The Agence nationale de la sécurité cybernétique said that public USB charging ports can allow malicious actors to steal personal data [1].
This warning highlights a growing vulnerability in public infrastructure where convenience often overrides security. As travelers rely on integrated charging stations, the risk of data theft through modified hardware increases.
According to the agency, these security risks are prevalent in public places such as train stations and other public transport locations [1, 2]. Malicious actors can exploit these USB ports to gain unauthorized access to connected devices and extract sensitive personal information [1].
This technique, often referred to as juice jacking, involves the installation of hidden hardware or software within a charging station. Because USB cables are designed to carry both power and data, a compromised port can establish a two-way communication link with a smartphone or tablet.
Once a connection is established, attackers may be able to install malware on the device or siphon off passwords, contacts, and photos. The agency said that users should exercise caution when plugging into unknown power sources to prevent such breaches [1].
To mitigate these risks, security experts recommend using a personal power bank or a standard AC wall outlet with a trusted adapter. Using a "USB data blocker"—a small device that physically prevents data transfer while allowing power through—is another effective defense against these attacks [1, 2].
Public transport hubs remain primary targets for these installations due to the high volume of transient users who are often desperate for power. The agency said it continues to monitor these threats to protect citizens from digital theft [1].
“Public USB charging ports can allow malicious actors to steal personal data.”
The warning from the Agence nationale de la sécurité cybernétique underscores the physical layer of cybersecurity. While most users focus on software firewalls and passwords, the physical connection of a USB cable creates a direct hardware bridge that can bypass many digital security measures, making public infrastructure a significant vector for data exfiltration.


