USB ports exist for two purposes at once: transferring power and transferring data. That dual function is the source of a real and documented security threat — one that’s been growing as public USB charging infrastructure has expanded everywhere from airports and hotels to coffee shops, gyms, and conference centres.
Juice jacking is the attack where a compromised USB port or cable attempts a data connection while you’re charging your device. In the simplest form, the malicious charger copies data from your phone. In more sophisticated versions, it installs malware that persists after you unplug. Either outcome can expose photos, files, messages, credentials, and every other piece of personal data on your device.
The FBI’s cybersecurity division has issued formal warnings about juice jacking at public charging stations. The FCC has done the same. The EU’s USB-C standardization mandate — which has made USB-C the universal charging standard for phones, tablets, and laptops across the region — has created a homogenized charging ecosystem that’s broadly useful and simultaneously creates a standardized attack surface for malicious hardware.
How Juice Jacking Works
When you connect a phone to a USB port, the port negotiates a connection with your device. That negotiation establishes whether the connection is for power only or power plus data.
A malicious charging station can be configured to exploit that negotiation process. Instead of simply delivering power, it sends signals that attempt to open a data transfer session. On older devices with permissive defaults, this can happen without any visible indication to the user. On more recent iOS and Android versions, you’ll typically see a prompt asking whether you trust the connected device — but not everyone notices, not everyone knows what that prompt means, and not all attack methods trigger it.
Hardware attacks are one vector: a compromised charging kiosk or a malicious cable left at a “forgotten” cable station. Software attacks are another: some attacks use the data channel to deliver malicious code that exploits vulnerabilities in USB handling or device pairing logic. State-sponsored threat actors have used juice jacking as an entry vector for targeted espionage.
The 2026 threat landscape has evolved from the basic proof-of-concept juice jacking demonstrated at security conferences in the early 2010s. Attacks are faster, more automated, and in some documented cases, capable of exfiltrating significant amounts of data during a brief connection.
What’s at Risk
When your phone is unlocked and connected to a malicious USB port, the potential exposure depends on what’s stored on and accessible from the device.
Your photo library is an obvious target — and for most people, the camera roll contains years of accumulated personal, family, and professional content. Documents, notes, and files stored in on-device apps are similarly accessible. Saved passwords and authentication tokens, depending on how they’re stored and what security the device enforces, can be extracted by sufficiently capable malware. Active session cookies — the tokens that keep you logged into services — can allow an attacker to access your accounts without needing your credentials.
For people who store sensitive personal documents on their devices — scans of ID documents, financial records, health information, personal correspondence — juice jacking represents a breach of everything they’ve worked to keep private.
The risk is higher when:
- Your device is unlocked at the time of connection
- You’re charging at a public station where you don’t control the hardware
- You’re using a cable you found rather than one you own
- Your device is running an older operating system with unpatched vulnerabilities
The USB-C Factor
USB-C is now the dominant charging standard for most consumer electronics. Its adoption was mandated for smartphones and tablets in the EU, and the rest of the global market has largely followed. This standardization is genuinely useful — you can charge most devices with the same cable — but it has security implications that aren’t always discussed alongside the convenience story.
USB-C cables can carry not just power and data but also video signals (DisplayPort, HDMI via adapter), high-speed networking, and protocols like Thunderbolt that provide deep hardware access. A malicious USB-C cable or port has a significantly richer attack surface than an older USB-A connection.
USB-C cables also look identical regardless of their internal complexity. A standard charging cable and a cable with an embedded microcontroller (capable of acting as a keyboard, injecting commands, or intercepting data) are visually indistinguishable. These “O.MG cables” and similar attack tools have been available to researchers and threat actors for several years, and the capabilities have expanded significantly.
How to Know If You’re at Risk
The risk isn’t uniformly high. Juice jacking attacks require physical access to infrastructure — someone has to compromise or install a malicious charging point. Random attacks on random travelers are less common than targeted attacks on specific individuals.
That said, high-traffic locations are more economically attractive targets for those who do deploy these attacks: airports with thousands of daily travelers, conference venues where security professionals or executives gather, hotels popular with business travelers. Opportunistic attacks — malicious cables “left behind” for unsuspecting finders — are another vector that doesn’t require access to fixed infrastructure.
The populations most at risk are frequent travelers, people who regularly use public charging infrastructure, and anyone who works with sensitive information that would have value to an attacker. For everyone else, the risk is real but lower — and the countermeasures are simple enough that the question is whether to apply them, not whether you can.
How to Protect Yourself
The good news is that juice jacking is one of the more straightforward security threats to address. You don’t need technical expertise or new software. You need a few changes to how you charge.
Use your own charger and a wall outlet. This is the simplest and most complete protection. A standard wall outlet delivers power only — there’s no data channel. Your own charger connected to a wall socket cannot juice jack you. Carry your own charger as standard travel practice.
Carry a portable battery pack. A power bank eliminates the need to use public charging infrastructure entirely. Charge the power bank from your own charger at home or in your hotel room, then use it to top up your devices on the go. No public USB ports needed.
Use a USB data blocker. A USB data blocker — sometimes called a “USB condom” — is a small pass-through adapter that physically disconnects the data pins while allowing the power pins to pass through. Plugging your cable into the data blocker, then into a public port, means only power flows to your device. Data transfer is physically impossible. These are inexpensive, widely available, and small enough to keep on a keyring.
Enable USB restricted mode. iOS has a feature called USB Restricted Mode that disables the data transfer function of the Lightning or USB-C port after the device has been locked for an hour. Even if a malicious charger is connected to a locked iPhone that’s been idle, the data channel isn’t accessible. On Android, the setting varies by manufacturer but is typically found in Developer Options — “USB configuration” or “Default USB configuration” should be set to “Charging only.”
Never use a cable you didn’t bring. Cables left at charging stations, in hotel rooms, or given to you by strangers are a significant risk. A cable with an embedded microcontroller looks exactly like a standard cable. The cost of a malicious cable is low enough that leaving one where someone will find it is a viable attack vector. Use your own cables.
Keep your device up to date. Many juice jacking attacks exploit vulnerabilities in how devices handle USB connections. OS updates patch these vulnerabilities. A device running current software is meaningfully more resistant to USB-based attacks than one running an outdated version.
The Business Travel Angle
Juice jacking risk is elevated for business travelers, and the consequences of a successful attack extend beyond personal privacy.
A compromised business device may expose client files, internal communications, intellectual property, or authentication credentials that provide access to corporate systems. Many organizations have IT policies that specifically address public charging infrastructure for this reason — but those policies are often buried in security training material that nobody reads until after an incident.
If you travel for work, it’s worth checking whether your organization has specific guidance on public charging. If it doesn’t, the simple answer is to default to wall outlets and your own cables, and to treat any public USB port as a potential attack surface rather than a convenience.
The Physical Security Habit
Juice jacking is a useful case study in a broader category of security risk: attacks delivered through physical infrastructure that looks normal.
Most security thinking focuses on software threats — phishing emails, malicious downloads, credential theft through web forms. Physical attacks are less common but can be more difficult to detect, because the attack surface is something you interact with in the real world rather than online.
Building the habit of questioning public charging infrastructure is a reasonable update to a modern security posture. The inconvenience is small: carry a power bank, pack your own charger, buy a USB data blocker for under ten dollars. The protection is meaningful, and it extends to any public charging infrastructure you’ll encounter — now and as the attack techniques continue to evolve.
Your phone holds more personal data than most people held in their entire home a generation ago. The charging cable it connects to is a potential access point. That’s a strange fact of contemporary life, but it’s one worth factoring into how you carry and charge your devices.