ocean · digital · transport · family: built to be open. now under attack
ships trust position data from strangers
Ship navigation systems accept unverified position data that can be spoofed from shore
Problem statement
The core navigation and identification systems on commercial vessels — Automatic Identification System (AIS), Electronic Chart Display and Information System (ECDIS), and GPS — accept inputs without cryptographic verification, enabling spoofing, manipulation, and denial-of-service attacks. AIS broadcasts vessel identity, position, speed, and course on unencrypted, unauthenticated VHF channels, so an attacker with an inexpensive software-defined radio can inject fake vessels, alter real vessel positions, or create ghost collision threats — attacks demonstrated end-to-end against both the protocol and online AIS providers by Balduzzi et al. (2014). GPS signals are weak enough to be overpowered by portable transmitters, and GPS spoofing affecting commercial shipping has been documented in the Black Sea, Eastern Mediterranean, and Persian Gulf (U.S. Maritime Advisory 2020-016) — most prominently in June 2017, when some 20 ships near Novorossiysk reported GPS positions clustered at Gelendzhik Airport, roughly 25 nautical miles inland; C4ADS (2019) documented nearly 10,000 spoofing instances affecting over 1,300 vessels in and around Russian waters. ECDIS systems that overlay AIS and GPS data on electronic charts inherit these vulnerabilities, meaning the integrated navigation picture displayed to bridge officers can be manipulated.
Why this matters
Over 80% of global trade by volume moves by sea (UNCTAD), and maritime navigation depends on GPS and AIS for collision avoidance, traffic management, and regulatory compliance. A successful AIS spoofing attack could cause collisions between vessels, ground ships by displaying false chart data, or make vessels invisible to traffic management systems. GPS spoofing in congested waterways (Strait of Hormuz, Strait of Malacca, English Channel) could trigger chain-reaction collisions. Beyond navigation, AIS manipulation is an established sanctions-evasion practice — vessels "go dark" or transmit falsified tracks so tankers appear to be in one location while actually loading oil elsewhere (U.S. State/Treasury/Coast Guard guidance, May 2020). The IMO's Maritime Cyber Risk Management guidelines acknowledge the threat but provide no technical specifications for authentication.
What’s been tried and why it hasn’t worked
AIS was designed in the 1990s as a cooperative safety system, not a security system — adding authentication would require replacing or upgrading AIS transponders across the world merchant fleet of roughly 116,000 vessels of 100 gross tons and above (UNCTAD, start of 2026), plus Class B units on smaller craft, with no retrofit mandate in force. Multi-receiver AIS validation (comparing a vessel's AIS-reported position with shore-based radar or satellite observation) can detect spoofed positions but requires infrastructure investment and doesn't prevent attacks in areas without shore radar coverage. GPS anti-spoofing techniques (multi-frequency receivers, inertial navigation crosschecking) exist for military systems but are rarely implemented in commercial maritime GPS. ECDIS type-approval testing historically included no cybersecurity evaluation — a certified ECDIS could be fully compliant with IMO standards while accepting every spoofed input it received; a cybersecurity test standard now exists (IEC 63154:2021) and IACS cyber-resilience requirements UR E26/E27 became mandatory for new ships contracted from 1 July 2024, but neither reaches the existing fleet. Software patches for ECDIS vulnerability require physical vessel access during port calls and are rarely applied.
What would unlock progress
Lightweight cryptographic AIS authentication protocols that can be deployed incrementally — vessels with upgraded transponders authenticate their messages, while legacy receivers can still decode the position data. Multi-sensor navigation integrity monitoring that crosschecks GPS, AIS, radar, and inertial navigation and alerts bridge officers when inputs disagree. Cybersecurity requirements integrated into IMO type-approval standards for ECDIS and navigation systems, creating market incentives for secure products. Shore-based maritime domain awareness systems that independently verify vessel positions using satellite radar (SAR) and optical imaging.
Entry points for student teams
A team could set up an AIS simulation environment using software-defined radio and an AIS transceiver simulator, demonstrate the attack surface of unauthenticated AIS, and prototype a simple consistency-checking algorithm that detects impossible vessel movements (speed/course/position contradictions). A navigation team could prototype multi-sensor integrity monitoring that compares GPS, ECDIS chart data, and simulated radar returns to detect spoofing. Relevant disciplines: cybersecurity, maritime engineering, RF engineering, signal processing.
Genome — every gene is a door
Tags marked “under review” were questioned by a later calibration pass; they stay visible here but are left out of filters until re-adjudicated.
Structural cousins — same reason stuck, other fields
Sources
Balduzzi, M., Pasta, A., and Wilhoit, K. (2014), "A security evaluation of AIS automated identification system," Proceedings of the 30th Annual Computer Security Applications Conference (ACSAC), pp. 436–445, U.S. Maritime Administration, U.S. Maritime Advisory "2020-016-Various-GPS Interference," IMO, "Guidelines on Maritime Cyber Risk Management," MSC-FAL.1/Circ.3/Rev.2, 7 June 2022 (superseded by Rev.3, 2025), C4ADS (2019), "Above Us Only Stars: Exposing GPS Spoofing in Russia and Syria," U.S. Department of State, U.S. Treasury (OFAC), and U.S. Coast Guard (May 14, 2020), "Guidance to Address Illicit Shipping and Sanctions Evasion Practices," UNCTAD, "Maritime and other transport" (world merchant fleet statistics), Accessed 2026-08-21 (original sources first accessed 2026-02-25) go to source 1 ↗ go to source 2 ↗ go to source 3 ↗ go to source 4 ↗ go to source 5 ↗ go to source 6 ↗
verification notes (working record)
The collection team’s own sourcing notes for this brief, kept verbatim:
Targets C8 (OT/Cyber-Physical Security). The structural pattern matches: safety-critical systems designed as cooperative/open protocols are now operating in adversarial environments, with an installed base of vulnerable devices (400,000+ vessels) and long replacement cycles (20–30 year vessel lifetimes). Adds ocean domain to C8 (currently: digital, energy, health, infrastructure, transport, water). The `temporal:worsening` tag passes the three-requirement test: (1) documented increase in GPS spoofing incidents in maritime environments since 2017; (2) increasing maritime system connectivity (satellite broadband, remote monitoring) expanding attack surface; (3) the spoofing threat is genuinely growing, not just more visible, as GPS spoofers become cheaper and more accessible.
Reconciliation 2026-08-21: Two of the four Source-line citations were bad. "Pavur, J. & Krawczyk, I., 'GPS Spoofing and Maritime Safety,' Journal of Cybersecurity, 8(1), 2022" could not be found in the Journal of Cybersecurity, on Google Scholar, or anywhere else — the surname Pavur belongs to a real satellite-security researcher (James Pavur, "A Tale of Sea and Sky," 2020) but no such paper or co-author exists; the citation was removed as fabricated and replaced with C4ADS (2019), "Above Us Only Stars: Exposing GPS Spoofing in Russia and Syria" (c4ads.org/reports/above-us-only-stars — ~10,000 spoofing instances, 1,300+ vessels), the primary documentation of maritime GPS spoofing. "MARAD Advisory 2024-02, 'Maritime Cybersecurity Standards'" carried a title MARAD never used — the real 2024-002 is "Worldwide-Foreign Adversarial Technological, Physical, and Cyber Influence" (Feb 21, 2024, about port equipment/LOGINK, not ship navigation); replaced with the on-topic U.S. Maritime Advisory 2020-016-Various-GPS Interference (maritime.dot.gov/msci/2020-016-various-gps-interference), which names the eastern/central Mediterranean and Persian Gulf — now also anchoring that body claim, alongside the newly named June 2017 Black Sea incident (~20 ships near Novorossiysk showing positions at Gelendzhik Airport; New Scientist/RNTF, GPS World, C4ADS). Balduzzi et al. verified exact (ACSAC 2014, pp. 436–445, DOI 10.1145/2664243.2664257 — authors Balduzzi, Pasta, Wilhoit; now cited in full) and IMO MSC-FAL.1/Circ.3/Rev.2 verified exact (issued 7 June 2022; note it was superseded by Rev.3 in 2025). Number corrections in the body: "over 90% of global trade by volume" → over 80% (UNCTAD Review of Maritime Transport); "~400,000 SOLAS vessels ... at an estimated cost of $2–5 billion" could not be sourced anywhere — the world merchant fleet is roughly 116,000 vessels of 100 GT and above (UNCTAD, start of 2026) — so the vessel count was corrected and the invented $2–5B retrofit estimate removed (this supersedes the "400,000+ vessels" figure in the note above, kept verbatim as written); the unsourced "$300 software-defined radio" price was generalized to "inexpensive." The ECDIS claim ("type-approval does not include cybersecurity evaluation") had gone stale: IEC 63154:2021 now defines cybersecurity type-testing for navigation equipment and IACS UR E26/E27 became mandatory for new ships contracted from 1 July 2024 — sentence updated to historical framing with the installed-base caveat. The sanctions-evasion claim verified and is now anchored to the May 14, 2020 State/Treasury(OFAC)/Coast Guard "Guidance to Address Illicit Shipping and Sanctions Evasion Practices." Triage's caution about cross-wired named incidents was warranted in one respect (the fabricated journal citation and the mistitled MARAD advisory) but the incident geography itself — Black Sea, Eastern Mediterranean, Persian Gulf — verified clean against MARAD and C4ADS. URLs checked: dl.acm.org/doi/10.1145/2664243.2664257, acsac.org 2014 program PDF, maritime.dot.gov/msci/2020-016-various-gps-interference, maritime.dot.gov/msci/2024-002 (to confirm the mismatch), imorules.com/MSCFAL_CIRC3.html and the IMO Rev.2/Rev.3 PDFs, c4ads.org/reports/above-us-only-stars, irclass.org OFAC-guidance circular, unctadstat.unctad.org/insights/theme/107.