Beautiful Virgin Islands

Tuesday, Jan 13, 2026

FBI warn about the dangers of using public USB charging stations

FBI warn about the dangers of using public USB charging stations

Travelers are advised to avoid using public USB power charging stations in airports, hotels, and other locations because they may contain dangerous malware, the Los Angeles District Attorney said in a security alert published last week.

USB connections were designed to work as both data and power transfer mediums, with no strict barrier between the two. As smartphones became more popular in the past decade, security researchers figured out they could abuse USB connections that a user might think was only transferring electrical power to hide and deliver secret data payloads.

This type of attack received its own name, as "juice jacking."

Across the years, several proofs-of-concept were created. The most notorious is Mactans, presented at the Black Hat 2013 security conference, which was a malicious USB wall charger that could deploy malware on iOS devices.

Three years later, in 2016, security researcher Samy Kamkar took the concept further with KeySweeper, a stealthy Arduino-based device, camouflaged as a functioning USB wall charger that wirelessly and passively sniffs, decrypts, logs, and reports back (over GSM) all keystrokes from any Microsoft wireless keyboard in the vicinity.

Following Kamkar's release of KeySweeper, the FBI sent out a nation-wide alert at the time, warning organizations against the use of USB chargers and asking companies to review if they had any such devices in use.

Also, in 2016, another team of researchers developed another proof-of-concept malicious USB wall charger. This one could record and mirror the screen of a device that was plugged in for a charge. The technique become known as "video jacking."



The LA District Attorney's warning [PDF] covers many attack vectors, because there's different ways that criminals can abuse USB wall chargers.

The most common way is via "pluggable" USB wall chargers. These are portable USB charging devices that can be plugged into an AC socket, and criminals can easily leave some of these behind "by accident" in public places, at public charging stations.

There are also USB chargers encased directly inside power charging stations installed in public places, were the user only has access to a USB port. However, LA officials say criminals can load malware onto public charging stations, so users should avoid using the USB port, and stick to using the AC charging port instead.

But the LA DA's warning also applies to USB cables that have been left behind in public places. Microcontrollers and electronic parts have become so small these days that criminals can hide mini-computers and malware inside a USB cable itself. One such example is the O.MG Cable. Something as benign as a USB cable can hide malware nowadays.


Taking all these into account, LA officials recommend that travelers:

Use an AC power outlet, not a USB charging station.

Take AC and car chargers for your devices when traveling.

Consider buying a portable charger for emergencies.

But there are also other countermeasures that users can deploy. One of them is that device owners can buy USB "no-data transfer" cables, where the USB pins responsible for the data transfer channel have been removed, leaving only the power transfer circuit in place. Such cables can be found on Amazon and other online stores.

There are also so-called "USB condoms" that act as an intermediary between an untrusted USB charger and a user's device.

Two such devices are SyncStop (formerly known as USB Condom) and Juice-Jack Defender. Many others also exist, and at one point, even Kaspersky researchers tried to build one -- called Pure.Charger -- but their Kickstarter fundraiser failed to raise the needed funds.

Update, November 15: After the publication of this article, there has been a wave of criticism from security researchers and the cyber-security community, who did not believe the LA DA's security alert was adequate, as there have been no known cases of "juice jacking" incidents detected in the real world, and beyond experimental work presented at security conferences. Furthermore, many have pointed out that since the first juice jacking demos back in 2013, both Android and iOS have now incorporated popups in their user interface to alert a user when a USB port is attempting to transfer data, rather than just electrical power.

US authorities usually issue security alerts based on reports and threats they see in the real world. After failing to respond to a phone call yesterday, the LA DA told fellow tech news site TechCrunch today that the security alert was part of an educational campaign, and not based on juice jacking attacks they've detected in the wild. The original LA DA advisory is still labeled as a "fraud alert" and "PSA" on the LA DA's website, though, with no evidence this is part of an educational campaign. However, the advice given to travelers is in no way bad or incorrect, and users should follow it.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Meghan Markle Could Return to the UK for the First Time in Nearly Four Years If Security Is Secured
Meghan Markle Likely to Return to UK Only if Harry Secures Official Security Cover
UAE Restricts Funding for Emiratis to Study in UK Amid Fears Over Muslim Brotherhood Influence
EU Seeks ‘Farage Clause’ in Brexit Reset Talks to Safeguard Long-Term Agreement Stability
Starmer’s Push to Rally Support for Action Against Elon Musk’s X Faces Setback as Canada Shuns Ban
UK Free School Meals Expansion Faces Political and Budgetary Delays
EU Seeks ‘Farage Clause’ in Brexit Reset Talks With Britain
Germany Hit by Major Airport Strikes Disrupting European Travel
Prince Harry Seeks King Charles’ Support to Open Invictus Games on UK Return
Washington Holds Back as Britain and France Signal Willingness to Deploy Troops in Postwar Ukraine
Elon Musk Accuses UK Government of Suppressing Free Speech as X Faces Potential Ban Over AI-Generated Content
Russia Deploys Hypersonic Missile in Strike on Ukraine
OpenAI and SoftBank Commit One Billion Dollars to Energy and Data Centre Supplier
UK Prime Minister Starmer Reaffirms Support for Danish Sovereignty Over Greenland Amid U.S. Pressure
UK Support Bolsters U.S. Seizure of Russian-Flagged Tanker Marinera in Atlantic Strike on Sanctions Evasion
The Claim That Maduro’s Capture and Trial Violate International Law Is Either Legally Illiterate—or Deliberately Deceptive
UK Data Watchdog Probes Elon Musk’s X Over AI-Generated Grok Images Amid Surge in Non-Consensual Outputs
Prince Harry to Return to UK for Court Hearing Without Plans to Meet King Charles III
UK Confirms Support for US Seizure of Russian-Flagged Oil Tanker in North Atlantic
Béla Tarr, Visionary Hungarian Filmmaker, Dies at Seventy After Long Illness
UK and France Pledge Military Hubs Across Ukraine in Post-Ceasefire Security Plan
Prince Harry Poised to Regain UK Security Cover, Clearing Way for Family Visits
UK Junk Food Advertising Ban Faces Major Loophole Allowing Brand-Only Promotions
Maduro’s Arrest Without The Hague Tests International Law—and Trump’s Willingness to Break It
German Intelligence Secretly Intercepted Obama’s Air Force One Communications
The U.S. State Department’s account in Persian: “President Trump is a man of action. If you didn’t know it until now, now you do—do not play games with President Trump.”
Fake Mainstream Media Double Standard: Elon Musk Versus Mamdani
HSBC Leads 2026 Mortgage Rate Cuts as UK Lending Costs Ease
US Joint Chiefs Chairman Outlines How Operation Absolute Resolve Was Carried Out in Venezuela
Starmer Welcomes End of Maduro Era While Stressing International Law and UK Non-Involvement
Korean Beauty Turns Viral Skincare Into a Global Export Engine
UK Confirms Non-Involvement in U.S. Military Action Against Venezuela
UK Terror Watchdog Calls for Australian-Style Social Media Ban to Protect Teenagers
Iranian Protests Intensify as Another Revolutionary Guard Member Is Killed and Khamenei Blames the West
Delta Force Identified as Unit Behind U.S. Operation That Captured Venezuela’s President
Europe’s Luxury Sanctions Punish Russian Consumers While a Sanctions-Circumvention Industry Thrives
Berkshire’s Buffett-to-Abel Transition Tests Whether a One-Man Trust Model Can Survive as a System
Fraud in European Central Bank: Lagarde’s Hidden Pay Premium Exposes a Transparency Crisis at the European Central Bank
Trump Announces U.S. Large-Scale Strike on Venezuela, Declares President Maduro and Wife Captured
Tesla Loses EV Crown to China’s BYD After Annual Deliveries Decline in 2025
UK Manufacturing Growth Reaches 15-Month Peak as Output and Orders Improve in December
Beijing Threatened to Scrap UK–China Trade Talks After British Minister’s Taiwan Visit
Newly Released Files Reveal Tony Blair Pressured Officials Over Iraq Death Case Involving UK Soldiers
Top Stocks and Themes to Watch in 2026 as Markets Enter New Year with Fresh Momentum
No UK Curfew Ordered as Deepfake TikTok Falsely Attributes Decree to Prime Minister Starmer
Europe’s Largest Defence Groups Set to Return Nearly Five Billion Dollars to Shareholders in Twenty Twenty-Five
Abu Dhabi ‘Capital of Capital’: How Abu Dhabi Rose as a Sovereign Wealth Power
Diamonds Are Powering a New Quantum Revolution
Trump Threatens Strikes Against Iran if Nuclear Programme Is Restarted
Apple Escalates Legal Fight by Appealing £1.5 Billion UK Ruling Over App Store Fees
×