Arab Press

بالشعب و للشعب
Wednesday, Nov 12, 2025

FBI warn about the dangers of using public USB charging stations

FBI warn about the dangers of using public USB charging stations

Travelers are advised to avoid using public USB power charging stations in airports, hotels, and other locations because they may contain dangerous malware, the Los Angeles District Attorney said in a security alert published last week.

USB connections were designed to work as both data and power transfer mediums, with no strict barrier between the two. As smartphones became more popular in the past decade, security researchers figured out they could abuse USB connections that a user might think was only transferring electrical power to hide and deliver secret data payloads.

This type of attack received its own name, as "juice jacking."

Across the years, several proofs-of-concept were created. The most notorious is Mactans, presented at the Black Hat 2013 security conference, which was a malicious USB wall charger that could deploy malware on iOS devices.

Three years later, in 2016, security researcher Samy Kamkar took the concept further with KeySweeper, a stealthy Arduino-based device, camouflaged as a functioning USB wall charger that wirelessly and passively sniffs, decrypts, logs, and reports back (over GSM) all keystrokes from any Microsoft wireless keyboard in the vicinity.

Following Kamkar's release of KeySweeper, the FBI sent out a nation-wide alert at the time, warning organizations against the use of USB chargers and asking companies to review if they had any such devices in use.

Also, in 2016, another team of researchers developed another proof-of-concept malicious USB wall charger. This one could record and mirror the screen of a device that was plugged in for a charge. The technique become known as "video jacking."



The LA District Attorney's warning [PDF] covers many attack vectors, because there's different ways that criminals can abuse USB wall chargers.

The most common way is via "pluggable" USB wall chargers. These are portable USB charging devices that can be plugged into an AC socket, and criminals can easily leave some of these behind "by accident" in public places, at public charging stations.

There are also USB chargers encased directly inside power charging stations installed in public places, were the user only has access to a USB port. However, LA officials say criminals can load malware onto public charging stations, so users should avoid using the USB port, and stick to using the AC charging port instead.

But the LA DA's warning also applies to USB cables that have been left behind in public places. Microcontrollers and electronic parts have become so small these days that criminals can hide mini-computers and malware inside a USB cable itself. One such example is the O.MG Cable. Something as benign as a USB cable can hide malware nowadays.


Taking all these into account, LA officials recommend that travelers:

Use an AC power outlet, not a USB charging station.

Take AC and car chargers for your devices when traveling.

Consider buying a portable charger for emergencies.

But there are also other countermeasures that users can deploy. One of them is that device owners can buy USB "no-data transfer" cables, where the USB pins responsible for the data transfer channel have been removed, leaving only the power transfer circuit in place. Such cables can be found on Amazon and other online stores.

There are also so-called "USB condoms" that act as an intermediary between an untrusted USB charger and a user's device.

Two such devices are SyncStop (formerly known as USB Condom) and Juice-Jack Defender. Many others also exist, and at one point, even Kaspersky researchers tried to build one -- called Pure.Charger -- but their Kickstarter fundraiser failed to raise the needed funds.

Update, November 15: After the publication of this article, there has been a wave of criticism from security researchers and the cyber-security community, who did not believe the LA DA's security alert was adequate, as there have been no known cases of "juice jacking" incidents detected in the real world, and beyond experimental work presented at security conferences. Furthermore, many have pointed out that since the first juice jacking demos back in 2013, both Android and iOS have now incorporated popups in their user interface to alert a user when a USB port is attempting to transfer data, rather than just electrical power.

US authorities usually issue security alerts based on reports and threats they see in the real world. After failing to respond to a phone call yesterday, the LA DA told fellow tech news site TechCrunch today that the security alert was part of an educational campaign, and not based on juice jacking attacks they've detected in the wild. The original LA DA advisory is still labeled as a "fraud alert" and "PSA" on the LA DA's website, though, with no evidence this is part of an educational campaign. However, the advice given to travelers is in no way bad or incorrect, and users should follow it.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Cristiano Ronaldo Embraces Saudi Arabia’s 2034 World Cup Vision with Key Role
Saudi Arabia’s Execution Campaign Escalates as Crown Prince Readies U.S. Visit
Trump Unveils Middle East Reset: Syria Re-engaged, Saudi Ties Amplified
Saudi Arabia to Build Future Cities Designed with Tourists in Mind, Says Tourism Minister
Saudi Arabia Advances Regulated Stablecoin Plans with Global Crypto Exchange Support
Saudi Arabia Maintains Palestinian State Condition Ahead of Possible Israel Ties
Chinese Steel Exports Surge 41% to Saudi Arabia as Mills Pivot Amid Global Trade Curbs
Saudi Arabia’s Biban Forum 2025 Secures Over US$10 Billion in Deals Amid Global SME Drive
Saudi Arabia Sets Pre-Conditions for Israel Normalisation Ahead of Trump Visit
MrBeast’s ‘Beast Land’ Arrives in Riyadh as Part of Riyadh Season 2025
Cristiano Ronaldo Asserts Saudi Pro League Outperforms Ligue 1 Amid Scoring Feats
AI Researchers Claim Human-Level General Intelligence Is Already Here
Saudi Arabia Pauses Major Stretch of ‘The Line’ Megacity Amid Budget Re-Prioritisation
Saudi Arabia Launches Instant e-Visa Platform for Over 60 Countries
Dick Cheney, Former U.S. Vice President, Dies at 84
Saudi Crown Prince to Visit Trump at White House on November Eighteenth
Trump Predicts Saudi Arabia Will Normalise with Israel Ahead of 18 November Riyadh Visit
Entrepreneurial Momentum in Saudi Arabia Shines at Riyadh Forward 2025 Summit
Saudi Arabia to Host First-Ever International WrestleMania in 2027
Saudi Arabia to Host New ATP Masters Tournament from 2028
Trump Doubts Saudi Demand for Palestinian State Before Israel Normalisation
Viral ‘Sky Stadium’ for Saudi Arabia’s 2034 World Cup Debunked as AI-Generated
Deal Between Saudi Arabia and Israel ‘Virtually Impossible’ This Year, Kingdom Insider Says
Saudi Crown Prince to Visit Washington While Israel Recognition Remains Off-Table
Saudi Arabia Leverages Ultra-Low Power Costs to Drive AI Infrastructure Ambitions
Saudi Arabia Poised to Channel Billions into Syria’s Reconstruction as U.S. Sanctions Linger
Smotrich’s ‘Camels’ Remark Tests Saudi–Israel Normalisation Efforts
Saudi Arabia and Qatar Gain Structural Edge in Asian World Cup Qualification
Israeli Energy Minister Delays $35 Billion Gas Export Agreement with Egypt
Fincantieri and Saudi Arabia Agree to Build Advanced Maritime Ecosystem in Kingdom
Saudi Arabia’s HUMAIN Accelerates AI Ambitions Through Major Partnerships and Infrastructure Push
IOC and Saudi Arabia End Ambitious 12-Year Esports Games Partnership
CSL Seqirus Signs Saudi Arabia Pact to Provide Cell-Based Flu Vaccines and Build Local Production
Qualcomm and Saudi Arabia’s HUMAIN Team Up to Deploy 200 MW AI Infrastructure
Saudi Arabia’s Economy Expands Five Percent in Third Quarter Amid Oil Output Surge
China’s Vice President Han Zheng Meets Saudi Crown Prince as Trade Concerns Loom
US and Qatar Warn EU of Trade and Energy Risks from Tough Climate Regulation
AI and Cybersecurity at Forefront as GITEX Global 2025 Kicks Off in Dubai
EU Deploys New Biometric Entry/Exit System: What Non-EU Travelers Must Know
Ex-Microsoft Engineer Confirms Famous Windows XP Key Was Leaked Corporate License, Not a Hack
Israel and Hamas Agree to First Phase of Trump-Brokered Gaza Truce, Hostages to Be Freed
Syria Holds First Elections Since Fall of Assad
Altman Says GPT-5 Already Outpaces Him, Warns AI Could Automate 40% of Work
Trump Organization Teams with Saudi Developer on $1 Billion Trump Plaza in Jeddah
Archaeologists Recover Statues and Temples from 2,000-Year-Old Sunken City off Alexandria
Colombian President Petro Vows to Mobilize Volunteers for Gaza and Joins List of Fighters
Nvidia and Abu Dhabi’s TII Launch First AI-&-Robotics Lab in the Middle East
UK, Canada, and Australia Officially Recognise Palestine in Historic Shift
Dubai Property Boom Shows Strain as Flippers Get Buyer’s Remorse
JWST Data Brings TRAPPIST-1e Closer to Earth-Like Habitability
×