Strait of Hormuz, April 2026: 1,100 Ships in the Electronic Fog — When Kinetic Blockade Meets PNT Warfare
On April 13, 2026 at 10:00 Washington time, US Central Command launched a maritime blockade of all Iranian ports on the Persian Gulf and the Gulf of Oman, following the presidential declaration that Iranian ships attempting to force the line would be sunk. Two guided-missile destroyers — USS Frank E. Petersen (DDG-121) and USS Michael Murphy (DDG-112) — transited the strait on April 11, the first US warships to do so since February 28, with a mandate to clear sea mines and open a route for merchant traffic. On the kinetic plane: blockade in force, military tension at its highest since the Iran-Iraq war, Macron and London preparing a "peaceful multinational mission to restore freedom of navigation".
The number that matters for those watching the economy rather than the military theater is different: the 100+ tankers that transited daily — a corridor carrying about 20% of world oil — have dropped to 10 or fewer. Bloomberg documented a single confirmed commercial transit in the 24 hours of April 13. According to analysts cited by CNN Business, even if the strait reopened today, crude flows would not return to pre-crisis levels before July. But underneath this visible crisis, made of hulls and missiles, a second is unfolding, made of photons and spoofing, that deserves the attention of every security team operating in sectors dependent on maritime logistics — and in Italy there are many more than one might assume.
The Electronic Fog: 1,100 Ships, 600 GNSS Events in 24 Hours
Data gathered by Windward, the Joint Maritime Information Center (JMIC), MarineTraffic and gCaptain in the first two weeks of April 2026 converge on a single picture. GPS jamming and spoofing of the AIS (Automatic Identification System) in the Strait of Hormuz, the Persian Gulf and the Gulf of Oman have reached unprecedented levels: over 1,100 ships affected in a few days, more than 600 GNSS disruption events in just 24 hours per JMIC. One order of magnitude above what was observed since 2019 — when sporadic PNT warfare incidents in the region began — and more than triple the late-2025 average.
The observed pattern has recognizable technical hallmarks. First: satellite navigation interference detected near the UAE coast that makes ships appear on maritime tracking systems as moving in straight lines toward the strait — when in reality they are stationary or on completely different routes. Second: massive AIS anomalies with manifestly false transmitted positions, showing hundreds of "ghost" vessels rotating in concentric circles around fictitious points. Third: intermittent GNSS signal degradation, with cyclical loss and reacquisition of position that prevents any reliable route planning. For the master of a 300-meter tanker in a channel 21 miles wide at its narrowest, with even moderate traffic of other ships, PNT loss is not an inconvenience: it is a condition that makes continuing the voyage irresponsible.
Key figures (April 13, 2026): over 1,100 ships hit by GNSS interference in the Gulf area, more than 600 GNSS disruption events in 24 hours (JMIC), commercial transits through the Strait collapsed from 130-150/day to single digits, a single confirmed commercial transit in the 24 hours of April 13 (Bloomberg).
Why PNT Is Invisible Critical Infrastructure
The Global Navigation Satellite System — American GPS, European Galileo, Russian GLONASS, Chinese BeiDou — is one of those services we take for granted as long as they work. When they stop, we discover how much of our economy depends on the signal of an atomic clock 20,000 km above our heads. PNT (Positioning, Navigation and Timing) is not only "where I am" and "where I am going": it is also, most importantly, the timing reference by which stock exchanges, 4G/5G cellular networks, payment systems, electricity grid exchanges, and data centers are synchronized. A massive GNSS attack is not just a navigation problem: it is an attack on a foundation shared by dozens of critical sectors.
In the Hormuz theater, the primary goal is maritime: deny safe navigation capability, force shipowners to refuse transit even without a formal blockade, amplify the economic damage of the kinetic blockade without having to extend it geographically. But the wave surface of GNSS spoofing is not surgical: it hits everything using the signal within the transmitter's range — civilian aircraft en route, onshore oil terminals with GPS synchronization, automated port infrastructure, energy operators with time-stamping critical for billing and dispatching. In a high-asset-density area like the Gulf, this disturbance wave is a form of warfare with low attribution and high collateral impact — exactly the profile chosen by Iranian cyber doctrine after Khamenei.
Attribution: Iran, But Not Only
Primary attribution of GNSS interference in the Gulf points toward Iran — and specifically toward IRGC electronic warfare units. Rough geolocation of interference sources, derived by triangulation from anomalous signals received by victim ships, places transmitters at points on the Iranian coast compatible with known military bases. The timeline reinforces attribution: the activity peak follows February 28 (US-Israel operation Epic Fury), with a second peak on April 12-13 matching the announcement and start of the CENTCOM blockade.
However, as also documented by gCaptain and Inside GNSS, at least part of the interference is compatible with Israeli defensive operations — GPS spoofing is a standard countermeasure against the Iranian drone threat approaching Israeli territory, and spillover toward the Gulf is a geographically known side effect. There are also reports of Houthi actors, who since 2024 have demonstrated naval targeting capability with drones and anti-ship missiles, and whose communications infrastructure includes tactical jammers of Iranian origin. The Hormuz electromagnetic theater in April 2026 is, essentially, a multi-actor contested area, where precise attribution of any single event is often impossible — and where for commercial defenders it matters less "who" than "how to mitigate".
PNT jamming/spoofing in the Gulf has at least three operational sources: (1) IRGC — Iranian electronic warfare units, primary source; (2) IDF — Israeli defensive spoofing against drones, with regional spillover; (3) Houthi + proxies — tactical jammers of Iranian supply. For the commercial defender, attribution matters less than mitigation.
Why It Matters to Italy (and Not Just to the Maritime Sector)
The reasoning on Italian impact proceeds along three vectors. First: Italy is the second European importer of crude from the Persian Gulf after Spain, with a significant share of supplies that transited or transits through Hormuz — ENI refineries at Sannazzaro, Taranto and Livorno have supply chains already reorienting to alternative routes (Red Sea-Bab al-Mandeb, Cape of Good Hope), with longer lead times and higher costs and an impact on consumer prices that will manifest over the next 4-8 weeks. Second: Italy has direct naval presence in the Eastern Mediterranean and the Red Sea (EU Aspides operation, frigates and patrol vessels), with crews and systems exposed to the same electromagnetic theater as the spoofing zone expands westward.
Third — and this is the point most directly relevant to security teams — PNT is not just for those who navigate. It serves anyone relying on precise time synchronization. Telecommunications operators for 4G/5G cell sync, exchanges and HFT trading with time-stamped logs for MiFID II compliance, energy distributors with time-stamping for billing and dispatching, airports with traffic management systems, data centers with distributed consensus protocols depending on synchronized clocks. An Italian operator does not see the jammer on the Iranian coast: they see a drift in synchronization, a small anomaly in logs, an alert in a QoS monitoring system. The question is not "am I involved?", but "could I detect a PNT quality loss if it happened?".
The Bridge to Post-Khamenei Iranian Cyber Doctrine
In the piece AEGIDA published on April 13 on post-Khamenei Iranian cyber escalation, we described the shift from a "noisy and demonstrative" cyber posture to a "sustained and strategic" posture, with the attack on PLCs in the US documented by CISA as the principal signature. Hormuz PNT warfare is the electromagnetic twin of that evolution: low attribution, high collateral impact, direct economic leverage (oil and shipping prices), constant political signaling without kinetic trigger. It is the perfect weapon for the post-ceasefire phase: invisible to news bulletins, measurable at terminals, scalable for days.
For those doing threat intelligence, the signal is: expect a "normalization" of PNT jamming as a tool of continuous pressure, not as an occasional event linked to escalation moments. Also expect progressive geographic extension — analogous operations in the Black Sea (already ongoing, documented by Inside GNSS and EASA since 2022), in the Eastern Mediterranean (Cyprus, Lebanon, Israel), and potentially in the Baltic after Russian pressures. For Italian organizations in sensitive sectors, integrating PNT spoofing into the threat model is now mandatory, not an academic exercise.
Indicators and Telemetry to Watch Today
- Anomalous drift of NTP/PTP reference clocks synchronized to GNSS sources (low-cost, high-sensitivity spoofing detector).
- Anomalous GPS SNR/CN0 spikes on ground receivers or mobile assets — a too-strong signal is often more suspicious than a weak one.
- Systematic discrepancies between GNSS position and independent sources (cell-ID, Wi-Fi beacons, inertial sensors) — pattern observed especially near sensitive coasts and commercial routes.
- AIS anomalies received by Italian port VTS systems (Genoa, Trieste, Gioia Tauro, La Spezia) — ships appearing/disappearing, "impossible" tracks, clustering at fictitious points.
- Degradation of time synchronization precision in logs of critical systems — exchanges, telco carriers, network operators — even without hard alarms.
- Increased delays in energy and industrial supply chains — indirect economic signal of combined PNT + blockade impact.
Recommendations for Italian Organizations Onshore (Not in Theater)
A necessary clarification before getting to the substance. The recommendations below do not concern those operating today inside the Hormuz theater — navigation, routing and physical safety decisions there rest with masters, shipowners and the military fleets escorting them, and our suggestions would add nothing to their playbook. They concern Italian and European organizations that depend on GNSS signal quality and maritime logistics stability without operating in the crisis theater: telco operators, exchanges, data centers, utilities, national ports, refineries, companies with sea supply chains. For these actors the risk is real and manageable with ordinary cybersecurity and business continuity controls, not heroics.
- 1.Audit of PNT dependencies in your systems: map every asset receiving GNSS signal directly or via NTP/PTP — exchange time servers, radio cell sync, legal time-stamping, cloud orchestrators — and classify by criticality. Many organizations discover forgotten dependencies precisely in this exercise.
- 2.Diversification of time sources in data centers and critical national sites: pair GNSS with at least one alternative source (local Rb/Cs atomic oscillators for critical systems, PTP over fiber, geographically diverse multi-source NTP peering), with automatic failover and alerts on divergences.
- 3.Monitoring of GNSS signal received at sensitive Italian and European sites (national ports, airports, logistics hubs, telco nodes): low-cost spoofing/jamming sensors (u-blox F9P multi-constellation) with alerting on anomalous SNR and cross-constellation discrepancies. Interference spillover to the Mediterranean has been documented for years and does not stop at the Gulf.
- 4.Business continuity: integrate prolonged GNSS loss scenarios into BC/DR plans of national-cabotage maritime operators, Italian ports, airports, energy and telco. Realistic timings are hours or days, not minutes; fallback procedures must be documented and tested.
- 5.Review of contractual and insurance clauses for your supply chains with Gulf and Red Sea exposure: rising war-risk premiums, force majeure clauses to re-read, alternative routes (Cape of Good Hope) to be priced into contracts. This is procurement and legal work, not ship-side.
- 6.Training SOC and NOC teams on what PNT warfare is: many managers have never handled a ticket where "time is off by 120 milliseconds", and the first reaction is to look for a config bug instead of external interference. Dedicated drills reduce diagnosis time.
- 7.SIEM integration of public PNT feeds (GPSjam, EUSPA/EMSA advisories, NATO Shipping Centre bulletins) as context to correlate internal anomalies with documented global events — so an anomalous jitter in logs becomes an indicator, not noise to archive.
Conclusion: The Invisible War Above the Visible Oil
The Strait of Hormuz in April 2026 has become the open-air laboratory for a conflict doctrine that synthesizes kinetic, economic, and cyber-electromagnetic into a single continuous operation. The US naval blockade makes headlines with warships and presidential ultimatums; Iranian — and Israeli, and Houthi — PNT jamming causes damage with transmitters costing tens of thousands of dollars and neutralizing billions of dollars of commercial traffic. For Italy, this is not a crisis to observe: it is an operational condition to absorb into risk models, network architectures, contractual clauses.
The broader lesson is that GNSS dependence is the modern equivalent of 1970s oil dependence: invisible, pervasive, taken for granted until it fails. The difference is that an oil crisis arrives in weeks and shows at the pumps; a PNT crisis arrives in milliseconds and shows only if you have the tools to look. April 2026 is offering us the most complete case study of the last twenty years. It is up to us to decide whether to use it to learn — or to wait for the edition that will hit closer to home.
Primary sources: Bloomberg — Iran War: Hormuz Shipping Collapses Again as US Starts Blockade (April 13, 2026); USNI News — Two U.S. Warships Sail Through Strait of Hormuz (April 11, 2026); Joint Maritime Information Center (JMIC) bulletins April 2026; Windward — GPS Jamming Disrupts 1,100+ Ships; gCaptain — Electronic Fog of War; Scientific American — GPS spoofing is scrambling ships in the Strait of Hormuz; Inside GNSS — GNSS Interference Complicates Navigation; SAFETY4SEA — AIS anomalies and jamming; CNN Business (April 12, 2026); Al Jazeera (April 10, 2026); Fortune and NPR April 2026. Internal reference: AEGIDA Research, "After Khamenei: Iranian Cyber Escalation" (April 13, 2026).