The FBI’s 2023 warning about free USB charging stations at airports, hotels and shopping centres drew attention to a threat commonly known as “juice jacking”: the possibility that a compromised port or cable could use a charging connection to access data, exploit a device or introduce malicious software.
The warning was useful because USB is not only a power standard. Many USB connections also support data transfer and accessory control. A device connected to an unknown port is therefore establishing a physical relationship with equipment it does not control.
The risk nevertheless requires careful framing. Researchers have demonstrated malicious charging stations, modified cables and USB-based attacks in controlled environments, but public evidence of widespread criminal campaigns targeting modern smartphones through airport or hotel charging ports remains limited. Modern operating systems also include permission, locking and accessory controls that make indiscriminate compromise more difficult than early warnings sometimes implied.
For a FinCrime audience, the importance lies less in the station itself than in what the mobile device represents. A smartphone can hold banking applications, email, authentication codes, digital wallets, passwords, identity documents and access to corporate systems. Compromising it—or manipulating the user into approving an unexpected connection—can create routes into account takeover, payment fraud, identity theft and business compromise.
Key Takeaways
- Public USB Charging Ports Can Create Cybersecurity Exposure
- “Juice Jacking” Can Exploit the Data Capabilities of USB Connections
- Compromised Charging Ports May Be Used to Install Malware
- Malicious USB Connections Can Enable Data Theft and Device Monitoring
- Airports, Hotels and Shopping Centres Represent Higher-Exposure Environments
- Mobile Device Compromise Can Lead to Wider Identity and Financial Fraud
- Stolen Credentials Can Enable Account Takeover
- Compromised Devices Can Expose Banking and Payment Information
- Public Charging Risk Demonstrates the Convergence of Cyber and Financial Crime
- Physical Access Points Can Become Digital Attack Vectors
- Using a Personal Wall Charger Reduces Exposure to Untrusted USB Infrastructure
- Portable Power Banks Provide a Safer Alternative to Public USB Ports
- Public Wi-Fi Can Create Additional Risk When Combined With Device Compromise
- Cybersecurity Hygiene Is an Important Component of Financial Crime Prevention
Listen the podcast
Watch the video
Why USB charging creates a security question
A traditional electrical socket supplies power without negotiating access to the connected phone. A USB port can supply power while also supporting communication.
A malicious or modified port could attempt to identify the device, request a data relationship, imitate an accessory or exploit a weakness in the operating system or USB implementation. The same principle applies to cables: an ordinary-looking cable may contain additional electronics, while an unknown adapter may behave differently from a simple power supply.
This does not mean that connecting to any public USB port automatically exposes a phone. On a current, properly configured device, meaningful access may require the device to be unlocked, a trust prompt to be approved, a data-transfer mode to be selected or an unknown vulnerability to be exploited.
The risk is conditional. It depends on the device, operating-system version, configuration, cable, port and attacker capability.
How a malicious connection could be used
The most frequently discussed scenario is unauthorised data access. A compromised charging system could attempt to establish a data connection and retrieve information made available by the device.
A second scenario involves malware delivery. This would normally require an exploitable weakness, unsafe configuration or user interaction. An attacker might imitate a computer or accessory and persuade the user to approve the connection.
A malicious USB device may also present itself as something other than storage, such as a keyboard or network adapter. This class of BadUSB-style attack exploits the difference between what the hardware appears to be and what it can actually do.
The common feature is inherited trust. The phone treats the cable or port as a potential accessory, while the user treats it as a source of electricity.
The evidence is more limited than the headlines
The FBI Denver message advised travellers to avoid free charging stations and use their own charger and cable with an electrical outlet. Similar precautionary guidance has been issued by other authorities.
Those warnings did not establish that airports and hotels were experiencing a documented wave of compromised charging points. CISA later noted that reports about criminals rigging public stations had not cited supporting evidence and used the discussion to raise a broader secure-by-design question: why should a device accept unnecessary risk merely because the user needs power?
The correct conclusion is not that juice jacking is impossible. USB-based attacks have been demonstrated, and targeted actors may have greater capability than ordinary criminals. The conclusion is that the threat should be assessed proportionately and mitigated through simple controls that cost little.
Modern phones have reduced the attack surface
Device manufacturers have added controls intended to prevent automatic data access through an unknown connection.
Current iPhones and iPads generally require the device to be unlocked before communicating with a new wired accessory or computer. Users can require manual approval for accessories, while managed devices can have those settings controlled centrally.
Android devices normally present a notification or selection when a USB connection supports functions beyond charging. File transfer or debugging should not occur merely because the phone receives power. Supported devices using Android’s Advanced Protection features can apply stronger restrictions to USB data connections.
These protections do not justify approving unexpected prompts. A tired traveller may press “allow” without reading it, while an outdated, rooted or jailbroken device may lack current safeguards.
Why mobile compromise becomes a financial-crime risk
The smartphone has become an identity and authentication hub. It may provide access to email, banking, payment cards, cryptoasset wallets, cloud storage, password managers and messaging accounts.
Email access can allow password resets and reveal financial relationships. Control of notifications may support impersonation or suppress warnings. A compromised banking session may expose balances, beneficiaries and transaction history.
A charging connection does not automatically bypass banking controls. However, device compromise can provide intelligence or persistence that supports later social engineering, credential theft or account takeover.
Corporate devices create wider exposure. A phone belonging to an executive, finance employee, investigator or compliance officer may contain privileged communications, authentication applications and access to internal systems. A targeted compromise could become an entry point for business-email compromise, data theft or payment diversion.
The relevant FinCrime question is not whether a charger can directly empty a bank account. It is whether an untrusted physical connection can help compromise the identity, communications or authentication layers protecting financial activity.
Public Wi-Fi is a separate risk
Charging-station warnings are often combined with advice about public Wi-Fi, but the threats should not be conflated.
A USB attack relies on a physical data connection. Public Wi-Fi exposes the device to an untrusted network and creates risks involving fraudulent hotspots, traffic manipulation and attempts to exploit network services.
A virtual private network can reduce some network exposure, but it does not make fraudulent websites genuine and does not protect against a malicious USB accessory. Each control addresses a different layer.
What a resilient personal control stack looks like
The simplest control is to carry a trusted wall charger and cable. Connecting that charger to an ordinary electrical outlet separates the phone from the data capabilities of a public USB port.
A portable battery pack is another practical option. Wireless charging can avoid a wired data connection, although the equipment should still be physically trustworthy.
A charge-only cable or trusted USB data blocker can prevent data conductors from connecting while allowing power to pass. These accessories should come from a reputable supplier; an unknown protective device simply replaces one untrusted component with another.
The phone should remain locked while charging. Prompts asking to trust a computer, allow an accessory, transfer files or enable debugging should be rejected unless the user deliberately initiated that function.
Operating systems and applications should be updated promptly. USB debugging should remain disabled unless genuinely required, and rooted or jailbroken devices should not be used for sensitive financial or corporate activity.
Strong screen locks, multifactor authentication, device encryption and remote-location or wiping functions reduce the consequences of theft, loss and wider compromise.
Higher-risk travellers need stronger measures
The average consumer and a high-risk individual do not face the same threat model.
Executives, government officials, journalists, lawyers, investigators and employees carrying commercially sensitive information may be targeted by actors willing to invest in tailored hardware and physical access.
Organisations should consider hardened or travel-only devices containing the minimum necessary data. Mobile-device management can restrict USB accessories, enforce updates, control applications and support remote wiping.
Sensitive work should remain on managed devices. After higher-risk travel, equipment may require review before reconnecting to critical systems.
The objective is data minimisation. A device without long-term credentials, historical messages or broad corporate access offers an attacker less value.
What to do after an unexpected USB event
A user who sees an unexplained trust, pairing, file-transfer or debugging prompt should reject it and disconnect.
If the phone behaved unusually, became unlocked during the connection or access was approved accidentally, account activity should be reviewed from a separate trusted device. Passwords may need to be changed, beginning with email and primary identity accounts. Active sessions and registered devices should also be checked.
Corporate users should report the event to security or IT teams immediately. Rebuilding or replacing a managed device may be appropriate where sensitive information was exposed and the incident cannot be assessed confidently.
The location, time and equipment should be recorded and reported to the venue if tampering is suspected. Users should not dismantle the station themselves.
What operators and manufacturers should do
Airports, hotels and transport providers should not place the entire burden on travellers. Charging equipment should provide power without unnecessary data functionality.
Ports should be physically protected, inspected for tampering and isolated from venue networks. Clear labelling can explain whether a port is power-only, while staff should have a process for investigating suspicious cables, overlays or damaged equipment.
Manufacturers should continue reducing the trust granted to newly connected accessories. Secure defaults, explicit permission prompts and locked-device restrictions are more effective than expecting every traveller to understand USB architecture.
Routine charging should not require a user to make a high-stakes cybersecurity decision.

What this means for financial crime leaders
The charging-station warning should not be treated as evidence of a major standalone fraud typology. It is a case study in how physical access, device security and financial identity now converge.
For financial institutions, mobile-risk controls should connect device integrity, session behaviour, authentication changes and transaction monitoring. A newly compromised device may produce unusual logins, recovery changes, wallet enrolment or payment behaviour before the customer recognises the problem.
Organisations should also avoid placing responsibility entirely on users. Managed-device restrictions, secure authentication and rapid session revocation can limit the impact when an employee connects to untrusted equipment.
The practical lesson is proportionate rather than alarmist. Public USB compromise is technically credible, but the everyday risk can be reduced almost completely by carrying a trusted charger or battery pack and refusing unexpected data permissions.
The deeper FinCrime lesson is that power, data and identity now travel through the same device. Security controls must recognise that a moment of charging can also become a moment of trust—and that attackers profit when those functions are treated as the same thing.
What Financial Institutions Should Consider
- Treat Compromised Devices as Potential Financial Crime Indicators
- Strengthen Device Intelligence and Device Risk Scoring
- Monitor Unusual Logins Following Device Changes
- Detect New Devices Accessing Existing Customer Accounts
- Apply Risk-Based Reauthentication to Suspicious Sessions
- Strengthen Account Takeover Detection
- Monitor Credential and Session Compromise Indicators
- Connect Device, Authentication and Transaction Intelligence
- Detect Unusual Beneficiary Creation Following Suspicious Logins
- Monitor Rapid Funds Movement After Device Compromise
- Strengthen Mobile Banking Application Security
- Implement Strong Session and Token Management
- Apply Phishing-Resistant Multi-Factor Authentication
- Integrate Cyber Threat Intelligence With Fraud Monitoring
- Monitor Downstream Fraud Following Malware Infection
- Train Customers on Public Charging and Device Security Risks
- Integrate Cyber, Fraud and Identity Investigation Teams
- Treat Device Compromise as a Potential Precursor to Financial Fraud




Warnings about public USB charging should be treated proportionately. There is limited evidence of widespread criminal campaigns compromising airport or hotel charging stations, but the technical risk is credible because USB connections can carry data as well as power.
For travellers, the simplest protection is to use a trusted wall charger, personal cable or portable battery pack and reject unexpected prompts requesting device access, file transfer or accessory approval. Keeping devices updated, locked and protected by strong authentication further limits potential exposure.
For organisations and financial institutions, the wider concern is the role of the smartphone as an identity and authentication hub. A compromised device may provide access to email, banking applications, payment credentials, corporate systems and security codes, creating opportunities for account takeover and follow-on fraud.
Ultimately, the issue is not whether every public charging station is dangerous. It is whether users should grant an unknown device a potential data connection when they only need electricity. Separating power from data is a simple control that removes most of the risk.