Imagine you're a teacher watching 367,000 students take a test in a gymnasium. Suddenly, 200 students in one corner all write the exact same wrong answer at the exact same time. They didn't cheat off each other — someone changed the answer key projected on their wall. That correlated-wrong-answer signature is exactly how this paper detects GPS spoofing at sea: not by catching the spoofer, but by noticing that dozens of ships in the same region simultaneously report physically impossible movements in the same direction. The committed claim: this is the first large-scale empirical measurement of regional GPS spoofing in global maritime traffic, covering 367,000 vessels over roughly three months (late November 2024 to early February 2025). The authors built a motion-aware, marine-specific detection framework that identifies when clusters of ships simultaneously exhibit implausible position jumps — the telltale fingerprint of an external GPS signal overriding the real one. They found 31 persistent anomalous hotspots, with at least 22 showing strong spoofing evidence. The detection architecture leans on Automatic Identification System (AIS) data — the transponder broadcasts that ships emit continuously with their GPS-derived coordinates. The key insight is that single-ship anomalies (equipment failure, operator error) look random, while regional spoofing creates correlated anomalies: many ships displaced in the same direction at the same time. The framework grades each detected region on the strength of this correlation, separating likely spoofing from ambiguous cases. This is signal processing on a geospatial correlation problem, not a cryptographic or RF approach. Two findings stand out for their temporal dimension. The spoofing in the Red Sea that caused the grounding of the 75,000-ton MSC Antonia was already active months before the incident — meaning the threat was measurable and in principle detectable before the ship ran aground. Similarly, persistent spoofing in the Strait of Hormuz was identified over a year before the 2026 Iran conflict disrupted commercial shipping there. Both findings suggest that spoofing is not episodic but structural: it persists for months and correlates tightly with regional conflict zones and sanctions-enforcement corridors. On the integrity side, this is observational measurement, not controlled experiment. The authors cannot ground-truth every detection against a confirmed spoofer — there is no registry of GPS spoofing events. Instead, they validate by checking spatial and temporal alignment with known conflict zones, sanctions activity, and publicly documented incidents like the MSC Antonia grounding. This is the best available validation for a measurement study of covert adversarial activity, but it means the false-positive rate on the remaining 9 ambiguous hotspots is genuinely unknown. The paper's real contribution is establishing baseline prevalence. Before this work, GPS spoofing in maritime contexts was documented through individual incidents and anecdotes. Now there's a systematic count: 22+ persistent zones, specific geographic coordinates, temporal persistence measured in months. This converts a vague threat narrative into something quantifiable and trackable over time. The framework is reusable — run it on next quarter's AIS data and you get an updated threat map. The obvious next experiment the authors did not run: applying the framework to historical AIS archives going back several years to establish a longitudinal trend. Is spoofing increasing? Did hotspots emerge gradually or appear suddenly with specific geopolitical events? The authors likely had access constraints on historical AIS data (it's commercially licensed and expensive at global scale), and the compute cost of processing years of data for 367,000+ vessels is nontrivial. This is almost certainly a resource limitation, not a strategic omission.