Travelbinger
TravelbingerTravel deals, guides and hacks
Travel News
Trip Planner
Sign In
Travel tips

Why Tech Experts Warn Against Using Airport Lounge USB Ports

Marco Kopinke

Marco Kopinke

September 25, 2026 · 9 min read

Share:
Why Tech Experts Warn Against Using Airport Lounge USB Ports
Add as a preferredsource on Google

Anyone who has raced through a terminal to catch a connecting flight knows the small relief of spotting a free USB port tucked into an airport lounge armchair. It seems harmless enough, just a quick top-up before boarding. Yet cybersecurity professionals, federal agencies, and even airport operators have spent the last few years sounding the alarm about exactly this habit, warning that those innocent-looking charging ports could be doing more than just filling your battery.

The concern has a name that sounds almost too dramatic to be real: juice jacking. It refers to the practice of tampering with public USB charging stations or cables so that instead of only delivering power, they also open a data channel that can be used to snoop on or infect a connected device. The warnings have persisted for well over a decade, and in 2025 they gained new life with a fresh piece of research that reignited debate over just how vulnerable modern phones really are.

The Origins of the Juice Jacking Warning

The Origins of the Juice Jacking Warning (Image Credits: Pexels)
The Origins of the Juice Jacking Warning (Image Credits: Pexels)

The term itself dates back to 2011, when security researchers at the DEF CON hacker conference in Las Vegas set up a booth to prove a point. The threat first came to light at the 2011 DEF CON hacker conference, when security researchers Brian Markus, Joseph Mlodzianowski, and Robert Rowley from Aries Security placed a malicious charging kiosk in the infamous “Wall of Sheep” area.[1] That demonstration was designed to show attendees how a seemingly ordinary charging kiosk could quietly access a connected phone.

What started as a proof of concept has resurfaced again and again over the years. The FBI’s Denver office tweeted about this threat back in 2023, and the LA County District Attorney’s office posted about it in 2019.[2] Researchers have kept the topic alive too, and as recently as 2016 the same Wall of Sheep team demonstrated an updated version of the attack, showing that the underlying vulnerability of USB connections was not going away just because a decade had passed.

What Federal Agencies Are Actually Saying in 2026

What Federal Agencies Are Actually Saying in 2026 (Image Credits: Pexels)
What Federal Agencies Are Actually Saying in 2026 (Image Credits: Pexels)

The warnings are not just internet folklore. On March 5, 2025, the U.S. Transportation Security Administration posted a public service announcement on its verified Facebook account, stating that hackers can install malware at USB ports, a practice they’ve been told is called “juice/port jacking.”[3] The agency’s advice was blunt: when you’re at an airport, do not plug your phone directly into a USB port, and instead bring your TSA-compliant power brick or battery pack and plug in there.[2]

The Federal Communications Commission has maintained similar guidance for years now. Cybersecurity experts warn that bad actors can load malware onto public USB charging stations to maliciously access electronic devices while they are being charged.[4] The agency explains that malware installed through a corrupted USB port can lock a device or export personal data and passwords directly to the perpetrator, and criminals can then use that information to access online accounts or sell it to other bad actors.[4] Even airport operators have taken notice, with major hubs adjusting their maintenance routines in response. New York and New Jersey Port Authority airports, which operate JFK, Newark, and LaGuardia, conduct regular inspections of charging stations for signs of tampering, according to a spokesperson.[5]

The Uncomfortable Truth: No Confirmed Real-World Cases

The Uncomfortable Truth: No Confirmed Real-World Cases (Image Credits: Unsplash)
The Uncomfortable Truth: No Confirmed Real-World Cases (Image Credits: Unsplash)

Here is where the story gets more complicated than the headlines suggest. Despite more than a decade of official warnings, nobody has actually documented a confirmed juice jacking attack happening to an ordinary traveler in the wild. A 2023 Ars Technica investigation reached the conclusion that there are no documented cases of public charging station juice jacking on modern iOS or Android devices, and Apple told the outlet it was unaware of any such attacks in the wild.[6]

Even the agencies issuing the warnings acknowledge this gap. The Federal Communications Commission notes that there are no confirmed instances of juice jacking occurring, though they acknowledge it has been demonstrated as technically possible.[5] A hacking researcher interviewed by Ars Technica put it plainly, noting that “if nobody can point to a real-world example of it actually happening in public spaces, then it’s not something that is worth stressing about for the general public.”[7] That does not mean the concern is fabricated, but it does mean travelers should understand the difference between a theoretical vulnerability and an active, widespread crime wave.

Why the Threat Is Still Taken Seriously by Researchers

Why the Threat Is Still Taken Seriously by Researchers (Ecole polytechnique / Paris / France, Flickr, CC BY-SA 2.0)
Why the Threat Is Still Taken Seriously by Researchers (Ecole polytechnique / Paris / France, Flickr, CC BY-SA 2.0)

The absence of confirmed cases has not stopped academic researchers from proving, again and again, that the attack is technically achievable. Back in 2013, a team at Georgia Tech demonstrated that a modified charging station could install malware on an iPhone in under a minute without any interaction from the user, using a repackaged app containing a malicious payload. That early proof of concept is part of why agencies have never fully dropped their guard, even without street-level evidence of victims.

More recently, the threat evolved into something researchers call ChoiceJacking, a technique that goes further than the original juice jacking concept ever did. This USB attack subverts protections on Android and iOS devices by using malicious chargers to spoof user consent dialogs and silently access sensitive data, bypassing long-standing defenses against the original juice jacking threat.[8] Unlike the old-school version, which mostly relied on victims not noticing a data prompt, this newer method is designed to defeat the very safeguards phone makers built specifically to stop juice jacking.

How ChoiceJacking Changed the Conversation in 2025

How ChoiceJacking Changed the Conversation in 2025 (Image Credits: Pexels)
How ChoiceJacking Changed the Conversation in 2025 (Image Credits: Pexels)

Security researchers from Austria’s Graz University of Technology unveiled ChoiceJacking at a major security conference, and it forced the industry to rethink assumptions that had held for nearly a decade. ChoiceJacking allowed a malicious USB charger to autonomously spoof user input and enable data transfer or code execution on eleven Android and iOS devices without user consent.[3] Even more unsettling, ChoiceJacking extracted files successfully from two locked devices.[3]

Part of what makes this technique effective is its timing. The researchers timed the attacks to occur when the user is least likely to notice unusual screen activity, such as screen flickering.[3] One technical breakdown of the research noted that the deceptive prompt appears and disappears in a fraction of a second, meaning anyone who plugs their device in to charge often continues using it and has no real chance of seeing the pop-up, let alone canceling it.[9] Fortunately, the response from device makers was relatively swift. Both Apple and Google blocked these attack methods in iOS/iPadOS 18.4 and Android 15, respectively, and now confirming USB data transfer requires biometric authentication or a password rather than just tapping “Yes.”[10]

The Bigger Risk Might Not Even Be the USB Port

The Bigger Risk Might Not Even Be the USB Port (Image Credits: Pexels)
The Bigger Risk Might Not Even Be the USB Port (Image Credits: Pexels)

Several cybersecurity professionals argue that travelers are worrying about the wrong threat entirely. During a recent interview, one cybersecurity CEO explained the mechanics simply, pointing out that public charging ports don’t only transfer power, they also transfer data, and they can transfer it both ways.[5] Still, the same expert suggested that the far bigger danger at airports is not the charging cable at all. Cybersecurity experts warn that unsecured Wi-Fi networks pose an even greater risk than compromised charging stations,[5] since it is far easier for a criminal to set up a spoofed hotspot than to physically tamper with a charging kiosk.

That sentiment is echoed elsewhere in the security community. One researcher noted flatly that unsecured airport and hotel Wi-Fi networks pose a far greater threat than USB ports, since man-in-the-middle attacks using rogue wireless hotspots are much more common.[6] Attacks of that kind, according to the same source, can capture passwords, intercept communications, and install malware without any physical connection[6] at all, which arguably makes them a more practical concern for the average traveler than a compromised charging cable.

Simple, Low-Cost Ways to Protect Yourself

Simple, Low-Cost Ways to Protect Yourself (Image Credits: Unsplash)
Simple, Low-Cost Ways to Protect Yourself (Image Credits: Unsplash)

None of this means travelers should shrug off the warnings entirely. The fixes are cheap, easy to carry, and require almost no extra effort. Government advisories consistently recommend the same basic steps: bring your own wall adapter and plug into a standard electrical outlet rather than a USB port, carry a portable battery pack, and if you must use a public USB port, invest in a “charge only” cable or a small adapter known as a USB data blocker that physically prevents any data pins from connecting.

Related Stories From Travelbinger

  • 23 Dangerous Airport Habits Security Experts Wish Every Traveler Would Drop
  • 17 Things Port Agents Handle That Passengers Never Hear About
  • 15 Quiet Favors Airport Lounge Staff Do for Travelers Over 60 That Members Never Notice

Software habits matter just as much as hardware choices. If you plug your device into a USB port and a prompt appears asking you to select “share data” or “charge only,” always select “charge only.”[11] Keeping your phone’s operating system current is another surprisingly effective defense, since software updates often patch security vulnerabilities that could be exploited through USB connections.[6] These habits cost nothing beyond a few seconds of attention, yet they close off the overwhelming majority of scenarios researchers have demonstrated in labs.

How to Think About the Risk Realistically

How to Think About the Risk Realistically (Image Credits: Unsplash)
How to Think About the Risk Realistically (Image Credits: Unsplash)

The honest answer sits somewhere between panic and dismissal. Juice jacking is not an urban legend invented by paranoid IT departments, since researchers have repeatedly proven it is technically possible and device manufacturers clearly took the threat seriously enough to build defenses against it. At the same time, the complete absence of confirmed victim cases after more than a decade suggests that criminals, so far, have found easier and more scalable ways to steal data than rigging airport furniture.

What tips the balance toward caution is uncertainty rather than certainty of harm. The absence of evidence is not evidence of absence, and caution is still advisable[12] when the cost of prevention is as low as tossing a spare cable or battery pack into your carry-on. Given how quickly attack techniques like ChoiceJacking have evolved, relying entirely on outdated protections built for the original threat would be a mistake, even if today’s phones are considerably better defended than they were even two years ago.

🔥 Would you like to save this?

We’ll email this post to you, so you can come back to it later.

Marco Kopinke

Marco Kopinke

Is a seniored binger who loves to travel to Thailand, Russia and Colombia for the culture and food. Always chasing local street food and hidden gems.

View Profile & Articles

More from Marco Kopinke

Why Tech Experts Warn Against Using Airport Lounge USB Ports

Why Tech Experts Warn Against Using Airport Lounge USB Ports

1 min read

5 Budget Airlines That Rival Major Carriers on Comfort and Service

5 Budget Airlines That Rival Major Carriers on Comfort and Service

1 min read

Swim With Marine Iguanas on a Galápagos Wildlife Cruise

Swim With Marine Iguanas on a Galápagos Wildlife Cruise

1 min read

8 Beach Destinations Some Travelers Consider Overrated

8 Beach Destinations Some Travelers Consider Overrated

1 min read

Latest News

Fresh travel updates

Why Tech Experts Warn Against Using Airport Lounge USB Ports

Why Tech Experts Warn Against Using Airport Lounge USB Ports

Marco Kopinke·Sep 25
5 Budget Airlines That Rival Major Carriers on Comfort and Service

5 Budget Airlines That Rival Major Carriers on Comfort and Service

Samanta Brown·Sep 25
Swim With Marine Iguanas on a Galápagos Wildlife Cruise

Swim With Marine Iguanas on a Galápagos Wildlife Cruise

Matthias Binder·Sep 25
8 Beach Destinations Some Travelers Consider Overrated

8 Beach Destinations Some Travelers Consider Overrated

Marcel Kuhn·Sep 25
View All News

Stay Updated

Get the latest travel news delivered to your inbox

Stay Inspired

Get travel inspiration, guides, and exclusive deals delivered to your inbox.

Travelbinger
TravelbingerTRAVEL DEALS, GUIDES AND HACKS

Discover the world through the eyes of seasoned travel experts. From breaking news to hand-picked destination guides, we bring you the stories that matter. Join our community for exclusive member deals and authentic inspiration for your next journey.

Deals

  • All Deals
  • Beach Holidays
  • City Breaks
  • Luxury Hotels
  • Last Minute

Popular Destinations

  • Europe
  • Asia
  • North America
  • South America
  • Africa

Company

  • About Us
  • Travel News
  • Editorial Policy
  • Contact

Legal

  • Privacy Policy
  • Terms & Conditions

This website contains affiliate links to trusted partners.

© 2026 Travelbinger. All rights reserved.

Secure payment with:
Visa
MC
PayPal
Klarna