Spoofing, Jamming and Takeover: The Threats an Autonomous Vessel Faces
Second of eight posts on securing autonomous vessels. Having established that an uncrewed ship is a target, this one gets specific: what an attacker would actually try, and why each attempt is dangerous
In the first post we said an autonomous vessel is, in effect, a computer that floats, and that being a computer makes it a target. This post gets specific about what an attacker would actually try.
It helps to know at the outset that almost everything falls into two groups. An attacker can go after what the vessel believes about the world — where it is, and what is around it. Or they can go after the relationship between the vessel and the people entitled to command it. These call for different attacks and different defences, so we will take them one at a time, and deal with the defences at the end of each half rather than scattering them about.
Part one — attacking what the vessel believes
Spoofing: lying to the vessel
Spoofing means feeding a system false data that it mistakes for the truth. The most familiar example in the maritime world involves satellite positioning — the same technology your phone uses to know where it is. A vessel relies on those signals to fix its position. If an attacker broadcasts a stronger, faked signal, the vessel can be convinced it is somewhere it is not. It will then correct its course based on a lie, steering confidently into danger while believing it is perfectly on track.
Positioning is not the only target. Vessels also broadcast and receive identification messages telling nearby ships who they are and where they are going. Those can be faked too — conjuring ghost ships that do not exist, or hiding real ones. For a vessel making decisions based on what it believes is around it, a convincing lie about nearby traffic is as dangerous as a real obstacle.
There is a characteristic fingerprint to this. The false position does not stay inside the vessel; it gets fed to the transponder that broadcasts identity and location to everyone nearby. On traffic displays the result shows up as clusters of ships apparently sharing one position, sometimes circling on the spot, often sitting on dry land. A spoofed vessel is not merely lost — it is actively misleading everything around it.
Jamming: drowning the signal out
Where spoofing whispers a convincing lie, jamming simply shouts over everything. Satellite positioning signals arrive at the Earth’s surface astonishingly faint — they have travelled some twenty thousand kilometres to get here — so it takes very little transmitted power to bury them in noise. That asymmetry is the whole problem. Jamming is cheap, and the signal it defeats is fragile by nature.
It is tempting to assume the result is at least clean: the position disappears and the vessel knows it is lost. Sometimes that is what happens. Often it is not. As interference builds, a receiver can produce a degraded fix before it produces no fix at all — a position carrying a large error it does not advertise. A vessel that takes that number at face value is worse off than one told plainly it has nothing, because it is confidently wrong rather than knowingly blind.
There is a second effect that is easy to overlook. Satellite constellations distribute very precise time as well as position, and a surprising amount of equipment quietly depends on that timing rather than on the position fix — including, in the wider maritime world, distress and safety communications.
Why the two arrive together
It is convenient to treat spoofing and jamming as alternatives — one lies to you, the other silences you. In practice they are routinely used together, and understanding why explains a great deal about why the obvious defences disappoint.
The obvious defence against a fake signal is a second opinion: there are several independent satellite constellations, so if one disagrees with the others, something is wrong. An attacker who wants a false position believed has to prevent that comparison. Faking every constellation on every frequency convincingly is difficult and expensive; jamming the ones you are not faking is neither. So the practical attack, and the one documented in European waters, is to spoof a single constellation while jamming the rest — leaving the receiver one apparently healthy source and nothing to check it against. The implication is uncomfortable: “we use several constellations” is not on its own an answer, because the combined attack exists precisely to defeat it.
None of this is theoretical for anyone operating in northern European waters. Interference across the Baltic and North Sea has become sustained enough that in January 2026 fourteen coastal states wrote jointly to the international maritime community about its effect on the safety of shipping. Research from the southern Baltic has recorded positioning being unavailable for a substantial fraction of the time in some coastal areas, and the reported pattern has been shifting away from signals simply vanishing towards manipulated positions that look entirely valid.
What defends the vessel’s senses
Four layers do the work, and it is worth being precise about them, because a good deal of this is not software.
The antenna. Against jamming this is the main event. Once a signal is buried in noise, no amount of clever processing recovers it; that is physics rather than engineering. What works is an antenna that can distinguish directions — an array that, in effect, deafens itself towards the interference while still listening to the rest of the sky. These exist in marine-hardened form, including for uncrewed vessels, and the better ones will tell you where the jammer is. They cost real money, take up real space, and can only handle so many separate jammers at once.
The receiver. A surprising amount of detection is nearly free. A receiver that watches how hard its own front end is working knows within seconds that it is being jammed, because interference drives that effort up. Related checks catch many spoofing attempts: signals whose shape is subtly wrong, satellites whose reported motion does not add up, a clock drifting in a way no real constellation would produce. This recovers nothing, but it does something almost as valuable — it tells the vessel that what it is receiving should not be believed.
Cryptography. Europe now signs its satellite navigation messages. Since July 2025 Galileo’s open service has carried an authentication feature letting a receiver verify that the navigation message genuinely came from the constellation and has not been altered — free to use, and without breaking older equipment that ignores it. A genuine advance with a genuine limit: it authenticates the message rather than the signal, so an attacker who records real transmissions and rebroadcasts them slightly late is not caught by it.
And then the part we build. Every layer above can be beaten by someone sufficiently determined, and the standard attack is designed to beat combinations of them. So the question that decides whether an autonomous vessel is safe is the one that comes after all of it has failed: what does the vessel do when it has no position it can trust? That means carrying navigation that does not depend on satellites at all — the vessel’s own motion sensors, radar fixed against charted coastline, what the cameras can see — and treating the satellite fix as one opinion among several rather than as ground truth. It means the vessel knowing how confident it is, not merely where it thinks it is, and letting that confidence change its behaviour: slowing down, widening its margins, telling its operators plainly that its position is no longer reliable.
A crewed ship has a mate on the bridge who looks out of the window and says that cannot be right. An uncrewed one has to do that for itself. That capability, rather than any single piece of equipment, is what makes autonomy trustworthy in contested waters.

Part two — attacking who the vessel takes orders from
Takeover: the nightmare scenario
The most serious threat is an attacker gaining genuine control — issuing commands the vessel accepts as legitimate. This is the maritime equivalent of a stranger grabbing the wheel, and if it succeeds none of the other protections matter, because the attacker is now driving.
There is a subtler variant worth naming, because it catches people out. An attacker who cannot forge a command may still be able to interfere with the order in which genuine commands arrive — delaying one, replaying an old one, or shuffling two. Every message is authentic; the sequence is not. A vessel that acts on them in the wrong order can end up somewhere its operator never intended, without a single forged instruction being involved.
Losing the link entirely
Jamming the vessel’s link to shore is a separate attack from jamming its positioning — different frequencies, different consequences — and the two are worth keeping apart, because a vessel that has lost one usually still has the other.
A vessel whose positioning is jammed can normally still be reached: its operators can read its telemetry and take control. What it has lost is its sense of place. A vessel that has lost its link is in the opposite situation — it very often knows exactly where it is; what it has lost is anyone to ask. The genuinely hard case is both at once, and that combination is not a remote hypothetical.
Listening in
Not every attack aims to control the vessel. Some just want to watch. An autonomous vessel used for surveillance or infrastructure monitoring carries a stream of potentially sensitive information — where it went, what it saw, what its sensors detected. An attacker who can quietly read that stream gains valuable intelligence without ever revealing themselves.
What defends the link
Where the vessel’s senses needed four layers, its command link needs five measures — and unlike the antenna, all of them are ours to build.
Prove who is speaking. Commands are cryptographically signed, so the vessel can verify origin and confirm nothing was altered in transit. Each vessel and each operator holds its own unique credentials. A command not properly signed by a recognised operator is refused, however legitimate it looks.
Seal the channel. The same encryption that stops commands being injected stops outsiders reading what flows the other way. If the channel cannot be read, there is no intelligence to harvest from it.
Protect the order. Numbering the messages lets the vessel detect that it is about to act on something out of sequence, or on something it has already seen. This is one of the few places in security where you can do better than testing and actually prove the defence works — which is the subject of Post 6.
Plan for silence. A poor design freezes when contact is lost, or carries on executing its last instruction with no way to be recalled. A sound one has a contingency agreed in advance — continue on a defined plan, hold station, or make for a rendezvous point — while it keeps trying to re-establish contact. The vessel has to be trustworthy precisely in the moments when no one can reach it.
Isolate the last metre. Somewhere on the vessel is the component that finally turns a command into physical movement — rudder, throttle. That is what an attacker most wants to reach, so it gets the strongest isolation and the simplest, most heavily scrutinised logic in the system. The more of the vessel’s cleverness you can keep away from it, the harder it is to subvert
From the CertifAI project — naming threats systematically, not from memory
CertifAI: a three-year EU-funded research project (2023–2026) on AI-assisted cybersecurity certification. MindChip led its maritime use case
Listing threats from a design team’s collective imagination is a poor foundation. It reflects what the team happened to think of on the day.
The tools CertifAI developed draw instead on curated, internationally maintained catalogues of attacker behaviour — separate bodies of knowledge for enterprise IT, for industrial control systems, for embedded devices and for AI-enabled systems. MindChip applied these to the Artificial Captain platform, which spans all four categories at once. The result is a threat list anchored in what attackers actually do, and one that can be refreshed as those catalogues are updated
The common thread
Look across all of these threats and a single principle emerges: an autonomous vessel must not naively trust its inputs. Not its position, not its picture of nearby traffic, not the commands arriving over the air, not even the order those commands arrive in. Every important input has to be checked — is it authentic, is it consistent, does it make sense? Building that disciplined suspicion into the vessel’s software is the heart of maritime cybersecurity.
Which raises an obvious question, and it’s the subject of the next post: how do you make sure you have thought of all of them?
About this series. This post is part of MindChip’s “Cybersecurity for Maritime Autonomy” series, sharing practical insight from our work securing, assessing and certifying autonomous surface vessels. MindChip OÜ led Use Case 3 — the maritime use case — in CertifAI (certifai.info), a three-year Horizon Europe research project that developed AI-assisted tools for cybersecurity certification. MindChip was one of eleven partners, alongside Tecnalia, Hitachi Rail GTS Austria, Schneider Electric, TTTech, DNV, NTNU, Simula Research Laboratory, UBITECH, Catalink and EZU.

Funded by the European Union under Grant Agreement No 101120606. Views and opinions expressed are however those of the author only and do not necessarily reflect those of the European Union or the granting authority. Neither the European Union nor the granting authority can be held responsible for them.
