The FBI has warned the public to stay away from free USB charging stations found in areas like airports, hotels, and shopping centers.
In a tweet last week, the FBI’s Denver office said that cybercriminals have figured out ways to introduce malware and monitoring software onto devices through such public charging stations. Federal agencies and cybersecurity experts refer to this malicious activity as “juice jacking.”
Interestingly enough, this is not a recent phenomenon, though the FBI’s warning has just brought it back into the spotlight. In 2021, the Federal Communications Commission (FCC) issued a public advisory warning people about the dangers of juice jacking.
The Los Angeles District Attorney also issued a public advisory to travelers in 2019, warning that public USB charging points may contain dangerous malware. The advisory is no longer available on the LA District Attorney’s Office website.
Carry Your Own Charger/USB Cord, Use Electrical Outlet Instead: FBI, FCC
The FBI’s message clearly warns people against using public USB ports, urging them to instead use their own chargers and USB cables, and to rely solely on electrical power outlets. The tweet echoes language in the FBI’s general advisory on scams and staying safe on the internet.
The FCC’s 2021 advisory also recommended that users rely on electrical outlets and their own USB cables, or use their own portable chargers or external batteries.
“Malware installed through a dirty USB port can lock a device or export personal data and passwords directly to the perpetrator. Criminals can use that information to access online accounts or sell it to other bad actors,” the FCC said.
It also urged them to use charging-only cables from a trusted supplier, which would block the transfer of any data while charging. The FCC also warned that unsecured public WiFi networks — such as those offered in cafes, hotels, airports, and other travel hubs — are another medium for bad actors to target travelers.
Juice Jacking Capabilities Remain Unclear
Multiple warnings from federal agencies and other branches of government indicate that juice jacking is a viable public concern. However, it is currently unclear exactly what a malicious actor can achieve through juice jacking. Despite the FCC’s warnings, there is very little public knowledge of a successful “in-the-wild” juice jacking incident.
These concerns first surfaced after the LA District Attorney’s warnings in 2019. Cybersecurity experts pointed out that most juice jacking incidents they found were proof-of-concepts and not active attacks. Cybersecurity researcher and editor Paul Wagenseil pointed this out once again after the FBI’s advisory.
However, despite skepticism in some corners, the existence of multiple proofs-of-concept examples, coupled with the multiple advisories, is enough reason to keep your guard up.
Apart from following the FCC’s guidelines, it is a good idea to use security tools on your devices when traveling, like antivirus and a VPN. Antivirus can stop malware in real-time or remove it if it’s already found its way onto your device. For unsecured public Wi-Fi, a VPN protects your internet connection, traffic, and any sensitive data that hackers or other interested third parties might be interested in.
