How employees actually spoof location
On Android, any user can enable Developer Options, tick 'Select mock location app' and install one of dozens of fake-GPS apps from the Play Store. The app then feeds a chosen coordinate to every other app on the phone. A guard sitting at home drops a pin on the client's gate, opens the attendance app and punches in inside the geofence. No root access is needed. iOS is harder to spoof without a jailbreak or a computer-based tool, which is why most incidents involve Android.
The tell-tale signs are consistent: punches from exactly the same coordinate every day to the decimal, zero GPS accuracy variation, a punch in Gurugram five minutes after a punch in Faridabad, or a device whose location provider is flagged as mock by the operating system.
Detection controls, from cheap to strong
The first line is the mock-location flag itself. Android exposes whether a location came from a mock provider, and a well-built attendance app reads that flag and either blocks the punch or records it for review. Root and emulator checks catch the next tier. Jump detection compares consecutive punches: two locations 40 km apart within 10 minutes are physically impossible and should be flagged.
The strongest control is to make location only one of several proofs. A selfie with liveness plus the GPS stamp plus a site QR code scanned at the gate means a spoofer must fake three things at once. For guards, a supervisor site-visit check-in and patrol checkpoints add periodic proof through the shift, not just at punch time.
- Read the OS mock-location flag and block or flag the punch
- Detect rooted devices and emulators
- Flag impossible travel between consecutive punches
- Watch for identical coordinates and constant accuracy values across days
- Pair GPS with selfie liveness, site QR or NFC checkpoints
Policy response when spoofing is found
Treat a flagged punch as unverified rather than as proven fraud on day one; GPS drift inside a basement or near a tall building can also look odd. Send it to the supervisor through regularization, ask for evidence (a site register signature, the client's own gate log), and record the outcome. Repeat offenders, or anyone found with a mock-location app enabled during a punch, should face the disciplinary steps your GPS attendance policy already names.
Write the policy before the first incident. It should state that location capture is used for attendance, that mock-location apps are prohibited on any device used for punching, and what happens on a first and second violation. Under the DPDP Act this notice is also the basis for collecting location data in the first place.
A guard rostered 20:00–08:00 at a warehouse in Bhiwandi punches in at 19:58 from a coordinate exactly 3 metres from the gate. His phone's location provider is flagged as mock. At 20:04 the same device punches out from a different app session 27 km away in Thane. The system flags both punches, the supervisor calls the site and the client's gate register shows no entry. The night is marked absent, and the client is not billed for a man-hour that was never worked.
Attend Mitra flags mock-location (fake GPS) punches on Android, records the flag against the punch and shows it on the live monitor, and lets you require a selfie with liveness and a geofence rule alongside the GPS stamp. Flagged punches can be routed through regularization with an audit trail rather than silently accepted.
