Skip to main content

Don’t touch that outlet: Public chargers could let hackers steal your data

public charger exploit phone chargers danger 0001
Image used with permission by copyright holder
There’s an unlikely danger lurking in the corner of every coffee shop, airport, conference center, and public library: Power strips and chargers. CNN reports that “compromised” outlets — chargers clandestinely commandeered by hackers — can wreak havoc on your smartphone.

“Just by plugging your phone into a [compromised] power strip or charger, your device is now infected, and that compromises all your data,” Drew Paik, an executive at Authentic8, told CNN.

Recommended Videos

Ne’er-do-wells with the right skill set can rewire USB charging stations to extract stored data when an unwitting user plugs in a smartphone — a process colloquially known as “juice jacking.” That’s easier said than done — both Android and iOS phones prompt users before a file transfer can begin — but a relatively new attack, “video jacking,” requires a lot less effort on the hacker’s part.

As demonstrated last year by researchers at Krebson Security, the “video jacking” method employs custom electronics hidden inside what appears to be a USB charging station. As soon as a vulnerable phone is connected to the appropriate cord, it’s pretty much game over: The machine records a video of everything tapped, typed, and viewed as long as the handset is plugged in, including PINs, passwords, emails, texts, pictures, and videos. Even worse, it’s completely silent — there’s generally no warning on the phone to alert the user that the device’s video is being piped to another source.

Not every smartphone’s equally vulnerable, to be fair. Certain models of iPhone, Android, and HDMI-ready smartphones from Asus, BlackBerry, HTC, LG, Samsung, and ZTE are at higher risk than others. But it’s an attack to which hundreds of people fall victim every day.

As an experiment, Authentic8 set up a hacked charging station at its RSA security conference booth in San Francisco earlier this week. Over the course of the following few days, it found that an overwhelming majority of attendees — about 80 percent — connected their phones without asking about the security.

“The majority are plugging in no problem. They are at a security conference and they should know better, but they probably feel safe,” Paik told CNET. “The others are making fun of them. They just walk by and say, ‘Do people really do that?'”

The safest alternative to a public power outlet is a portable USB battery pack, or a USB cord that doesn’t transmit data. But generally speaking, you’re safest relying on your own charger.

“If [you’re] concerned about security, don’t use public ports,” Paik told CNET. “If [you’re] desperate and need to upload your selfie, take your chances.”

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
I reviewed an electric car like it was a phone, and I came to a shocking conclusion
The front of the Cupra Born VZ.

The Cupra Born VZ is not a smartphone — it’s an electric car. Yet, during my time driving it over the last five days, it has reminded me more than once about the device I spend most of my time using and reviewing.

This is not a put-down, nor is it a comment on electric versus combustion-engine vehicles, but more about how I, someone who doesn’t professionally review cars, can still easily recognize what’s good and bad about it. What’s more, the categories I usually break phone reviews down into, and the language I regularly use to talk about them, also neatly applies to the Born VZ.

Read more
A must-try Android app has finally arrived on the iPhone
Person holding a phone with Google Gemini Live being shown.

A few days ago, Google Gemini appeared in the Apple App Store for a user in the Philippines, who was even able to download it. We took it as a sign that the new AI assistant would soon make its way to the App Store in the U.S. Well, we were right, as you can now download Gemini as a standalone app on your iPhone, after previously only being able to access it through a browser.

The Gemini app is free to download and has a surprising number of features available. More powerful functions are available for a $20-per-month subscription, but you can try Gemini Advanced out for one month for free. It grants priority access to new features and gives a "1 million token" context window.

Read more
We’ve got our first big clue about the Galaxy S25’s arrival
Samsung Galaxy S24 Ultra in Titanium Gray in hand.

The Samsung Galaxy S25 has had a tentative early 2025 launch date for months now, but we might finally have an actual date to look forward to. Samsung will hold its next Galaxy Unpacked event on January 23, according to FNNews, a South Korean website, with the Galaxy S25 series as the star of the show. It's the most precise date we have seen yet for the speculated Galaxy S25 announcement.

Take this news with some skepticism, though, as Samsung has not confirmed any dates for its Unpacked event yet. The report also states San Francisco is "a strong candidate" for the city to host the event. The last Galaxy Unpacked event was held in Paris in July.

Read more