving legitimate GPS or Galileo signals, but is in reality processing fabricated data. This makes GNSS spoofing more dangerous than ordinary signal interference: the device itself detects nothing wrong.

In 2026, the number of GNSS attacks is increasing worldwide, particularly around conflict zones and critical infrastructure. The consequences extend beyond navigation errors: time synchronization, financial transactions, and industrial processes can all be disrupted. In this article, we answer the most frequently asked questions about GNSS spoofing, from the technical mechanics to concrete protective measures.

How does GNSS spoofing work technically?

In a GNSS spoofing attack, an attacker transmits radio waves on the same frequencies as genuine satellite signals, but with a stronger or more precisely timed transmission. The receiver automatically selects the strongest signal and processes the false data as legitimate. This allows the attacker to make the receiver believe it is in a different location or that the time is incorrect.

The process typically unfolds in stages. First, the attacker closely tracks the real signal. Next, an identical but slightly offset signal is injected, which is then gradually shifted further from reality. The receiver barely notices the transition, because the deviation is built up incrementally. This is known as a meaconing attack: the receiver is, in effect, slowly steered away from its true position.

Modern GNSS receivers work with multiple satellite systems simultaneously, such as GPS, Galileo, and GLONASS. A sophisticated spoofing attack must replicate all of these systems at once, raising the technical barrier. Nevertheless, the required resources have become increasingly accessible, enabling non-state actors to carry out this type of attack as well.

What is the difference between GNSS spoofing and GNSS jamming?

GNSS jamming disrupts or completely blocks the satellite signal, preventing a receiver from determining its position or time. GNSS spoofing, by contrast, replaces the real signal with a false one, allowing the receiver to continue functioning but with incorrect data. Jamming is loud and easy to detect; spoofing is silent and dangerous precisely because it goes unnoticed.

With jamming, a system knows there is a problem: there is no signal. With spoofing, the system believes everything is working normally. This makes spoofing far harder to identify and potentially more damaging, especially in applications where the integrity of location or time data is critical.

Both attack types fall under the broader category of GNSS security risks, but require different countermeasures. Jamming calls for signal redundancy and alternative positioning sources. Spoofing requires active signal validation and authentication mechanisms.

Ready for the next step?

Explore our solutions or get in touch with one of our experts directly.

Ready for the next step?

Explore our solutions or get in touch with one of our experts directly.

Which sectors are most at risk from GNSS spoofing?

The sectors at greatest risk are those that depend on precise positioning or time synchronization for business-critical processes. These include aviation, maritime shipping, power grids, telecommunications, financial infrastructure, and transportation. A successful GNSS attack in these sectors can lead to serious operational disruptions or safety incidents.

Transportation and maritime

Ships and aircraft rely on GNSS for navigation. Spoofing can cause a vessel to navigate toward an entirely incorrect position, with dangerous consequences in busy shipping lanes or during port operations. In aviation, spoofing attacks can disrupt flight route calculations.

Energy and telecommunications

Power grids and telecommunications networks use GNSS for time synchronization of critical processes. Even a minor deviation in the time reference can cause protocol errors, network failures, or incorrect event logging. Financial institutions are equally vulnerable: transaction timestamps must be accurate for compliance and fraud detection purposes.

How can you detect GNSS spoofing?

Detecting GNSS spoofing requires active monitoring of signal characteristics. Indicators include a sudden position jump, inconsistent signal strengths from multiple satellites, deviations in the received time reference, and implausible Doppler shifts. A single indicator is not always conclusive, but a combination of anomalies strongly suggests an attack.

Technical detection methods include:

  • Multi-constellation verification: by comparing multiple satellite systems simultaneously, inconsistencies become visible that would not occur during genuine signal reception.
  • Signal strength analysis: false signals are often unnaturally strong or display a different strength pattern than authentic satellite signals.
  • Inertial navigation systems (INS): by comparing GNSS data with data from accelerometers and gyroscopes, deviations can be identified.
  • Time comparison with alternative sources: if the GNSS time reference diverges from an independent source, this is an indicator of possible manipulation.
  • Antenna position verification: a fixed installation that suddenly reports a different position is a direct indication of spoofing.

Advanced receivers include built-in spoofing detection algorithms. Even so, external monitoring and network management remain essential for a complete picture, as attacks continue to grow more sophisticated.

What measures protect against GNSS spoofing?

Effective protection against GNSS spoofing combines multiple layers: signal validation, redundant time sources, hardware adaptations, and organizational measures. No single measure provides complete protection on its own; a layered approach is the standard in critical environments.

The most effective measures are:

  1. Multi-band and multi-constellation receivers: receivers that simultaneously process multiple frequencies and satellite systems are more difficult to spoof all at once.
  2. Galileo OSNMA: Galileo’s Open Service Navigation Message Authentication protocol provides cryptographic verification of satellite signals, enabling false signals to be identified.
  3. Redundant time synchronization: by linking time references to alternative sources such as synchronization via fiber optic infrastructure, time accuracy is maintained even if GNSS fails or is compromised.
  4. Directional antennas: antennas that only accept signals from the direction of the sky reduce susceptibility to ground-based spoofing transmitters.
  5. Real-time anomaly detection: continuous monitoring of signal characteristics and time deviations enables a rapid response in the event of an attack.
  6. Physical security of receivers: protecting GNSS antennas against physical tampering or replacement is a frequently underestimated but relevant measure.

For organizations that depend on accurate time data, combining GNSS validation with an independent time source is the most robust approach. This ensures business continuity is maintained even during an active attack.

How we help with GNSS security and time synchronization

We understand that reliance on GNSS signals poses a real risk for organizations in sectors such as transportation, energy, telecommunications, and critical infrastructure. That is why we offer end-to-end solutions that ensure both the reliability and integrity of time synchronization and positioning.

Specifically, we can help you with:

  • Advanced multi-band GNSS receivers with built-in spoofing and jamming detection
  • Redundant time synchronization via fiber optic infrastructure as a backup for GNSS signals
  • Validation and monitoring of time signals to identify deviations at an early stage
  • Advice and design of a layered GNSS security strategy, tailored to your sector and risk profile
  • End-to-end support from implementation to ongoing management, backed by more than 20 years of expertise in network infrastructure

Would you like to know how vulnerable your infrastructure is to GNSS spoofing, or do you have questions about the right security approach? Contact us and we will be happy to help.

Ready for the next step?

Explore our solutions or get in touch with one of our experts directly.

Smart Connections for Your Organization

Would you like to learn more about what we can do for your IT organization? Our experts would be happy to help!