Skip to content
Briefing

Going dark: Legal risks of GPS jamming and AIS spoofing – insurance

In this final instalment of HFW’s briefing mini-series on the legal risks arising from GPS jamming and AIS spoofing,1 we turn our attention to the potential insurance implications of the manipulation of vessel identity and location data, and how these risks may affect the availability of cover.

Insurance considerations arise in relation to GPS jamming and AIS spoofing in a variety of ways. In the context of vessel damage due to a collision or grounding, assuming no cyber buyback cover has been purchased, it is necessary to assess whether an owner’s hull and machinery insurance policy excludes losses arising from cyber threats. The most common cyber exclusion clause is the Lloyd’s Market Association clause LMA5403 which excludes cover for: “…loss, damage, liability or expense directly or indirectly caused by or contributed to, by or arising from the use or operation, as a means of inflicting harm, of any computer, computer system, computer software programme, malicious code, computer virus or process or any other electronic system.” [emphasis added].

The insurer bears the burden of establishing that the exclusion applies and must therefore prove that the loss was linked to the use of an electronic system operated as a means of inflicting harm. While there is little doubt that a GPS spoofing or jamming system would fall within the broad scope of “any computer … or any other electronic system“, knowledge of the perpetrator’s identity will be necessary in order to ascertain intent.

Link between loss and jamming or spoofing

An insurer would not need to demonstrate that the spoofing or jamming was the proximate (i.e. direct) cause of the loss, as the inclusion of the words “indirectly caused” and “contributed to” means that the insurer merely needs to show that the spoofing or jamming had some genuine effect on events. In Arc Capital Partners Limited v Brit Syndicates Limited [2016] EWHC 141, the High Court had to consider whether an exclusion clause which stated “… any claim … arising from or in any way involving any act, error or omission committed or alleged to have been committed prior to 5th June 2009” applied. The High Court stated that “arising from” meant the same as “directly caused by” and, on the basis of Coxe v Employers’ Liability Assurance Corporation Limited [1916] 2 KB 629, held that “indirectly caused by” meant placing the assured in a position specifically exposed to danger. Applied to a jamming or spoofing scenario, the insurer would therefore only need to show that the jamming or spoofing had placed the vessel in a position of “special danger”. The burden would then be on the owner to try and prove that, for instance, the crew were not navigating using GPS and/or AIS, but using navigational charts and/or Automatic Radar Plotting Aids (ARPA), such that jamming or spoofing did not indirectly cause the incident, or that the incident was caused by another event entirely, such as a crew member being intoxicated.

Means of inflicting harm

In 2025, the Association of Average Adjusters published a discussion paper concerning the interplay between traditional marine perils, AIS spoofing and cyber exclusions. The paper concluded that if a vessel is sailing through a known high-risk area with increased political tensions when suddenly she experiences AIS spoofing, the courts may take the view that there is a rebuttable presumption that the spoofer intended harm.

To examine this issue further, we need to understand the possible motivations for jamming and spoofing. In areas such as the Persian Gulf, experts have suggested that Iran was previously using jamming and spoofing to mask increased cooperation between Iranian and Sudanese naval forces. In more recent times, jamming and spoofing was used by a variety of nations to protect against Iranian drones. In the Baltic Sea, the Finnish authorities have indicated that they suspect a major cause of the jamming observed in the area to be from Russian military sources aimed at protecting Russian ports from potential drone strikes. Similarly, in recent years jamming has occurred throughout Israel, with the Israeli Defence Forces acknowledging that the incidents were intentional military operations, attempting to thwart unmanned aerial vehicle attacks. These examples demonstrate that the motivations behind jamming and spoofing can often be either subterfuge or protection of national infrastructure. In these circumstances, we consider that the English courts would be slow to conclude that there is a rebuttable presumption that the perpetrator of the jamming or spoofing intended harm. Instead, the burden would remain on the insurer to demonstrate that the incident which gave rise to the claim was intended by the actor to cause harm. Nevertheless, spoofing and jamming is a recognised part of the growing trend in “grey warfare” whereby states agitate in the ambiguous “grey zone” between peace and full-scale war with the goal of achieving a strategic advantage without triggering a direct military response. If an insurer can demonstrate that the incident which gave rise to the claim was a clear example of grey warfare, then this will go a long way towards discharging the burden of proof that the jamming or spoofing was performed as a “means of inflicting harm“.

Finally, due to the nature of spoofing and jamming, it may be difficult, if not impossible, to positively identify the party responsible and, accordingly, their motives, unless the responsible party identifies themselves and claims responsibility for an incident. Whilst responsibility or motive may be readily established in certain contexts, this is unlikely to be the case when it comes to grey warfare between, for example, Russia and the European Union. It is also worth noting that spoofing and jamming is not the sole preserve of state actors. Criminals are increasingly using GPS jammers to facilitate theft and smuggling.

Drawing these threads together, where a vessel was involved in a collision or a grounding having been subjected to jamming or spoofing, such that the hull and machinery policy would otherwise respond, it is doubtful whether LMA5403 would exclude cover in the absence of clear evidence that the spoofing or jamming was deployed “as a means of inflicting harm“.

From a P&I perspective, there is no express cyber exclusion in the International Group of P&I Clubs’ rules or conditions of cover, although cover is subject to the war risks exclusion, where the loss is caused by “war…or any hostile act by…a belligerent power, or any act of terrorism“. Again, the group responsible for the jamming or spoofing may be difficult to identify, but in the right circumstances, if responsibility could be attributed to a group falling within the definition of terrorism or a group that was a state actor (whether in law or in fact as per Atlantic Mutual Insurance Co v King [1919] 1 K.B. 307), then cover could be excluded.

Constructive total loss

Spoofing and jamming could also lead to insurance issues if a vessel sailed in waters it would otherwise want to avoid, leading to its seizure and detention, and potentially a claim for constructive total loss further down the line. An example of AIS spoofing leading to detention is the seizure by Iran of the British‑flagged oil tanker “STENA IMPERO” in 2019. It was reported that the vessel had been subjected to a spoofing attack, causing the crew to sail into Iranian waters where she was seized. Although the vessel was released after several months, had the detention continued for the requisite time to support a claim for constructive total loss under the policy, it is arguable that the owner would have satisfied section 60(2)(i) of the Marine Insurance Act 1906, namely that it would be deprived of possession of the vessel and unlikely to be able to recover it.

Whether an incident involving GPS jamming or AIS spoofing falls within the scope of cover will ultimately depend on the specific policy wording and the nature of the loss. As these practices become more widespread and sophisticated, we expect to see a corresponding rise in complex coverage disputes .

If you require guidance on any of the issues addressed across the four briefings in this mini-series, or would like to discuss HFW’s work in these areas, please do not hesitate to contact the authors.

Footnotes

  1. See earlier briefings:
    Going dark: Legal risks of GPS jamming and AIS spoofing – collisions and groundings | HFW
    Going dark: legal risks of GPS jamming and AIS spoofing – charterparties | HFW 
    Going dark: Legal risks of GPS jamming and AIS spoofing – sanctions and cargo | HFW
Published
22 July 2026
Reading Time
9 minutes