The thing I keep noticing about GPS spoofing coverage is that it is written in the present tense. Aircraft over a particular region are receiving false positions. Flights near a particular border are being diverted. It reads like weather. You pass through it, and then you have passed through it.
I spent my service as a Counter-IED and Electronic Warfare Officer, which meant I was on the transmitting side of this problem rather than the receiving side. That vantage gives you one durable instinct: an attack on a sensor is not an event that happens to a sensor. It is a state you put the sensor into. Getting out of range of the transmitter does not automatically get the sensor out of the state.
On 12 March 2026 the FAA's Flight Technologies and Procedures Division published Version 1.1 of its GNSS Interference Resource Guide, a 69-page document written for pilots. It is not a policy paper and it is not a threat assessment. It is closer to a field manual. And it contains several statements that are more pointed than anything I have seen in the coverage of it.
The algorithm that was never on duty
If you have flown behind a GPS navigator, you have encountered RAIM, Receiver Autonomous Integrity Monitoring. It is the function that is supposed to notice when the satellite picture stops making sense. In a great deal of casual discussion, RAIM occupies the role of the immune system: the thing that catches bad GPS.
Here is the guide, in section 1.6, in full:
"RAIM does not protect against GNSS spoofing. The RAIM algorithm's design never had an intent to do so. Thus, the RAIM algorithm cannot distinguish the authentic GNSS signal from false, spoofing signals, especially when the GNSS sensor receives spoofing signals in a consistent format mimicking the GNSS signal."
Read the second sentence twice. This is not a story about a defense that was overwhelmed, or a defense that needs a software update. It is a statement that the defense was built for a different threat and is being asked to do a job that was never in its specification.
The job RAIM actually has is described right above that passage: it protects "against faults from a single satellite by removing the individual satellite's signal" from the position solution. That is a design for a broken satellite, or an atmospheric artifact, or a clock drifting somewhere in the constellation. It assumes the rest of the constellation is honest and looks for the one member that disagrees with the others.
A spoofer does not present as one satellite disagreeing. A competent spoofer presents as an entire constellation in perfect agreement, agreeing on the wrong answer. RAIM's whole method is consensus, and consensus is precisely what the attacker manufactures. The algorithm is not fooled so much as bypassed. It runs, it finds no outlier, and it reports integrity, correctly by its own logic and uselessly by yours.
This is the single most transferable idea in the document, and it goes well beyond aviation. Any integrity check that works by looking for internal disagreement is defeated by an adversary who controls enough of the inputs to remove the disagreement. That describes sensor voting schemes, redundant instrument channels, and a fair number of the anomaly detectors currently being marketed with the word "AI" attached.
The corruption follows you home
Section 1.7 of the guide is titled "Lingering Effects of Spoofing," and it is the part I would put in front of anyone who thinks of this as a transient hazard:
"GNSS sensors corrupted by interference may be difficult to detect because the receiver may appear to be functioning normally while providing false information for hours after the event. GNSS receivers may need a ground reset or in some instances, a full 'factory reset'."
Two things in that sentence deserve separating. The first is duration: hours, not seconds. The second is presentation: the receiver appears to be functioning normally. There is no caution light for this condition. The failure mode is a healthy-looking instrument that is confidently wrong, which is the worst failure mode any instrument can have and the one that operators are least equipped to catch, because everything about the interface is telling them things are fine.
The guide then lists where the contamination goes, and this is the part that reframes the whole problem. Spoofed GPS data "can corrupt the INS, causing it to continue calculating an incorrect position even after leaving the area of spoofing." The flight management system "may persist in using the inaccurate data integrated during the spoofing event." Terrain warnings can fire falsely "for the duration of the flight including the en route and the approach phases." ADS-B can broadcast false positions to controllers and to other aircraft. A corrupted master clock can break datalink communications.
Notice what happened there. The inertial navigation system is the classic answer to GPS denial: a self-contained system that needs no signal and cannot be jammed. That is true, and I have written before about why inertial and other signal-independent methods are the real fallback. But an INS is not purely self-contained in practice, because it is periodically corrected against GPS to control its drift. Feed it a poisoned correction and you have not merely lost your backup. You have converted your backup into a second confident liar, one that keeps lying after the transmitter is over the horizon.
That is the difference between jamming and spoofing stated in its most practical form. Jamming takes something away from you and the loss is visible. Spoofing installs something in you, and the installation persists.
The detector is a wristwatch
Given all that, you would expect the guide's recommended countermeasure to involve new equipment. It mostly does not. The cross-check discipline it lays out is built almost entirely from instruments that have nothing to do with satellites.
In the in-flight vigilance list, pilots are told to monitor the "Aircraft clock for incorrect time (should be compared with independent timekeeping device)." In the section on confirming you are clear of interference, the first positive indication listed is "Correct UTC time as compared with an independent time source (i.e. watch)."
A watch. The FAA's published test for whether a modern airliner's navigation suite has been compromised by an electronic attack begins with looking at your wrist.
This is not quaint, it is the correct engineering answer, and it is worth understanding why. GPS is fundamentally a timing system; position is what you compute after you have solved for time. That means a spoofer manipulating your position is very often manipulating your clock as a side effect, which is why the guide lists time and date shifts among the primary indications of spoofing. And a mechanical or quartz watch has one property that no avionics box in the aircraft has: it shares no input path with the attacker. It cannot be reached.
The rest of the cross-check list has the same shape. Compare position against ground-based navigation aids. Compare ground speed against true airspeed. Compare the captain's clock against the first officer's. Compare the flight management system's position against a handheld device or a tablet. Every one of these works by introducing a source the adversary does not control, which is the only move that reliably survives a well-run deception. Adding another satellite-derived opinion adds nothing, because the attacker owns that whole channel.
The indications the guide lists for the onset of spoofing are worth committing to memory for anyone in this field: position shifting several miles in seconds, inertial and GNSS positions diverging, estimated position uncertainty climbing rapidly, the autopilot commanding a turn nobody asked for, and cockpit messages reading CHECK GNSS or FMS-GPS DISAGREE. Most of those are not detections of the attack. They are detections of a disagreement between two systems, which is a different and more honest thing to build on.
It is a maintenance problem, not just a flight problem
Section 4.11 is the part of the document I have seen discussed least, and operationally it may matter most. If interference is suspected, pilots are told to document it in the maintenance log so that maintenance clears all system faults. The guide continues that it "may be necessary for maintenance personnel to perform a 'hard reset' of the GNSS/MMR systems and if necessary, a factory reset or replacement of damaged systems," and says these should be treated as standard maintenance for aircraft flying through known interference areas.
Then it adds a detail that tells you how real this is. If GPS from a previous flight leg left the system inoperative or showing an incorrect date or time, cycling the multi-mode receiver circuit breakers on the ground may resolve it. Even where GPS recovers on its own and the clock looks right, the guide recommends a ground check before the next flight. And it attaches a caution: "Repeated reset of the circuit breaker may lead to premature failure."
Put those together and the picture is a wear item. An electronic attack that costs the attacker nothing per aircraft is generating hardware resets, maintenance actions, and occasionally replacements on the receiving end. That asymmetry is the entire economic logic of electronic warfare, and it is the reason I take the maintenance paragraph more seriously than the flight-deck paragraphs. The flight-deck effects are handled by trained crews with procedures. The maintenance effects accumulate quietly across a fleet.
One more scoping detail from section 1.6, because it is routinely underestimated: interference in conflict zones "may extend hundreds of miles beyond the immediate conflict area, potentially impacting manned aircraft flying in the vicinity." The affected airspace is much larger than the map of the conflict, which is what you would expect from transmitters operating against a receiver designed to hear signals from orbit.
What I could not confirm
The guide does not quantify "hours," and it does not say what fraction of encounters produce persistent corruption versus clean recovery. It says corruption may persist, which is a warning rather than a rate.
It is also explicit that its system descriptions are generic. The guide tells pilots to refer to their Airplane Flight Manual and to work with manufacturers on aircraft-specific effects, and defers to manufacturer guidance on reset procedures and on how far to fly before restoring GNSS navigation. So the persistence behavior almost certainly varies a great deal by avionics suite, and this document is not the place to learn what your particular aircraft does.
I have not independently verified the guide's account of the 2022 Denver and Dallas events, nor the claim that most GNSS interference in the U.S. National Airspace System stems from sanctioned government testing. Those are the FAA's characterizations, reported here as such.
Finally, this is a resource guide, not a regulation. It offers safety suggestions. Nothing in it is a requirement, and I have made no attempt to assess compliance or fleet practice.
The signal
Three things to take away from a document most people will never open.
First, RAIM is not a spoofing defense and was never intended to be one. If a vendor, a briefing, or an article implies that integrity monitoring covers deception, the FAA's own guide contradicts it in two sentences.
Second, spoofing is a persistent condition rather than a passing hazard. The receiver can look healthy and report false position for hours after the aircraft is clear, and it can push that error into the inertial system, the flight management system, terrain warnings, the transponder, and the clock. Leaving the area is not recovery. Verification is recovery.
Third, the verification that works comes from outside the compromised channel. A watch, a ground-based navigation aid, an airspeed comparison, the other pilot's clock. The general rule holds anywhere you are defending a sensor: you cannot audit a channel using only sources that channel controls. When someone tells you their system validates its own inputs, that is the moment to ask what the input is being compared against, and who supplies it.
Sources
- Federal Aviation Administration, Flight Technologies and Procedures Division (AFS-400), "GNSS Interference Resource Guide, Version 1.1," 12 March 2026, 69 pp. (Primary, official. Downloaded and read in full via local text extraction. Source of every verbatim quotation in this report: the RAIM passage in section 1.6; the "hundreds of miles beyond the immediate conflict area" scoping line; the section 1.7 "Lingering Effects of Spoofing" passage and its list of affected systems, including the INS, FMS, TAWS, ADS-B and clock effects; the section 4.2 and 4.7 spoofing indications; the section 4.7 instruction to compare the aircraft clock with an independent timekeeping device; the section 4.8 "Correct UTC time as compared with an independent time source (i.e. watch)" line; and the section 4.11 post-flight maintenance guidance, including the hard-reset and factory-reset language and the circuit-breaker caution. The document's revision history records Version 1.0 dated 04 December 2025 and Version 1.1 dated 12 March 2026, with changes noted to Section 4 and paragraph 4.9.)
- Kerry Lynch, "FAA Revises GPS/GNSS Interference, Spoofing Guidance," Aviation International News, 25 March 2026. (Secondary, trade press. Opened and cited for the fact that the revision was reported at the time and that NBAA encouraged members to read it, describing it as heavily revised. The page content retrieved was brief, and no characterization of its depth or completeness is offered here beyond what is quoted.)
Onur Oncer
U.S. Army combat veteran (Counter-IED / Electronic Warfare), peer-reviewed researcher in microwave spectroscopy, and founder & CEO of Shroombiosis. Consults on laboratory operations, AI, and supplement formulation.