Public USB charging ports at airports, hotels and shopping malls carry a small but real risk: a corrupted port or cable can quietly install malware on a phone the moment it starts charging, according to the Federal Communications Commission. The technique, known as juice jacking, exploits the fact that a standard USB cable carries both power and data on the same set of pins. Malware delivered this way can lock a device or export personal data and passwords directly to whoever controls the port. The FCC says the attack has been proven technically possible, though it has never confirmed a case happening outside a demonstration. The agency still treats the risk as real enough to publish a standing consumer advisory on how to avoid it, rather than dismiss it as theoretical.
How data and power share the same USB pins
A standard USB connector has five pins, but charging only needs one of them; two others handle data transfer by default. On most modern phones, that data channel stays disabled unless someone actively approves it, which is why plugging into an unfamiliar computer usually triggers a prompt asking whether to trust the connection. Older Android devices, and any port a criminal has modified to force that channel open regardless of the prompt, do not always ask first.
Security researchers describe two versions of the resulting attack: one that quietly copies data and passwords off the phone, and another that drops malware capable of locking the device outright. The FCC’s own guidance says a corrupted port can lock a device or export personal data and passwords directly to the perpetrator, who can then use that access to break into accounts or resell the stolen information. Neither version of the attack requires physical theft of the phone itself; the port or cable does the work while the owner assumes a normal charge is underway.
The 2011 airport kiosk that started the warnings
The term itself traces to a single conference booth rather than a wave of real thefts. At DEF CON in 2011, Brian Markus, president of the security firm Aires Security, built a public-looking charging kiosk with Joseph Mlodzianowski and Robert Rowley of the hacking-awareness group Wall of Sheep, then wired it to flash a warning instead of stealing anything. The kiosk’s screen warned each of more than 360 attendees who plugged in anyway that public kiosks should never be trusted with a smartphone, since information could be retrieved or downloaded without consent, then noted dryly that this particular booth had taken the ethical route and left visitors’ data alone.
One of those attendees later found that a USB transfer setting he believed he had switched off had “instantly went into USB transfer mode” the moment his phone touched the kiosk — the exact blind spot that gave the demonstration its point, and the moment security writer Brian Krebs coined the phrase “juice jacking” while covering the booth that week.
No confirmed cases, but repeated warnings
Despite that 2011 origin, and repeated warnings from federal agencies since, the FCC says it is still not aware of any confirmed instance of juice jacking happening to a real traveler outside a lab or a demonstration booth. That has not stopped the warnings from recurring. In April 2023, the FBI’s Denver field office told travelers on social media to “avoid using free charging stations in airports, hotels or shopping centers” because “bad actors have figured out ways to use public USB ports to introduce malware and monitoring software onto devices,” urging people to carry their own charger and cord instead. The FCC’s guidance and the Denver field office’s post make roughly the same recommendation independently, without either citing a specific victim by name.
Not every security researcher treats the threat as urgent. Allan Liska, a threat intelligence analyst at the cybersecurity firm Recorded Future, said of the FBI’s warning that “one of the challenges with the FBI tweet is that they don’t provide any real-world examples,” adding that while the attack remains technically feasible, “the risk is relatively low.”
Cheap defenses: outlets, cables and data blockers
The FCC’s own advice is low-tech. Pack an AC wall charger, a personal USB cable, or a portable battery pack rather than relying on a public port at all. When a port does prompt with a choice, selecting “charge only” instead of “share data” or “trust this computer” blocks the data channel outright. For anyone who wants a physical safeguard, a small adapter often called a USB data blocker passes power through while physically disconnecting the two data pins, typically for $10 to $20.
Fifteen years after a hacking-awareness booth invented the scenario to prove a point, the gap between what juice jacking could do and what it has actually done to a traveler in the wild remains exactly where Krebs and the FCC both left it: technically real, repeated in official advisories every few years, and still waiting for its first documented victim.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Older Teslas are wearing out in ways early owners never saw coming
- Early electric-car owners are hitting battery and screen failures no one warned them about
- A magnitude 5.3 quake struck off the Oregon coast this week
- Amazon’s Prime refunds are rising to $200 as millions more customers become eligible