Reviewed and updated in October 2026.
USB ports were introduced on computers to replace parallel, PS/2 and serial ports for printers, scanners and mice, and USB devices have now been part of our lives for around 30 years. USB is the standard for charging mobile and portable devices, and USB charging ports are everywhere, from coffee shops to airports. USB flash drives have largely replaced writable discs as the way to exchange documents between devices quickly and easily. However, you need to be careful what you plug in and where, because USB remains one of the easiest ways for attackers to gain physical access to a system.
Most charging stations and ports in public places are legitimate, but some may have been tampered with to damage your device or even contain a small computer, such as a Raspberry Pi, that tries to connect to your device and copy data from it. This is often called "juice jacking". The best option is still to use your own charger and plug it into a power socket.
Current smartphones make this harder than it used to be. An iPhone or iPad asks whether you trust a connected computer before it exchanges data, and you can control whether USB accessories may connect while the device is locked. On Android, file transfer has to be switched on by the user after connecting. These prompts only help if users read them, so do not confirm a request you did not expect while charging.
The same applies when you connect a USB stick or external drive to a computer to copy documents. Make sure you know who the device comes from, where it has been and what it is supposed to contain. Your computer should have malware protection that scans it for viruses, trojans and other threats.
This attack vector has made it into film and TV. In an episode of the first season of Mr. Robot, the hackers drop USB sticks in the parking lot of a prison, hoping someone will pick one up and plug it into a computer on the prison network. A police officer does exactly that, but antivirus software detects the malware and the attack fails. In real life, you want the same outcome: the stick gets plugged in, and your protection catches it.
Ideally, use a dedicated computer, isolated from your local network, to plug in and scan an unknown USB device first. If it is clean, copy the documents to your computer via another trusted device. This may seem impractical, but it also protects your main device from a USB killer, a device that looks like a regular USB stick but sends high-voltage surges into the device it is connected to and can destroy hardware components. These precautions may sound excessive for a seemingly harmless USB stick, but the attack potential is well established.
One of the best ways to ensure your data is not compromised is to secure your devices. From an enterprise perspective, you want to prevent unauthorized access to any device, personally owned or corporate owned, depending on where corporate data resides. Your UEM software should already include USB-related policies that control how the USB port can be used. Some examples:
And for users:
This post is part of our Everyday Security Risks series, which started with QR codes at restaurants and continues with Wi-Fi. For more on keeping data inside managed boundaries, see Demystifying Security: Data Loss Protection (DLP).
Need help defining USB and device policies across your fleet? Our team supports endpoint management projects end to end, and our trainings cover UEM policies in depth. If you have questions about improving your security posture, contact us.