Attendance · Glossary

GPS Spoofing / Mock Location

Also called: fake GPS attendance, mock location, location spoofing, fake location app

Definition

GPS spoofing, or mock location, is the practice of making a phone report a false position so that a GPS or geofenced attendance punch appears to come from the work site when the employee is somewhere else. It is usually done with a free 'fake GPS' app and Android's developer-options mock-location setting, and it is the main fraud risk in mobile attendance for field and security staff.

How employees actually spoof location

On Android, any user can enable Developer Options, tick 'Select mock location app' and install one of dozens of fake-GPS apps from the Play Store. The app then feeds a chosen coordinate to every other app on the phone. A guard sitting at home drops a pin on the client's gate, opens the attendance app and punches in inside the geofence. No root access is needed. iOS is harder to spoof without a jailbreak or a computer-based tool, which is why most incidents involve Android.

The tell-tale signs are consistent: punches from exactly the same coordinate every day to the decimal, zero GPS accuracy variation, a punch in Gurugram five minutes after a punch in Faridabad, or a device whose location provider is flagged as mock by the operating system.

Detection controls, from cheap to strong

The first line is the mock-location flag itself. Android exposes whether a location came from a mock provider, and a well-built attendance app reads that flag and either blocks the punch or records it for review. Root and emulator checks catch the next tier. Jump detection compares consecutive punches: two locations 40 km apart within 10 minutes are physically impossible and should be flagged.

The strongest control is to make location only one of several proofs. A selfie with liveness plus the GPS stamp plus a site QR code scanned at the gate means a spoofer must fake three things at once. For guards, a supervisor site-visit check-in and patrol checkpoints add periodic proof through the shift, not just at punch time.

  • Read the OS mock-location flag and block or flag the punch
  • Detect rooted devices and emulators
  • Flag impossible travel between consecutive punches
  • Watch for identical coordinates and constant accuracy values across days
  • Pair GPS with selfie liveness, site QR or NFC checkpoints

Policy response when spoofing is found

Treat a flagged punch as unverified rather than as proven fraud on day one; GPS drift inside a basement or near a tall building can also look odd. Send it to the supervisor through regularization, ask for evidence (a site register signature, the client's own gate log), and record the outcome. Repeat offenders, or anyone found with a mock-location app enabled during a punch, should face the disciplinary steps your GPS attendance policy already names.

Write the policy before the first incident. It should state that location capture is used for attendance, that mock-location apps are prohibited on any device used for punching, and what happens on a first and second violation. Under the DPDP Act this notice is also the basis for collecting location data in the first place.

Example: impossible travel on a 12-hour post

A guard rostered 20:00–08:00 at a warehouse in Bhiwandi punches in at 19:58 from a coordinate exactly 3 metres from the gate. His phone's location provider is flagged as mock. At 20:04 the same device punches out from a different app session 27 km away in Thane. The system flags both punches, the supervisor calls the site and the client's gate register shows no entry. The night is marked absent, and the client is not billed for a man-hour that was never worked.

How Attend Mitra handles this

Attend Mitra flags mock-location (fake GPS) punches on Android, records the flag against the punch and shows it on the live monitor, and lets you require a selfie with liveness and a geofence rule alongside the GPS stamp. Flagged punches can be routed through regularization with an audit trail rather than silently accepted.

Frequently asked questions

Can GPS spoofing be completely prevented?
Not by location checks alone, because the phone belongs to the employee. What you can do is make spoofing detectable and pointless: read the mock flag, check for impossible travel, and require a live selfie and a site QR scan with the punch. Once three independent proofs are needed, the effort exceeds the benefit for almost everyone.
Is fake GPS attendance a criminal offence in India?
There is no specific statute naming it, but falsifying attendance to claim wages is misconduct under most standing orders and can amount to cheating. In practice employers handle it through disciplinary action and recovery of wrongly paid wages. Make sure your policy names it explicitly so the action is defensible.
Why does a genuine employee sometimes get flagged?
GPS accuracy drops indoors, in basements and between tall buildings, so a real punch can land 100 metres outside the geofence or show a sudden jump. That is drift, not spoofing, and it will not carry the mock-location flag. Set the geofence radius realistically and review flagged punches rather than auto-rejecting them.
Does the attendance app need root access to detect mock location?
No. Android reports whether a location fix came from a mock provider to any app that asks, without special permissions. Root detection is a separate check. Both are standard in serious attendance apps.

Related terms

GPS Attendance
GPS attendance is a mobile attendance method that records the phone's satellite location coordinates at the moment an employee punches in or out, so the employer knows not only when but where the punch was made. It is usually paired with a geofence rule that accepts the punch only inside a defined area, and with selfie or face verification to prove who punched.
Geofencing Attendance
Geofencing attendance is a rule applied at punch time that accepts an employee's check-in or check-out only if the phone's GPS location falls inside a virtual boundary drawn around the workplace. The boundary, or geofence, is usually a circle of 50–200 metres around a site's coordinates. Punches from outside are rejected or flagged for supervisor review.
Geofence
A geofence is a virtual boundary defined on a map – most often a circle described by a centre coordinate and a radius in metres, sometimes a polygon drawn along a plot boundary – that software uses to decide whether a GPS position is inside or outside a place. In attendance systems, each work site has a geofence and punches are tested against it.
Liveness Detection
Liveness detection is the check inside a face or selfie attendance app that confirms a real, living person is in front of the camera rather than a printed photo, a phone screen playing a video, or a mask. It runs before the face is matched against the enrolled record, so an employee cannot mark attendance for a colleague by holding up their picture.
Selfie Attendance
Selfie attendance is a mobile attendance method in which the employee takes a photo of themselves in the app at punch time. The app verifies the face against the enrolled profile, stamps the punch with GPS coordinates and time, and stores the image or its descriptor as evidence. It is the standard method for security guards, field sales and other staff who work away from a fixed device.
Proxy Attendance
Proxy attendance is the Indian workplace term for attendance recorded for a person who was not actually present – a colleague punching for them, a supervisor marking absent workers present in the register, or a contractor listing 'ghost' workers who exist only on the muster roll. It covers buddy punching and goes further, into supervisor and contractor-level fraud that affects wages, PF, ESI and client billing.

Go deeper

See how this works inside Attend Mitra

Verified attendance, shift rosters, leave, and payroll-ready reports in one platform built for Indian teams.

Browse all terms