GNSS jamming and spoofing over the Baltic, 2023-2026
What happened, who is affected, what mitigation works and what it costs
Since 2022, GNSS jamming and spoofing has escalated across the Baltic Sea Region, disrupting flights to Tartu, grounding a bulk carrier near Ust-Luga, and pushing national regulators, EASA, EUROCONTROL, ICAO, ITU and IMO into a string of advisories, resolutions and a 22-action aviation plan -- none of them a binding penalty. Attribution to Kaliningrad ranges from precise academic triangulation to single-source, confidential-sourced claims, and mitigation (R-Mode Baltic, CRPA antennas, NATO's GANDALF sensor, new insurance products) is real but still partial.
Select any sentence or paragraph to go deeper or ask a question. You see the evidence and the price first; if our research can’t answer, you’re not charged. First 2 answers free.
Jamming and spoofing: two different problems, often blurred
GNSS jamming and GNSS spoofing are physically distinct. Jamming floods a receiver with interference so it cannot lock onto genuine satellite signals at all -- an outage, usually noticed immediately. Spoofing broadcasts counterfeit signals convincing enough that a receiver computes a wrong position, altitude or time while believing it is correct -- a deception, often unnoticed until something goes wrong. EASA, the aviation-safety standard-setter, and IALA, the marine aids-to-navigation standards body, define the two the same way, and a June 2025 EU Council note uses near-identical language. That convergence matters: it means the Baltic's problem is not one phenomenon called 'GPS jamming' but two, with different detectability and different safety consequences.
Since February 2022, EASA has tracked worsening jamming and spoofing severity, intensity and sophistication concentrated around conflict zones -- the Mediterranean, Black Sea, Middle East, Baltic Sea and Arctic. Public interference maps such as GPSJam.org, built from aircraft-reported positioning accuracy, mark an area 'red' once more than 10% of transiting aircraft report low accuracy in a 24-hour window; that threshold-based, aircraft-derived methodology is the backbone of most of the maps cited in Baltic reporting, including this one. Even so, a great deal of press coverage still uses 'GPS jamming' as a catch-all for both mechanisms without specifying which was observed -- this report treats that looseness as a source of imprecision to flag, not to repeat.
What the interference datasets actually show
Finland's Traficom publishes the most granular national dataset found in this research. GPS-interference notifications concerning Finland itself rose from a handful per year before 2022 to 65 in 2022 and 239 in 2023; notifications from Finnish operators flying outside Finland (mostly over the Baltic and near Kaliningrad) rose in parallel, hitting 7,370 in 2023 alone. By the first four months of 2024, the Finland-domestic count had already exceeded its full 2023 total; the outside-Finland count was running well above prior years but had not yet reached its full 2023 total. Traficom's own April 2026 update adds an important caveat that applies to every dataset in this section: part of the apparent year-on-year rise reflects the build-out of its spectrum-monitoring system itself, not only a real-world increase, so raw counts across years are 'not directly comparable.'
| Year | Notifications: Finland | Notifications: Finnish operators outside Finland |
|---|---|---|
| 2018 | 0 | 6 |
| 2019 | 8 | 137 |
| 2020 | 27 | 34 |
| 2021 | 8 | 71 |
| 2022 | 65 | 1,331 |
| 2023 | 239 | 7,370 |
| 2024 (by 30 Apr) | ~1,200 | ~2,100 |
Sweden's Transport Agency offers a cautionary tale about reading these numbers too literally. It logged 142 GNSS-interference reports by 28 May 2026, versus about 336 in the same window of 2025 -- on its face, a decline. But the agency itself warned against that reading: 2026 data are preliminary, and EASA changed its own reporting criteria in between, breaking the comparison. Meanwhile the agency's own aviation-airspace lead described spoofing as having become 'more systematic and geographically widespread' since the end of May 2026, and Polish monitoring over the same window shows disruption on the large majority of days -- the opposite of a genuine decline.
Latvia's Electronic Communications Office recorded 820 interference cases in 2024, up from just 26 in 2022 -- roughly a 31-fold increase -- and separately warned the affected area has 'expanded significantly.' The most detailed cross-country dataset this research located, however, comes not from a national regulator's annual total but from a footnote in a European Council document.
This dataset, tallied by unique aircraft ICAO identifier and submitted jointly by Lithuania, Czechia, Estonia, Finland, Italy, Latvia, Romania and Spain to the EU Council in June 2025, is the most precise, apples-to-apples cross-country comparison this research found. Three of four countries rose between October 2024 and January 2025; Estonia alone recorded a small decline (1,150 to 1,085), inside an overall regional pattern the same document calls a 'dramatic increase' since August 2024, attributed 'mainly' to sources in Russia and Belarus.
Poland shows the clearest 2026 escalation. Its National Institute of Telecommunications recorded full-band GNSS disruption on roughly 63% of the first 19 days of August 2026, after disruption-free days fell to just 10-13% in May-June 2026; in July 2026 alone, its Gdansk-area station logged nearly 90 hours of disruption. Poland's own Civil Aviation Authority told ICAO in mid-2025 that the interference affecting the Baltic Sea and northern/eastern Europe originates from Russian territory.
Where it is coming from: attribution and evidence quality
The strongest attribution evidence this research found is academic, not diplomatic. In spring 2025, researchers from Gdynia Maritime University and Germany's DLR aerospace centre triangulated Baltic jamming and spoofing emissions, using monitoring stations around Gdansk Bay, to within roughly one kilometre of two sites inside Kaliningrad: the Okunevo coastal antenna complex and the Baltiysk naval harbour area.
Weaker, but widely repeated, is the claim that Russia's 'Tobol' electronic-warfare network, headquartered at a facility in Pionersk, is itself responsible; that claim traces to Estonian broadcaster Delfi citing 'confidential sources' rather than to open, independently checkable evidence. A separate report places the headquarters of the 218th Independent Electronic Warfare Regiment not at Pionersk but a few driving minutes from the Okunevo site, sourced only to unnamed 'open sources' -- a materially different evidence standard from the triangulation above, even though all three locations sit in the same exclave.
Lithuania's communications regulator (RRT) reported on 26 May 2026 that Russian GPS-spoofing antennas identified in Kaliningrad had grown from three in early 2025 to 36 -- a twelvefold increase in about fifteen months -- projecting a roughly 450 km spoofing radius that reaches Estonia, Latvia, Lithuania, Poland, Finland, Sweden and Belarus. The regulator's deputy head said the estimate came from analysis of civilian aircraft ADS-B data, not military intelligence. Reported civilian side-effects include degraded mobile networks near Kaliningrad and failed GPS-dependent bus-arrival displays in Klaipeda.
Not every expert accepts a single-transmitter picture. A Tallinn University of Technology researcher argues the Estonia/Finland border pattern is more consistent with a distributed network of many smaller jammers -- some potentially mounted on mobile-network towers, each covering roughly a 25 km radius -- than with one very powerful emitter. Both the Finnish authorities (via the marine-insurance literature) and this same researcher converge on a common motive: protecting Russian ports and strategic sites from Ukrainian drone strikes, rather than a purely anti-NATO signal.
Incidents: aviation and maritime
The clearest early aviation incident was Tartu, Estonia. Finnair suspended its daily Helsinki-Tartu service for a full month, from 29 April to 31 May 2024, after two flights could not land because Tartu's approach depended on GNSS and diverted back to Helsinki; the airline used the suspension to help stand up a non-GNSS approach procedure before resuming on 2 June 2024. Days into the episode, Estonia summoned Russia's charge d'affaires over the suspected jamming, with the foreign minister calling it a 'hybrid attack.' Estonia's own transport regulator, meanwhile, said Tallinn Airport itself was unaffected because it has an independent DME-DME ground network as backup.
Two high-profile military-flight incidents near Kaliningrad round out the aviation picture: a RAF Falcon 900LX carrying then-UK Defence Secretary Grant Shapps in March 2024, and a Spanish Air Force A330 MRTT carrying Defence Minister Margarita Robles on 24 September 2025. Spain's own account of the Robles flight is notable: because the aircraft's navigation system is encrypted, officials said the attempted disruption 'was not affected' the flight at all -- one of the few directly reported cases in this research where a stated countermeasure visibly held. Both incidents, however, rest on government and press statements rather than the kind of independent triangulation applied to the Kaliningrad emitter sites themselves. A separate, widely reported incident affecting European Commission President Ursula von der Leyen's aircraft near Plovdiv, Bulgaria is deliberately excluded here as out of scope: Bulgaria is outside the Baltic Sea Region, and even within that incident Bulgaria's own Prime Minister pushed back on the 'targeted attack' framing, calling the jamming a generic 'side effect' of the war rather than an attack on von der Leyen specifically -- a reminder that attribution to a specific target can be looser than headlines suggest.
At sea, the bulk carrier Meghna Princess ran aground on an underwater rock near Ust-Luga on 29 December 2024 after GPS jamming caused its crew to lose course orientation, its AIS track showing the classic spoofing 'ship-on-land' signature. The vessel sat aground for over two months, taking on hull damage, flooded tanks and a damaged propeller, before salvage -- secured only after pressure from the International Transport Workers' Federation -- refloated it on 6 March 2025.
More recently, the Polish Navy minehunter ORP Albatros experienced GPS jamming during Baltic operations on 21 August 2026, confirmed by NATO's Joint Force Command Brunssum, and the Lithuanian parliament sheltered under its first-ever air-danger warning on 20 May 2026 -- in the same week regulators reported the sharp jump in Kaliningrad-area spoofing infrastructure.
- 29 Apr-31 May 2024 -- Finnair suspends Helsinki-Tartu flights after GPS-dependent approach failures
- 8 May 2024 -- Estonia summons Russia's charge d'affaires over suspected jamming
- March 2024 -- UK Defence Secretary's aircraft reportedly jammed near Kaliningrad
- 29 Dec 2024 -- Meghna Princess grounds near Ust-Luga after GPS jamming; refloated 6 Mar 2025
- 20 May 2026 -- Lithuanian parliament's first air-danger shelter warning
- 24 Sep 2025 -- Spanish defence minister's jet reportedly targeted near Kaliningrad; encrypted system unaffected
- 21 Aug 2026 -- Polish minehunter ORP Albatros jammed during Baltic operations, confirmed by NATO
Regulation and diplomacy: advisories, resolutions, no binding penalty yet
EASA's core guidance document, Safety Information Bulletin 2022-02, has been revised repeatedly as the problem worsened: Revision 2 (6 November 2023), Revision 3 (5 July 2024), and Revision 4 (3 July 2026), each adding newly observed symptoms and updated mitigation recommendations covering both regulators and airlines.
On 26 March 2026, EASA and EUROCONTROL jointly published a 22-action European Aviation Action Plan for GNSS interference -- 17 of the 22 actions flagged short-term with 2026-2028 deliverables -- aimed at keeping aviation safe for at least three years while interference persists. It followed a 6 June 2025 letter from 13 EU member states (Lithuania, Latvia, Estonia, Germany, Slovakia, Finland, Slovenia, Czechia, Italy, the Netherlands, Spain, Denmark and Romania) demanding coordinated EU action; two days earlier, a Council note co-sponsored by eight of those states had previewed the letter with seven concrete proposals, including exploring whether Russia's and Belarus's ITU spectrum-registration rights could be suspended while interference continues.
Multilaterally, the ICAO Assembly condemned both Russia and North Korea on 3 October 2025 for recurring GNSS interference amounting to infractions of the 1944 Chicago Convention -- one of ICAO's sternest rebukes on record -- while ITU, ICAO and IMO's Secretaries-General jointly urged member states in a 'grave concern' statement to protect the Radio Navigation Satellite Service, retain conventional navigation backups, and report interference to the ITU. IMO's own Maritime Safety Committee circular (MSC.1/Circ.1644) and the SOLAS convention's requirement that every ship carry a working position-fixing receiver of some kind sit underneath all of this as the longer-standing legal scaffolding.
Mitigation: what is actually deployed, not just proposed
The most mature Baltic-specific mitigation is R-Mode, a GNSS-independent ranging system broadcast over existing maritime radio-beacon infrastructure. The original R-Mode Baltic project (2017-2021), led by Germany's DLR aerospace centre and spanning Germany, Poland, Sweden and Denmark, built the world's first large-scale R-Mode test bed on a EUR 3.43 million budget; a nine-month R-Mode Baltic 2 follow-on (EUR 0.70 million) pushed the concept from a contingency tool toward a genuine GNSS-independent backup system. The currently running ORMOBASS project (2023-2026) is extending the test bed from the Kiel Canal to the Gulf of Finland and adding an interference-monitoring layer.
IALA, the marine aids-to-navigation standards body, frames R-Mode and the Enhanced Radar Positioning System (ranging to enhanced radar beacons) as the two leading GNSS-independent backup concepts for shipping, tied to IMO Resolution A.915(22) and its own Recommendation R-129. On the detection side, NATO's NCIA ran a GANDALF-4 interference-detection measurement campaign with the Finnish Border Guard in July 2026, mounting sensors on the patrol vessel Turva and an H215 helicopter, alongside parallel evaluation of Controlled Reception Pattern Antenna (CRPA) technology that lets a receiver keep operating under jamming by electronically steering its reception pattern away from the interference source.
On the funding side, the EU's European Defence Fund committed EUR 1.07 billion across 57 projects in its 2025 call (announced 15 April 2026), including GNSS_ARMOUR, a multilayer anti-jam GNSS-receiver project -- though this research found no project-specific funding figure for GNSS_ARMOUR itself. Separately, the EU states' own June 2025 request list explicitly calls for accelerating anti-spoofing features within the Galileo satellite-navigation program.
Aviation contingency measures are less novel but already deployed: EASA recommends keeping conventional ILS/DME/VOR infrastructure operational, using inertial/GNSS hybrid positioning, and training crews to recognise interference symptoms. Estonia's own transport regulator confirms Tallinn Airport already relies on an independent DME-DME network, and larger modern aircraft already carry inertial navigation as GNSS backup -- concrete, already-working examples rather than aspirational recommendations. The clearest single case in this research of a stated countermeasure holding up in a real incident is the Robles flight: Spain's account is that the aircraft's encrypted navigation system was simply unaffected by the attempted disruption.
Insurance and liability: a market still catching up
Marine insurers face real coverage uncertainty. The standard cyber-exclusion wording, Lloyd's Market Association clause LMA5403, excludes hull cover for loss linked to an electronic system used 'as a means of inflicting harm' -- but per legal analysis from HFW, the insurer must prove the jammer intended harm, which is difficult when the perpetrator's identity and motive are unclear. P&I cover has no express cyber exclusion but remains subject to the standard war-risks exclusion, which could only bite if the responsible party is shown to be a state or terrorist actor.
A 2025 discussion paper from the Association of Average Adjusters suggested courts might presume a spoofer intended harm if a vessel is spoofed while transiting a known high-risk area -- but HFW's own analysis argues English courts would likely resist extending that presumption to Baltic-style state jamming, where the apparent motive (protecting Russian ports from drones) is not obviously an intent to harm the specific ship affected. A separate, older exposure -- spoofing leading to detention, as in Iran's 2019 seizure of the tanker Stena Impero after an alleged spoofing incident -- illustrates a route to a constructive-total-loss claim distinct from collision or grounding.
The market's clearest new product is Sompo Japan's marine-cyber insurance extension, launched from August 2026 on top of a product first introduced in November 2025: it pays lost earnings when GNSS or radio interference forces an operational shutdown even with no physical damage, conditional on crew completing a ClassNK cybersecurity course. On the evidence in this research, it is the first insurance product marketed specifically for this peril -- itself a sign the market views existing hull and P&I wording as insufficient rather than merely untested.
Evidence quality: what to trust, what to watch
This research applied one evidence hierarchy consistently: academic triangulation to a named site within ~1 km (the Gdynia/DLR research) outranks a regulator's antenna-count estimate derived from civil aviation data (Lithuania's RRT), which in turn outranks specific military-unit claims sourced to a single outlet's 'confidential sources' or unnamed 'open sources' (the Pionersk/Tobol reporting and the separately-sourced 218th Independent Electronic Warfare Regiment claim). All three point at Kaliningrad, but readers should not treat them as equally certain.
- Whether Sweden's apparent 2025-to-2026 decline in interference reports (C010) reflects a real de-escalation or a reporting-criteria change remains unresolved by any source this research opened
- No source found gives a Baltic-specific vessel-count breakdown from Windward or GPSPATRON, despite both naming the Baltic as a 2025 'hotspot'
- No EU or UN document found imposes a binding penalty specifically for GNSS jamming/spoofing, as opposed to advisories and condemnations
- This research could not confirm whether the EU's proposed ITU spectrum-registration suspension against Russia/Belarus has actually been used
- No project-specific funding figure was found for the EDF-backed GNSS_ARMOUR receiver project