Juice Jacking: Can a Public Charger Actually Steal Your Phone?
Free: How to Keep Yourself Safe From Scammers
9 chapters. Reporting checklist. 30-second protection checklist. Read on the site.
Juice Jacking: Can a Public Charger Actually Steal Your Phone?
Gate B14, phone at 4%, boarding in eleven minutes. There's a charging kiosk bolted to the wall with a USB-C cable already dangling from it, like someone left it out just for you. You plug in. Nothing looks wrong. Nothing ever does — that's the whole point of an attack that lives inside a piece of infrastructure instead of a suspicious text.
That's "juice jacking": a rigged public USB port or cable that pulls data off your phone, or pushes malware onto it, while it's supposedly just charging. It's been a talking point since 2011, dismissed by plenty of security writers as overhyped along the way. Then in 2025, a team of Austrian researchers published a working attack that quietly makes the old dismissal outdated.
How this one actually works
Every USB connection carries two things down the same cable: power and data. A charger only needs the power pins. A malicious one uses both.
For about a decade, phones have defended against exactly this with a simple gate: plug into an unfamiliar USB device, and the phone asks you to approve the data connection — the "Trust This Computer?" or "Allow access?" prompt you've probably tapped through without thinking. No tap, no data transfer. That single confirmation dialog is the reason juice jacking mostly stayed theoretical for years.
In August 2025, researchers Florian Draschbacher, Lukas Maar, Mathias Oberhuber, and Stefan Mangard from Graz University of Technology presented an attack called ChoiceJacking at the USENIX Security Symposium. Instead of trying to sneak data past the prompt, it fakes the tap: a rigged charger can impersonate a USB keyboard or a Bluetooth input device and simulate the "Allow" press itself, all before you'd notice anything happening on screen. Their paper clocked the whole thing at roughly 133 milliseconds — faster than a blink — tested successfully against a range of Android and iOS devices running at the time. It's the first new attack to get past that decade-old confirmation prompt.
Apple has since closed the specific hole: starting with iOS 18.4, connecting a new USB accessory requires your device passcode or Face ID, not just a tap, which blocks the known ChoiceJacking technique. That's the pattern with this stuff — a real vulnerability gets published, a patch follows, and the fix only helps you if your phone is actually running it.
Not sure if your message is real? Paste it into Cautellus and get a risk score before you reply.
Scan it now →Or: Get the Chrome extension to scan pages without leaving your browser.
Why this one is harder to spot than a phishing text
Almost everything else on this site lives in a message you can read and pick apart: a link, a phone number, an urgent deadline. Juice jacking doesn't give you a message to inspect. There's no bad grammar, no spoofed sender, no countdown timer pressuring you into a mistake. It's a physical object sitting in public, doing the one job it appears to do — charging your phone — while quietly doing a second job you can't see.
That's also why the FBI's Denver field office got attention, and pushback, for a 2023 warning telling travelers to avoid free public charging stations. Neither agency pointed to widespread real-world victims, and CBS News noted there wasn't hard evidence the attack was happening at scale. Fair criticism of the alarm level — but not the same thing as the attack not being real. The 2025 research is the update: the capability got sharper, so the old "don't worry about it" take is worth revisiting.
The red flags hiding in plain sight
There's no message to reread here, but the hardware and the setting still leave tells:
- A cable already plugged in and dangling. Public charging spots don't usually supply the cable for you — one pre-attached and ready to go is doing you an unusual favor.
- A USB-only port with no ordinary outlet nearby. No simple AC outlet in sight is a design choice, not a coincidence.
- A permission prompt the moment you connect. Any pop-up asking to "Trust," "Allow," or pair a new device the instant you plug in is your phone asking permission to do the one thing a legitimate charger never needs.
- A generic, unbranded kiosk with no visible owner. No airline logo, no venue signage, no maintenance sticker — just a box, with nobody accountable for what's inside it.
- Placement right past security or in a single choke-point hallway. High foot traffic in one predictable spot is where this kind of setup gets the most phones for the least effort.
- A charging locker that also offers USB pass-through instead of just power. That's functionally the same risk as a wall kiosk.
- "Free charging" stations that appeared suddenly at a one-time event. Conferences, festivals, and pop-ups are common spots for temporary, unaccountable hardware nobody can trace back tomorrow.
If this already happened to you
Don't panic, and don't throw the phone away. Work through it in order:
- Unplug it. That stops anything further from happening through that connection.
- Think back to whether you tapped anything. The prompt you approved — "Trust," "Allow," a pairing request — is the moment that actually mattered, not the act of plugging in.
- Update your OS immediately. Security patches (including the fix for ChoiceJacking-style attacks) only protect you once installed.
- Check Bluetooth and paired/trusted device lists for anything you don't recognize, and remove it.
- Change passwords on sensitive accounts — email, banking, anything with saved payment info — from a different device you trust, not the one that was just plugged in.
- Watch for the second wave. A common pattern after any account compromise is a follow-up text or email about a "suspicious purchase" or "locked account." That message is its own separate scam riding on the first one — scan it before you click or call anything in it.
- If you have real reason to think malware landed and won't clear, back up your important files through your cloud account (not the suspect device's local storage) and do a full factory reset.
If you're worried your accounts or credentials showed up somewhere they shouldn't after all this, Cautellus's breach checker will tell you whether your email is tied to a known leak.
How to not become the next data point
The fix here isn't vigilance — there's nothing to watch for when the danger looks exactly like an ordinary charger. The fix is making the port irrelevant:
- Bring your own brick and cable, and use an actual outlet. No data pins involved, nothing to compromise.
- Carry a portable battery pack so you're never dependent on public infrastructure at all.
- Or carry a USB Data Blocker — a small adapter that strips the data pins out of any USB connection, so a public port only ever sends power. Plug it in once and every kiosk or hotel nightstand becomes as safe as your own wall outlet.
- If you're a frequent flyer or a student living out of a backpack, a Travel Laptop Backpack with USB Charging Port with a built-in port wired to your own power bank does the same job passively.
- Keep your phone's OS updated. The fix for ChoiceJacking-style attacks is a software patch, and it only works if you've installed it.
- Decline "Trust This Computer" and pairing prompts from anything you didn't plug in at home or work. That single tap is the whole attack surface.
None of this replaces good judgment about the messages that show up on your phone — a data blocker won't catch a fake QR code taped over a parking meter or a scam text that arrives an hour later. If you've already clicked something you're not sure about, here's exactly what to do in the next few minutes. If you're already the kind of person who carries a backup hardware security key for phishing, this is the same instinct applied to the plug in the wall — the shop has the short list of gear we'd actually hand to family, including the two items above.
Got something like this in your inbox? Drop it into the scanner — it takes 5 seconds and could save you thousands.
Check it now →Already been scammed? See where and how to report it.
FAQ
Is juice jacking actually real, or is it internet paranoia? Both things are true at once. There's no evidence of juice jacking happening to regular travelers at scale — the FBI and FCC have both said as much. But the technical attack is completely real: in 2025, researchers at Graz University of Technology published a working method that beats the phone-side protection built to stop it. "Rare" and "fake" aren't the same thing, and this one's cheap to make irrelevant.
Does my phone already warn me if a charger is trying to steal data? It's supposed to. Since the early 2010s, Android and iOS have required you to tap "Trust This Computer" or approve a data connection before a USB device can pull files. The 2025 ChoiceJacking attack found ways to fake that tap — spoofing a keyboard or Bluetooth signal to hit "Allow" without you touching the screen. Apple closed that specific hole starting with iOS 18.4, which requires your passcode or Face ID for a new USB connection. Keep your OS updated and that protection stays current.
Will a phone case or a different charging cable protect me? Only if the cable is doing the protecting on purpose. A USB data blocker (sometimes called a "USB condom") is a small adapter that physically removes the data pins from the connection, so only power gets through — a rigged port or cable has nothing to talk to. Your regular charging cable does nothing; it's built to carry both power and data.
I think I plugged into a bad charger. What do I actually check? Unplug first. Then check whether you tapped "Trust," "Allow," or approved any pairing request while it was connected — that's the moment that matters. Update your phone's OS, check Bluetooth and paired-device lists for anything you don't recognize, and change passwords on sensitive accounts from a different device you trust. If you get a follow-up text about a "purchase" or "account alert" afterward, scan it before you touch it — that's a separate scam riding on the first one.
Are airports really the riskiest spot for this? They're the highest-traffic spot, which is what matters to someone running this at scale — a single rigged kiosk near a security line reaches far more phones than one placed somewhere quiet. Hotels, conference centers, and shopping malls carry the same underlying risk for the same reason: a public USB port with no owner you can identify.
A charger that only wants to give you power has nothing to hide. Bring your own, and the whole category of attack stops being your problem.
Sources: CBS News — FBI office warns against public phone charging stations · USENIX Security 2025 — ChoiceJacking: Compromising Mobile Devices through Malicious Chargers
Think you've been targeted? Paste any text, link, email, or screenshot into Cautellus for instant AI analysis.
Check something now →Want unlimited scans + the Chrome extension? See pricing.
Courtney
Founder, Cautellus · 20+ years in financial services
Two decades in financial compliance, digital security, and fraud prevention. Built Cautellus because the scam detection tools that exist were made for IT departments, not for real people getting weird texts.
Learn moreKeep reading
Support Our Mission
Cautellus is built to protect people from online fraud. Your contribution helps us keep building security tools and resources.