The hidden dangers of public USB charging

Introduction
Smartphones have become an essential part of everyday life – We use them for just about everything from communication, banking, authentication, navigation, photography and accessing sensitive information.
Unfortunately, smartphones also have one problem that almost everyone encounters at some point – a low battery.
This creates an opportunity for attackers.
Public USB charging stations can appear to be a convenient solution when a phone is running out of power.
However, USB connections carry both electrical power and data, meaning that a charging connection can potentially become an attack vector.
This is the basis of juice jacking – Juice jacking is an attack where a malicious or compromised charging connection is used to attempt to access, manipulate or compromise a connected device.
What is juice jacking?
Juice jacking describes attacks that abuse the USB connection between a mobile device and a charging source. The important point is that USB was designed to do more than simply provide electricity.
A USB connection can provide:
- Electrical power
- Data communication
- Device identification
- Peripheral communication
A normal charger only needs the power functionality. A malicious charging station, however, may attempt to establish a data connection with the connected smartphone.
The attack therefore exploits the fact that the user believes they are connecting to a charger, when they may actually be connecting to a computer or other data-capable device.
Why USB can be dangerous
USB is an extremely versatile system. A single USB connection can allow devices to communicate with each other as well as transfer electrical power.
For example, connecting a smartphone to a computer can allow the computer to potentially interact with the phone. This is useful when transferring:
- Photos
- Videos
- Files
- Music
- Backups
However, it also means that USB represents a potential trust boundary.
If the device on the other end of the connection is malicious or compromised, the attacker may attempt to exploit that relationship.
How a juice jacking attack works
An attacker could compromise an existing public charging station or install a malicious charging device.
When a victim connects their smartphone because they need to recharge the battery, the charging station provides power, but may simultaneously attempt to establish a data connection.
An attacker could then attempt to exploit vulnerabilities or persuade the device to provide access.
Depending on the device, configuration and vulnerabilities involved, the attacker may attempt to access information, install malicious software or exploit the device.
One such example of a malicious charging device is the cable itself.
The O.MG cable is a hand made USB cable with an advanced implant hidden inside that can conduct various attacks against a connected device:
- Keystroke injection
- Mouse injection
- Malware payloads
- Keyloggers
- Encrypted communications
This is why using trusted charging equipment is generally preferable to using unknown cables.
Data theft
One potential objective of juice jacking is data theft. If an attacker can establish an unauthorised data connection, they may attempt to access information stored on the device.
Potential targets could include:
- Photos
- Documents
- Contacts
- Messages
- Application data
- Authentication information
However, modern smartphones generally include protections that prevent an unknown USB device from automatically accessing all of this information.
For example, the operating system may require the user to unlock the device or explicitly authorise a computer before data access is permitted.
This significantly reduces the risk compared with older devices.
Malware installation
Another potential objective is to use the USB connection to deliver malicious software. An attacker could attempt to exploit a vulnerability in the smartphone’s operating system or connected services.
If successful, this could potentially allow malware to be installed.
The malware could then potentially:
- Steal information
- Monitor activity
- Access applications
- Capture credentials
- Track the user
- Communicate with an attacker-controlled server
However, this generally requires an additional vulnerability or weakness – Simply connecting a modern smartphone to an unknown USB port does not automatically install malware.
Malicious charging stations
Public charging stations are particularly interesting from an attacker’s perspective because they provide access to multiple potential victims.
They may be found in:
- Airports
- Railway stations
- Hotels
- Shopping centres
- Conference venues
- Cafés
- Public transport facilities
The attacker does not necessarily need to know who will use the station – They simply need to create an opportunity for someone to connect their device.
This makes juice jacking an example of an attack that combines physical access, social engineering and technology.
potentially contain hardware capable of interacting with the connected device or computer.
Juice filming
A related concept to Juice Jacking is sometimes referred to as juice filming. Rather than primarily attempting to install malware, the objective is to obtain information from the connected device.
The distinction is useful because USB attacks do not necessarily have to involve malicious software.
The attacker may simply be interested in accessing or copying information.
The exact capabilities available to an attacker depend on the smartphone, operating system, USB configuration and security controls in place.
Modern smartphone protections
Modern smartphones are significantly better protected against USB attacks than many older devices. Operating systems can require the user to explicitly authorise a computer or other device before allowing data access.
Security mechanisms may include:
- Device locking
- USB access controls
- User authorisation
- Application sandboxing
- Encryption
- Secure boot
- Hardware-backed security
- Operating-system security updates
For example, a smartphone may display a warning asking whether the user wants to trust or allow access to a connected device.
This creates an additional security barrier, and the user should never automatically approve such a request when they only intended to charge the phone.
USB data blockers
One way to reduce the risk of a Juice Jacking attack is to use a USB data blocker.
A USB data blocker is designed to allow electrical power to pass through the connection while preventing the USB data lines from communicating.

This means that even if the charging station is malicious, the data connection is physically prevented.
However, a data blocker does not protect against every possible threat. It is primarily designed to prevent USB data communication while charging.
Detecting juice jacking
Juice jacking can be difficult to detect because the attack may occur while the victim is simply waiting for their phone to charge.
Potential warning signs include:
- Unexpected USB security prompts
- Requests to trust an unfamiliar device
- Unexpected file-transfer notifications
- Unusual device behaviour after connecting
- Applications behaving unexpectedly
- Unexpected security warnings
- A charging station that appears physically modified
However, the absence of obvious warning signs does not necessarily mean that a charging connection is trustworthy.
Preventing juice jacking
- Use Your Own Charger – The safest approach is to use your own charging equipment and connect it directly to a conventional electrical outlet.
- Avoid Unknown USB Charging Stations – If possible, avoid connecting your phone directly to public USB ports.
- Use a USB Data Blocker – A data blocker can allow charging while preventing USB data communication.
- Carry a Power Bank – A personal power bank removes the need to connect your smartphone to an unknown charging station.
- Don’t Trust Unknown Devices – If your phone asks whether you want to trust or allow access to a connected device, do not approve the request unless you know exactly what the device is.
- Keep Your Phone Updated – Operating-system updates can address vulnerabilities that could potentially be exploited through USB connections.
- Lock Your Device – Keeping your smartphone locked when connecting it to a charging source provides an additional layer of protection.
- Switch the phone off when charging – Most phones will still charge whilst powered off. This reduces but does not eliminate the ability of the phone to transfer data
Why Juice jacking matters
Juice jacking demonstrates an important security principle – Physical connections are security boundaries.
Users often think of a USB connection as simply a way of providing power, but USB can also provide a pathway for data and device communication.
This means a malicious charging station can potentially turn an everyday activity into a security risk.
Conclusion
Juice jacking exploits the dual-purpose nature of USB connections – A USB connection can provide power, but it can also provide a pathway for data communication and potentially malicious interaction.
Modern smartphones include significant protections against unauthorised USB access, meaning that simply connecting a phone to a malicious charger does not automatically result in compromise.
However, vulnerabilities, weak configurations or user interaction can potentially turn a charging connection into an attack vector.
The simplest defence is also one of the most effective – If you don’t trust the USB port, don’t connect your phone to it.
Use your own charger, a conventional power outlet, a trusted power bank or a USB data blocker whenever possible.