Why Timing Is Becoming a Cyber Attack Vector

Why Timing Is Becoming a Cyber Attack Vector: GNSS Jamming and Spoofing Explained

An attack vector is the route or method an attacker uses to access a system or cause harm.

For years, accurate time has been the quiet utility in the background: always there, broadly trusted and rarely questioned. Unfortunately, attackers rather like things nobody is watching.

Financial markets use time to order trades. Telecoms networks use it to synchronise infrastructure. Energy operators use it to align measurements. Data centres use it to correlate events. Defence organisations rely on Positioning, Navigation and Timing (PNT) to co-ordinate people, platforms, communications and effects.

If that shared reference is disrupted or manipulated, the problem travels far beyond the clock.

The numbers are difficult to ignore. IATA’s 2025 Safety Report states that reported GNSS jamming events increased by 67% between 2023 and 2025, while GPS spoofing incidents rose by 193%. The UK Government estimates that a nationwide GNSS loss lasting 24 hours could cost the UK economy £1.42 billion, rising to £7.64 billion over seven days.

So yes, timing is still an engineering dependency. It is also quickly becoming part of the attack surface.

Why can timing be used as an attack vector?

Modern systems use time to decide when something happened, which event came first and whether data arrived when expected. In most environments, that time is trusted automatically.

An attacker does not always need to compromise the final application. If they can deny, delay or falsify the time it relies on, they can disrupt the outcome indirectly. One compromised reference may affect hundreds or thousands of downstream systems, while the resulting error can easily be mistaken for a network fault or configuration issue.

Worse still, incorrect time can look perfectly believable. A failed clock may trigger an alarm; a clock confidently distributing the wrong time may carry on unnoticed.

The NIST Foundational PNT Profile treats the disruption and manipulation of PNT data as a cyber-risk management issue, covering threats such as interference, denial of service, data manipulation, abnormal network delays, jamming, spoofing and compromised PNT components.

Want to understand where that risk sits in your environment? Explore our timing consultancy services.

GNSS jamming, spoofing and network time attacks

Jamming: making the clock go quiet

GNSS jamming overwhelms legitimate satellite signals with interference. A receiver disciplined by GPS, Galileo or another constellation may lose the external reference on which its clock depends.

A resilient system should enter holdover and continue using its local oscillator. However, holdover is not magic. Without the right performance, the clock gradually drifts until connected systems move outside their required accuracy.

GNSS spoofing: teaching the clock to lie

Spoofing is sneakier. Counterfeit or rebroadcast signals are presented as genuine, causing the receiver to calculate false positioning or timing data. The receiver may stay locked, look healthy and continue distributing the wrong time.

Put simply: jamming stops a receiver hearing the truth; spoofing persuades it to trust a lie.

Network time manipulation

The threat does not stop at the antenna. Once time enters the network through protocols such as NTP or PTP, attackers may target false sources, management interfaces, configuration, packet delay, replay, redirection or denial of service.

Network Time Security can add cryptographic protection to NTP synchronisation, but authentication is only one layer. Resilience also depends on source diversity, path diversity, monitoring, holdover and a tested response when the preferred reference disappears.

Explore resilient timing and synchronisation solutions →

Why is the risk growing now?

More systems are connected, automated and time-sensitive, so a clock error that once affected one device can now spread into distributed applications, operational technology and shared infrastructure.

At the same time, the UK Government says the country’s PNT is provided almost completely through GNSS, primarily GPS. That creates the potential for a common failure across services that may otherwise look independent.

Interference is also becoming more persistent. In March 2026, EASA and EUROCONTROL described GNSS interference as a regular occurrence, particularly around conflict zones.

This is where cyber security, electronic warfare and operational resilience collide: a radio-frequency attack can corrupt the input, while a network attack can influence how that false reference is selected, distributed and recorded.

How timing attacks affect critical industries

Financial services

Financial systems need accurate timestamps to sequence trades, reconstruct events and maintain regulatory evidence. If clocks diverge, confidence in event order, transaction reporting and audit trails can quickly unravel. During an incident, poor time also makes activity across platforms, databases and security tools harder to correlate. Learn more about resilient timing for finance and fintech.

Telecommunications

Mobile and fixed networks depend on reliable frequency, phase and time synchronisation. A lost or corrupted reference can contribute to degraded service, radio interference, failed handovers and loss of availability. The ITU identifies GNSS jamming, spoofing and packet-layer attacks as timing-resilience concerns for telecoms. Explore timing infrastructure for telecoms networks.

Energy and utilities

Power networks use precise time to align measurements, analyse disturbances and establish the sequence of events around faults. Manipulated or inconsistent timestamps can weaken grid visibility and undermine confidence in operational data exactly when teams need it most. See how edgeTime supports timing resilience across energy and utilities.

Data centres

Servers, databases, monitoring platforms and security controls all rely on consistent time. When clocks disagree, applications may behave unpredictably and incident timelines become harder to trust. Certificates, credentials, replication and backup processes can also be sensitive to clock errors. Discover our approach to data centre timing and synchronisation.

Aviation, maritime and transport

Transport makes the threat easy to see because GNSS provides both navigation and timing. Jamming can remove information; spoofing can provide a convincing but incorrect answer. In 2025, the ITU, ICAO and IMO jointly warned that harmful GNSS interference affects aviation, maritime operations, telecommunications and international commerce.

Why timing matters to defence, military and security

For defence, reliable timing is inseparable from assured PNT and mission assurance.

Military operations use a common reference for navigation, command and control, communications, intelligence and surveillance, unmanned systems, co-ordinated manoeuvre and precision effects. If it is denied or manipulated, units can lose more than location; they can lose shared situational awareness and confidence in the origin, order and validity of information.

The UK’s Joint Doctrine Publication on Space Power describes navigation warfare as co-ordinated action to assure friendly PNT while preventing an adversary from using it. The Strategic Defence Review 2025 also highlights electromagnetic warfare used to degrade command and control and jam signals used by drones and missiles.

The obvious outage is not always the most dangerous outcome. A denied system can trigger a fallback. A deceived system may carry on with complete confidence and completely false information.

Resilient military timing therefore needs five things: integrity, availability, continuity, traceability and recoverability. Accuracy matters, but being precisely wrong is not much of a win.

Explore timing and synchronisation for defence and security →

More satellites do not automatically mean resilience

Using GPS, Galileo, GLONASS and BeiDou can improve availability and help with a problem affecting one constellation. It does not automatically create four independent backups.

Those signals may still share the same antenna, receiver, environment and parts of the radio-frequency spectrum. It is one basket with more satellites in it. Real resilience comes from diversity across sources, technologies, routes and failure modes.

What does resilient timing look like?

There is no magic box that removes every timing risk. A resilient design uses several layers and proves how they behave together:

  1. Map every dependency: know where time originates, how it travels and which systems consume it.
  2. Use genuinely diverse references: combine independent sources and paths where the operational requirement justifies it.
  3. Design holdover around the mission: specify how long the system must survive and how much drift applications can tolerate.
  4. Secure distribution: protect timing devices, management interfaces, configurations and protocols.
  5. Monitor time as security data: compare sources and alert on slow drift or disagreement, not only total signal loss.
  6. Test realistic failures: validate GNSS loss, source failure, delay, holdover, failover and recovery before deployment.
  7. Include timing in incident response: define who is alerted, which source is trusted and how accurate time will be restored.

If owning and managing every layer is adding too much complexity, explore edgeTime as a Service, from fully managed timing delivery to compliance and hybrid ownership models.

Timing should be treated as a security control

Timing usually sits quietly in the background. That is precisely what makes it useful to an attacker.

GNSS jamming, spoofing and network time manipulation show that a clock is not merely an operational component. It is a source of trusted data that must be protected, monitored and tested.

The question is no longer only, “How accurate is our time?”

It is, “How do we know we can trust it when the network is under attack?”

Speak to an edgeTime specialist about assessing your timing dependencies, testing resilience and designing a solution around your operational requirements.

Frequently asked questions

What is a timing attack vector?

It is a method of disrupting or manipulating the time information a system depends on. The attack may target GNSS, network protocols, timing equipment or the systems that decide which source to trust.

What is the difference between GNSS jamming and spoofing?

Jamming prevents a receiver from tracking legitimate signals; spoofing presents false signals that can produce an incorrect position or time. Jamming denies information, while spoofing deceives.

Can GPS spoofing affect time as well as location?

Yes. GNSS receivers use precisely timed satellite signals and often provide time to other systems, so spoofing can corrupt timing as well as location.

How can an organisation improve timing resilience?

Start by mapping dependencies, then introduce diverse references and paths, suitable holdover, secured distribution, continuous monitoring, response procedures and realistic testing.


Leave a Reply

Your email address will not be published.

Send us a message