Spoofing

What is Spoofing?

Spoofing is a deceptive tactic where a scammer disguises their identity—by faking emails, phone numbers, or websites—to trick individuals into revealing sensitive information or taking harmful actions. Common in phishing attacks and cyber fraud, spoofing undermines trust in digital communications. Recognizing spoofing attempts is key to staying safe online.

The Basic Idea

You log onto Instagram (or Facebook or TikTok or whatever your platform of choice is) and see that you have a new message. It’s from your celebrity crush, saying that they’ve found your profile, they think you seem amazing, and you two should grab a drink sometime. Your palms start to sweat as you double-check their name and profile photo, and yes, they still look as gorgeous as ever. As your brain kicks into overdrive thinking about how to respond, you notice one other strange detail... they only have six followers? Turns out, it was actually your friend who made a fake account to trick you for April Fool’s Day. 

You might feel a bit let down, but hopefully the prank was mostly funny. Now imagine that, instead of impersonating your celebrity crush, someone was pretending to be your bank, your boss, or your internet router. It’s not quite as funny, and the consequences of responding incorrectly are likely much higher. That’s the essence of spoofing: it’s all about faking identity to gain trust and cause trouble.

Spoofing is a deceptive cyber technique in which an attacker deliberately falsifies data or their identity to masquerade as a trusted source, often to gain unauthorized access to systems or to trick individuals into revealing sensitive information.1 Spoofing can take many forms, such as email spoofing, IP spoofing, GPS spoofing, caller ID spoofing, and website spoofing—each involving the manipulation of communication protocols or visual cues to create a false sense of legitimacy. This tactic exploits both technical vulnerabilities and human cognitive biases, particularly our tendency to trust familiar or authoritative signals, making it a common precursor to more damaging attacks like phishing, malware delivery, or system infiltration.1

It’s important to note that spoofing and phishing, although sometimes used interchangeably, are different concepts. Spoofing is when an attacker fakes their identity or source, like forging an email address, a caller ID, or a website to appear legitimate. Phishing goes a step further: it uses spoofing tactics to trick victims into providing personal info, like passwords or credit card numbers. In short, spoofing is often a tool used in phishing and hacking, but not all spoofing is phishing. For example, someone might spoof a website just to spread misinformation, not to steal data.

“

There are only two different types of companies in the world: those that have been breached and know it and those that have been breached and don’t know it.


― Ted Schlein, venture capitalist and founding partner at Ballistic Ventures

Key Terms

Phishing: A form of social engineering where attackers trick individuals into revealing sensitive information (like passwords or credit card numbers) by pretending to be a trustworthy source, often via email or fake websites. It often works by exploiting trust and urgency, leading users to act without verifying the authenticity of the source.2

ARP (Address Resolution Protocol): A protocol used within local area networks to map IP addresses to MAC (Media Access Control) addresses. It enables communication between devices on the same network but is inherently trusting, which makes it vulnerable to spoofing attacks such as ARP poisoning.3

DNS (Domain Name System): The system that translates human-readable domain names (like www.example.com) into numerical IP addresses that computers use to locate each other on the internet. DNS spoofing attacks manipulate this system to redirect users to malicious sites without their knowledge.3 

Malware: Any software intentionally designed to cause damage, steal data, or gain unauthorized access to systems. The name comes from “malicious software,” and it includes viruses, worms, spyware, trojans, and other harmful programs often delivered through spoofed or deceptive means.2

Ransomware: A type of malware that encrypts a victim’s files or locks them out of their system, demanding payment (often in cryptocurrency) to restore access. It frequently enters through spoofed emails or malicious websites and is used in both individual and large-scale attacks.2

History

Technically, because spoofing involves impersonating someone or something else to gain access, influence, or information, this type of fraud has likely existed for a long time. However, spoofing as we know it first became widespread with the advent of computer networking. In the 1970s and 1980s, it was difficult to establish any kind of authentication protocol. For example, Address Resolution Protocol (ARP) spoofing was introduced in 1982, allowing devices on a local network to map IP addresses to MAC addresses. Its trust-based design made it an early spoofing target, as attackers could send falsified ARP messages to reroute data.1,3

In the mid-1980s, Robert Tappan Morris highlighted IP spoofing risks by demonstrating that attackers could forge packet headers to appear as if they were from trusted sources. This method became a critical tool in early denial-of-service (DoS) attacks.3 In 1989, computer scientist Steven Bellovin published a paper on IP and TCP spoofing, which emphasized just how vulnerable many of our systems are. 

The rapid growth of email in the 1990s created a fertile ground for yet another type of spoofing. The backbone of email networks was known as SMTP (Simple Mail Transfer Protocol), and it didn’t initially authenticate sender information, so attackers exploited this to forge headers and send spam or spoof emails. In fact, the Morris Worm, created by Robert Tappan Morris in 1988, was one of the first large-scale computer worms distributed via the Internet.3 Although Morris didn’t intend to create something so destructive, his work led to the development of future worms, including the ironically named “I Love You” worm in 2000.4 

This computer virus was disguised as a mysterious confession of love with an attached love letter in an email. Unfortunately for the unsuspecting (and perhaps overly earnest) users, the worm would then overwrite files, alter system settings, and spread itself to all addresses in the user's Outlook address book. This ultimately affected over ten million Windows computers, disrupting not only the individuals but also their workplaces and many internet services as a whole. After this fiasco, potential hackers were more aware of the vulnerability of email-based malware, and spoofers began to take further advantage of cybersecurity weaknesses.4 Researcher Markus Jakobsson was one of the first to study how spoofers were increasingly trying to impersonate banks and institutions, and his research on anti-spoofing tactics has helped protect others from future attacks.2

Since then, all sorts of other mobile spoofing attacks have occurred, with hackers figuring out how to bypass Wi-Fi restrictions, alter their caller ID and voice over, and even track people’s location data in real time. The mid-2000s telemarketing spread created an opportunity for scammers to disguise their phone numbers and voices, and even as late as 2023, the FCC has reported that spoofed robocalls are among the top consumer complaints.5 For businesses, the consequences of a spoofing attack can be mind-bogglingly costly. In 2021, for example, the Colonial Pipeline network was hacked through a series of spoofing and ransomware attacks, and then-CEO Joseph Blount ultimately decided that the company would give in to the $4.4 million ransom demand.8

A new frontier in spoofing involves deepfake technology, where AI-generated voices and videos impersonate real people. This is often done through a process of machine learning involving generative adversarial networks, which learn from trial and error and learn to produce more realistic outputs over time. In 2019, fraudsters used AI voice spoofing to steal $243,000 by mimicking a CEO’s voice in a phone call.6 Cybersecurity research now focuses on developing machine learning-based spoof detection, especially for biometric systems like facial recognition. As spoofing continues to evolve, the ramifications of a data breach are even higher than they once were. Our lives are often inextricably integrated with our technology, and thanks to the IoT (Internet of Things), AI, and social engineering, complex attack chains can mean one malevolent spoof or phishing attack can quickly unravel an entire ecosystem of our well-guarded private lives. 

People

Robert Tappan Morris

The creator of the Morris Worm in 1988, one of the first large-scale computer worms distributed via the Internet. His work inadvertently demonstrated the power of IP spoofing to propagate malware by exploiting trust relationships in network protocols. Although his intent was not malicious, the worm’s unintended consequences raised global awareness about spoofing vulnerabilities and led to the first conviction under the U.S. Computer Fraud and Abuse Act.3

Steven Bellovin

A computer scientist and one of the earliest researchers to identify security flaws in Internet protocols, especially TCP/IP spoofing vulnerabilities. His 1989 paper, Security Problems in the TCP/IP Protocol Suite, highlighted fundamental weaknesses that spoofers could exploit. Bellovin's work laid the scientific foundation for modern network security defenses against spoofing attacks.3

Thomas E. Humphreys

A GPS security researcher who became prominent for exposing the risks of GPS spoofing. In 2013, he and his team at the University of Texas successfully hijacked a luxury yacht’s navigation system using a GPS spoofing device. His demonstrations have been critical in raising awareness about the security gaps in civilian GPS infrastructure and advancing countermeasures.7

Markus Jakobsson

A leading expert in phishing and online fraud, and co-author of the influential book Phishing and Countermeasures. His research helped establish the link between email spoofing and social engineering, offering scientific methods to detect and prevent such attacks. Jakobsson's contributions have shaped both academic research and practical anti-spoofing tools used today.2

Joseph Blount

The retired former President and CEO of Colonial Pipeline. It was during Blount’s time as president that the infamous May 2021 spoofing and ransomware attack on the company occurred, where hackers exploited a legacy VPN account lacking multi-factor authentication to infiltrate Colonial Pipeline's network, leading to a shutdown of critical fuel infrastructure and a $4.4 million ransom payment.8

behavior change 101

Start your behavior change journey at the right place

Impacts

Spoofing can mean many things—from lighthearted parody videos to serious cyberattacks—but in the digital world, it typically refers to the act of impersonating a trusted source to deceive. While some spoofing is as simple as a fake email or phone call, other forms target the very architecture of the internet, using sophisticated tactics like DNS or IP spoofing to manipulate systems and users alike.

The Straightforward Spoofs

The most basic types of spoofs often involve calls and emails. Spoofers can distort their caller ID or voice and often contact people directly, claiming that they’re someone else. This requires the recipient to take some sort of action; although they may be wise enough to not give a caller their credit card information over the phone, they may absentmindedly click on a link from a spoofed email, inadvertently exposing themself to future fraud. Some spoofers even design websites or domain names to mimic familiar sites. 

Imagine you get an email claiming to be from your bank, Wells Fargo, with a link to log into your bank account directly and check the secure message. You feel safe knowing that you’re not being asked to supply any important information over email, and so you follow the link. Unfortunately, what you miss is that the URL has actually taken you to “Wells Frago,” which looks exactly like your familiar banking site. It may be easy to miss this small typo, but that’s exactly what the spoofers are hoping for; many spoofers use a similar tactic to lure you into another website or system where you’ll feel safe and not realize you’re on a foreign site. Once there, you’ll be asked to enter sensitive personal information (like your banking username and password), and then hackers can steal your data. 

Despite the slew of examples related to phishing and hacking, not all spoofing is designed to steal sensitive information. Some spoofing involves people posing as a credible source and then spreading misinformation. When spoofers trick people into thinking they’re a reputable news site, for example, they can quickly spread fake news to serve their own agenda. This type of manipulation can lead to political interference, social discontent, and public health risks.

Technologically Complex Spoofing Attacks 

The more technologically complex forms of spoofing happen at deeper layers of the internet's architecture and include strategies like IP spoofing, ARP spoofing, and DNS spoofing. These can be particularly effective because they exploit the very systems we rely on to determine what's real online. The first type, IP spoofing, involves forging the source address of Internet Protocol (IP) packets so they appear to come from a trusted source.9 Think of it like receiving a letter that looks like it's from your bank, but the return address is fake. Attackers use this to hide their identity, impersonate trusted machines, or launch attacks like DDoS (Distributed Denial of Service), which in turn overwhelms the system using traffic from fake addresses. This tactic relies on a “trust by familiarity” bias; just like people often assume a familiar face is safe, systems trust traffic from familiar IP addresses.9

The second type is ARP (Address Resolution Protocol) spoofing. The ARP helps computers in a local network match IP addresses with physical MAC addresses—kind of like a phone book for machines. In this case, an attacker sends fake ARP messages to trick devices into associating the attacker’s MAC address with the IP address of another device (often the network gateway).3 This allows the attacker to intercept, modify, or even block communication. Just as people can be misled by someone claiming to be “a friend of a friend,” machines can be misdirected by poisoned ARP tables.

A final example involves the Domain Name System (DNS), which translates user-friendly domain names (like google.com) into IP addresses that computers understand. DNS spoofing tricks a DNS server into returning a forged IP address for a given domain name. This means users trying to reach a trusted site may be silently redirected to a malicious one.3 Perhaps when you typed “wellsfargo.com,” you were automatically redirected to a phishing site. 

There are many other technologically complex spoofing strategies, and as our technology becomes more interconnected and complex, strategies will likely evolve in response. Past, present, or future, almost every spoofing tactic relies on our automatic and unconscious trust. We trust our own eyes and ears, and we trust our devices to manage complexity. Just like people trust emails from known senders or logos, computers trust familiar IPs, MAC addresses, and domains. Attackers exploit this by mimicking those trusted sources.

Alternative Definitions of Spoofing

This article has focused on the term spoofing as a way to describe when someone impersonates another party, usually using technology, for a malicious purpose. However, it’s important to remember that spoofing is not always intended to do harm. The term “spoof” originally came from a game created by British comedian Arthur Roberts. That’s why the original use of the word often referred to a trick or prank of some sort, and why we still use the term in comedic parodies.10 Perhaps you’ve watched spoofs on YouTube of famous commercials or songs. These skits aren’t about cybersecurity, but the root concept is the same: spoofing involves impersonating someone else.  

The other common use of the term spoofing refers to a type of stock market manipulation. Although distinct from how those outside the finance world typically use the term, stock market spoofing is similarly sinister to the traditional cybersecurity genre. Spoofing in the stock market is a form of market manipulation where traders place orders to buy or sell securities but have no intention of executing them.11 This is illegal because it distorts the market prices into an inaccurate reflection of true supply and demand. This type of spoofing is also unfair to other market participants and undermines the integrity of the market as a whole, which can lead to losses for unsuspecting investors.11

Controversies

As spoofing techniques grow more sophisticated, they now target everything from our physical location to our facial features. Whether it’s hackers manipulating GPS signals, tricking facial recognition systems with masks or photos, or slipping past digital defenses with phishing scams, the range of spoofing threats is expanding rapidly. Understanding how these attacks work—and how to prevent them—is more crucial than ever.

Geolocation Spoofing 

In the 2010s, a significant leap in the capabilities of spoofing occurred with GPS spoofing, where attackers emit counterfeit GPS signals to mislead receivers. In 2013, researchers, including Thomas Humphreys at the University of Texas, successfully hijacked a yacht’s navigation system using spoofed GPS signals.7 This highlighted the risks that nations face on a geopolitical scale, and in the following years, several high-profile incidents were documented of ships reporting false locations on the Black Sea. Similarly, during the 2019 protests in Moscow, reports emerged of spoofed GPS signals redirecting users’ locations to Vnukovo Airport, over 20 kilometers away, likely to disrupt location-based protest coordination.12 

On both a commercial and military level, drone operators in extreme conflict zones have reported severe navigational anomalies due to GPS spoofing. In some cases, this means that their drones have been disabled or redirected, and as wars increasingly rely on unarmed aerial systems, protection from GPS spoofing becomes more important.13 Even outside of conflict, spoofing has been used to exploit location-based services, like players faking their whereabouts in Pokémon Go, or drivers gaming ride-hailing platforms by simulating traffic congestion to raise fares. Although these may be less severe, the implications of this form of attack are clearly widespread. 

Facial Recognition Technology 

There is something so freeing and futuristic about facial recognition technology; whether it’s getting into your phone or on an international flight, biometric security technology seems to be just about everywhere. I recently visited my friend’s apartment in South Korea, and their apartment complex used facial recognition to unlock doors for residents. The idea that you could walk around, unencumbered by any cards or keys or text message dual-authentication-nightmares, with nothing but your own skin and bones needed to get you where you need to go, was mind-boggling. It’s understandable that this simplicity is appealing for platforms like Airbnb and Uber, which have increasingly been relying on facial recognition technology to verify users’ identities. 

Unfortunately, this has made many of the systems that rely on biometric verification vulnerable to spoofing attacks. As facial recognition and other biometric technologies like fingerprint scans become more mainstream and continue to be used in consequential settings like national ID cards, hackers have more incentive to develop sophisticated facial recognition spoofs. Research on the evolution of face anti-spoofing methods has revealed that approximately 70% of spoofing attacks on facial recognition software are successful.14 There are even online tutorials on how to trick facial recognition systems, which usually rely on face spoofing or presentation attacks. This can involve hackers spoofing the systems by pretending to be someone else with photos, videos, or even a 3D mask.14 

This unauthorized access poses huge risks, but the development of technology designed to deter these dangers often lags behind. Some systems now look for motion and liveliness checks (verifying blinking to make sure a spoofer isn’t using a standard photo), or even use specialized cameras that can sense blood flow in a person’s face.14 As spoofing attempts become more elaborate, and as we continue to roll out facial recognition technology in more places (the top 20 airports in the United States already use facial recognition technology to identify international passengers, including U.S. citizens), we must continue to implement procedures to protect ourselves from facial spoofing attempts. 

How to Prevent Spoofing

So, besides developing new AI programs or sophisticated technologies designed to identify spoofing attempts, how can we protect ourselves from being attacked? The first piece of advice most experts offer is to utilize your spam filter. At present, most email programs do a good job of identifying fake emails and filtering them out so you never have to face them in the first place. If an email from a spoofer does make it to your inbox, be on the lookout for people claiming to be someone or representing an organization that doesn’t match their email address. The same is true for the spoofing texts, which often claim to come from the postal service or a toll collection company, but the sender shows that the message is coming from an obscure Gmail address. 

Be extra suspicious of unknown senders and unsolicited emails, and never click on the links or downloadable files from these mysterious texts and emails. You can often view the file extension name in the “View” tab of File Explorer if a document is attached, so even if the email seems safe, it’s a good idea to double-check the file name before downloading anything. While you may be used to filtering spam calls, hold the same level of suspicion for those on the internet. Anyone can claim to be your bank, government office, or even the police. Before you give away any personal information, do a bit more digging. 

One of the best ways to verify the validity of a call to action is to go directly to the source. For example, you may get a text or call that your bank requires additional verification immediately. Instead of responding to the email or following the links provided by the potential spoofer, open a new tab or go into your mobile app and log into your bank account directly. Call the source whenever possible; if you can speak to someone at the bank, they should likely be able to tell you right away if you have any outstanding paperwork or if they have been trying to contact you. If not, steer clear.

In the 2000s and 2010s, countless people fell victim to some version of the following scam: they’d get an email signed by their “employer” asking them to purchase 100 iTunes gift cards, promising to reimburse the person on their next paycheck. Usually, there was an urgent need for these gift cards as a last-minute gift or thank-you for a client, so the email emphasized the need to act quickly. Then, the spoofer (pretending to be someone’s boss) would ask for the gift card number and PINs to be sent over right away, to speed the process along. Although this strange request may now raise red flags for most people, the early days of widespread internet use, coupled with the pressure from spoofers to act quickly without taking the time to confirm any details or contact the supposed sender directly, led to many spoofing victims losing huge amounts of money or even company assets.15 

Lastly, anti-malware and antivirus software can be hugely beneficial in blocking spoofing attempts and dangerous downloads. Even free software systems are often sufficient to serve as an extra layer of protection against hacking attempts. 

Case Studies

Sony Pictures: Peace Definitely Not Guarded 

You may have seen (or at least remember hearing about) the 2014 comedy film The Interview, which stars Seth Rogen and Dave Franco and depicts a plot to assassinate the North Korean leader, Kim Jong-un. What you may have forgotten is that the fictional movie came close to never being released due to a criminal group that used spoofing tactics to hack into the film studio’s software system.16 

In November 2014, Sony Pictures was attacked by the group “Guardians of Peace,” which leaked a reported 100 terabytes of data from the film studio. But the attackers likely laid their trap months before anyone was even aware of the security breach, according to the computer security firm Cylance, which analysed the leaked data. The company found that many top Sony executives, including CEO Michael Lynton, received spoofing emails that appeared to be from Apple.16 The phishing messages asked them to provide ID verification emails, and promptly redirected them to a bogus site that captured their login credentials. With this information, the attackers accessed a trove of data, including details about Sony Pictures employees and their families, private correspondences, and information regarding then-unreleased films. To compound the damage, the attackers employed a wiper malware to erase Sony’s computer infrastructure.16

In a Hollywood-level twist of events, it turns out that the attackers were likely motivated by their political background: they belonged to a state-sponsored North Korean group. Their main demand? That Sony withdraw the film The Interview.16 They even threatened terrorist attacks at cinemas that screened the film, which resulted in many movie theater chains opting not to show it. Given the unusual nature of the incident, it’s hard to calculate the exact damages, but Jim Lewis, senior fellow at the Center for Strategic and International Studies, estimated that it cost Sony Pictures more than $100 million. 

We are Excited to Announce That Insulin... Still Costs Too Much

Regardless of whether or not you’ve ever had to purchase insulin, you likely know that this life-saving medication that people with type I and type II diabetes rely on is notoriously expensive. Despite recent headlines focused on a small percentage of the United States finally being granted access to their medication for around $35 per month, most people in the U.S. still pay thousands each year.17 This problem is particularly gruesome in the United States, where, compared to their neighbor Canada, the cost of insulin can reach ten times Canada’s average insulin price out of pocket.18 That’s why, in 2022, when a tweet that appeared to be from the pharmaceutical company Eli Lilly and Co stated simply, “We are excited to announce that insulin is free now,” the tweet went viral.18 Of course, this was spoofing in action. 

The account actually belonged to writer Sean Morrow, and surprisingly, he hadn’t done anything illegal. In fact, he’d used his own existing Twitter account, changed the name, and used the feature Elon Musk had established wherein users could simply pay for the blue checkmark, which had previously signalled an account’s authenticity. Morrow had crafted this spoof tweet (which in this case follows the definition of spoof as both pretending to be someone else and as a satirical event) to call attention to the absurdity of the pharmaceutical industry’s price-jacking and corporate greed. Although most people recognized that the post was fake, the ease with which the message spread highlights the danger of spoofing. 

If Morrow’s goal had been less about satire and political commentary and instead a malicious intent to spread fake news, then the message could have quickly caused a widespread panic or health crisis. As it was, the tweet prompted a huge drop in Eli Lilly’s stock and forced them to pull all advertising from Twitter.18 It’s getting easier for those on the internet who wish to trick other people and masquerade as someone or something else to get away with it, and that’s especially scary when used to spread misinformation. The change in verification process on (formerly Twitter, now called) X clearly leaves the door open for more spoofing opportunities, potentially with higher costs (although anything is a higher cost than free). 

Related TDL Content

How to Run Scenario Planning Drills: A Cybersecurity Risk Management Solution 

As spoofing tactics get progressively elaborate, and as more of our work and personal data is stored remotely, cybersecurity needs have also increased. In a post-COVID era of widespread WFH policies, cyberattacks have become more common and more dangerous. This article explores how scenario planning drills can be leveraged to mitigate some of this risk.

Cybersecurity 101 Training: How to build employee habits that prevent cyberattacks 

The best defense against spoofing attacks is to be proactive. Educating employees early and often on how to prevent cyberattacks is one of the best ways to keep companies alert and protected. In this piece, the team lays out the basic training tips and tricks for employees to follow to help prevent cyberattacks.

Sources

  1. Bhaskari, L., & Satyanarayana, C. (2010). A Comprehensive Analysis of Spoofing. ResearchGate. https://www.researchgate.net/publication/49597043 
  2. Jakobsson, M., & Myers, S. (2006). Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft. MIT Press. 
  3. Bellovin, S. M. (1989). Security Problems in the TCP/IP Protocol Suite. ACM SIGCOMM Computer Communication Review, 19(2), 32–48.  
  4. Griffiths, J. (2020, May 3). ‘I love you’: How a badly-coded computer virus caused billions in damage and exposed vulnerabilities which remain 20 years on. CNN. https://www.cnn.com/2020/05/01/tech/iloveyou-virus-computer-security-intl-hnk 
  5. Federal Communications Commission. (n.d.). Call authentication. https://www.fcc.gov/call-authentication
  6. Damiani, J. (2019, September 3). A voice deepfake was used to scam a CEO out of $243,000. Forbes. https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000 
  7.  Humphreys, T. E., et al. (2013). GPS Spoofing and the Challenge of Civilian Navigation Integrity. Journal of Field Robotics.
  8. Eaton, C., & Volz, D. (2021, May 19). Colonial Pipeline CEO tells why he paid hackers a $4.4 million ransom. The Wall Street Journal. https://www.wsj.com/tech/cybersecurity/colonial-pipeline-ceo-tells-why-he-paid-hackers-a-4-4-million-ransom-11621435636
  9. Sahoo, P. K., & Jena, S. K. (2016). Analyzing Spoofing Attacks in Wireless Networks. ResearchGate.
  10. Merriam-Webster. (n.d.). The origin of 'spoof'. https://www.merriam-webster.com/wordplay/spoof-meaning-origin
  11. Investopedia. (2024, March 10). Spoofy: What it means and special considerations. In A. Chavarria (Ed.) & V. Velasquez (Fact checker). https://www.investopedia.com/terms/s/spoofy.asp 
  12. Sebastian, C. (2016, December 2). Getting lost near the Kremlin? Russia could be 'GPS spoofing'. CNN Business. https://money.cnn.com/2016/12/02/technology/kremlin-gps-signals/:contentReference[oaicite:4]{index=4} 
  13. Liaquat, S., Faizan, M., Chattha, J. N., Butt, F. A., Mahyuddin, N. M., & Naqvi, I. H. (2024). A framework for preventing unauthorized drone intrusions through radar detection and GPS spoofing. Ain Shams Engineering Journal, 15(5), 102707. https://doi.org/10.1016/j.asej.2024.102707  
  14. Antil, A., & Dhiman, C. (2025). Unmasking deception: A comprehensive survey on the evolution of face anti-spoofing methods. Neurocomputing, 617, 128992. https://doi.org/10.1016/j.neucom.2024.128992
  15. Federal Trade Commission. (n.d.). Avoiding and reporting gift card scams. https://consumer.ftc.gov/articles/avoiding-and-reporting-gift-card-scams  
  16. Steinberg, S., Stepan, A., & Neary, K. (2022). The hacking of Sony Pictures: A Columbia University case study (SIPA-21-0023). Columbia University School of International and Public Affairs. https://www.sipa.columbia.edu/sites/default/files/2022-11/Sony%20-%20Written%20Case.pdf 
  17. American Diabetes Association. (n.d.). Insulin cost & affordability. https://diabetes.org/tools-resources/affordable-insulin
  18. Goodyear, S. (2022, November 24). How a viral 'free insulin' tweet sparked a debate about access to medicine. CBC Radio.https://www.cbc.ca/radio/asithappens/viral-free-insulin-tweet-1.6663358

About the Author

A smiling woman with long blonde hair is standing, wearing a dark button-up shirt, set against a backdrop of green foliage and a brick wall.

Annika Steele

Talent Acquisition Specialist, GiveWell

Annika completed her Masters at the London School of Economics in an interdisciplinary program combining behavioral science, behavioral economics, social psychology, and sustainability. Professionally, she’s applied data-driven insights in project management, consulting, data analytics, and policy proposal. Passionate about the power of psychology to influence an array of social systems, her research has looked at reproductive health, animal welfare, and perfectionism in female distance runners.

About us

We are the leading applied research & innovation consultancy

Our insights are leveraged by the most ambitious organizations

Image

“

I was blown away with their application and translation of behavioral science into practice. They took a very complex ecosystem and created a series of interventions using an innovative mix of the latest research and creative client co-creation. I was so impressed at the final product they created, which was hugely comprehensive despite the large scope of the client being of the world's most far-reaching and best known consumer brands. I'm excited to see what we can create together in the future.

Heather McKee

BEHAVIORAL SCIENTIST

GLOBAL COFFEEHOUSE CHAIN PROJECT

OUR CLIENT SUCCESS

$0M

Annual Revenue Increase

By launching a behavioral science practice at the core of the organization, we helped one of the largest insurers in North America realize $30M increase in annual revenue.

0%

Increase in Monthly Users

By redesigning North America's first national digital platform for mental health, we achieved a 52% lift in monthly users and an 83% improvement on clinical assessment.

0%

Reduction In Design Time

By designing a new process and getting buy-in from the C-Suite team, we helped one of the largest smartphone manufacturers in the world reduce software design time by 75%.

0%

Reduction in Client Drop-Off

By implementing targeted nudges based on proactive interventions, we reduced drop-off rates for 450,000 clients belonging to USA's oldest debt consolidation organizations by 46%

Read Next

Notes illustration

Eager to learn about how behavioral science can help your organization?