What is juice jacking - and how worried should you be?
Last reviewed July 16, 2026
Juice jacking is the use of a public USB charging port, station, or cable to reach a device's data lines - not just its power lines - in order to copy information off the device or push malware onto it while it charges. The term exists because USB was designed to carry power and data over the same connector: every time you plug in to charge, you are also plugging into a potential data connection.
What U.S. agencies actually said
In April 2023 the FBI's Denver field office advised the public to “avoid using free charging stations in airports, hotels or shopping centers” because bad actors can use public USB ports to introduce malware (CNBC coverage, CBS News). The FCC published a consumer guide on juice jacking that recommended carrying your own charger and - notably - “a charging-only cable, which prevents data from sending or receiving while charging, from a trusted supplier.” The FCC has since taken that page offline; an archived copy is preserved by the Internet Archive (archived FCC consumer guide). The NSA's Mobile Device Best Practices guide (2020) instructed users to use only trusted charging accessories and "DO NOT use public USB charging stations" (archived NSA guide).
The honest part: how common is it?
Documented, confirmed cases of criminals juice-jacking travelers in the wild are rare - the FCC's own guide said it was “not aware of any confirmed instances of it occurring” (archived FCC consumer guide). When pressed after the 2023 advisory, the FBI said the warning was precautionary and not prompted by a specific incident (Slate's analysis). We make a product in this category and we'd rather tell you that plainly than sell you fear. Even the security industry says so on the record - Kaspersky's 2025 analysis states plainly that "no real-world attacks have ever been publicly documented" (Kaspersky, 2025).
So why does anyone bother protecting against it?
- The attack is demonstrated, not theoretical. Security researchers have shown working juice-jacking rigs since 2011 - the mechanism is simply how USB works.
- The exposure is asymmetric. One compromised device can mean drained accounts for an individual - or, for an organization, an incident measured in millions. IBM put the global average cost of a data breach at $4.44 million in its 2025 report (IBM Cost of a Data Breach 2025).
- Detection is nearly impossible for a user. A tampered port or cable looks identical to a clean one. You can't inspect your way to safety.
How the attack works, in one paragraph
A standard USB connection carries power on some wires and data on others. When you plug into a port you don't control, the equipment behind that port decides what to attempt over the data wires: it can present itself as a computer and request access, exploit a device vulnerability, or in the crudest version simply prompt you to “trust this computer” and hope you tap yes. Modern phones have gotten better at asking permission - but the defense still depends on software behaving correctly and users answering prompts correctly, every single time. And in 2025, peer-reviewed research from Graz University of Technology showed a malicious charger can bypass those trust prompts entirely: the “ChoiceJacking” attacks gained data access on devices from eight vendors, including the top six by market share (USENIX Security 2025 paper). Vendors are patching - but a physically disconnected data line never needed the prompt in the first place.
Protection, ranked by strength
- Use your own charger in a wall outlet. No USB data path exists at all. This was the FBI's first recommendation - when an outlet is available and you remembered the charger.
- Cut the data lines in the cable. A data blocker, charge-only cable, or switchable cable makes the data path physically absent, so it doesn't matter what the port tries. A switchable cable (this is what Lion Cables are) does this without giving up data function when you actually want it - flip the switch, and an illuminated indicator shows which mode you're in.
- Answer the prompt correctly. If your phone asks, always choose “charge only” / don't trust. Worth doing, but the weakest layer: it depends on the prompt appearing, on you never tapping wrong while distracted at a gate - and 2025 research showed a malicious charger can answer the prompt itself.
Frequently asked questions
What is juice jacking?
Juice jacking is a cyberattack technique in which a public USB charging port, station, or cable is modified to use the data wires of a USB connection - not just the power wires - to copy data from a device or install malware on it while the device charges.
Is juice jacking real or a myth?
The attack is technically real and has been demonstrated repeatedly by security researchers since 2011. However, publicly documented cases of criminals actually compromising travelers this way are rare; the FBI's 2023 advisory was precautionary rather than a response to a specific incident. Agencies have warned about it because a standard USB connection has no built-in defense.
Did the FBI really warn about public charging stations?
Yes. In April 2023, the FBI's Denver field office advised the public to avoid free charging stations in airports, hotels, and shopping centers, recommending travelers carry their own charger and use an electrical outlet instead. The FCC also published a consumer guide about the same risk; that page has since been taken offline, but an archived copy remains available.
How do I protect my phone at a public charging station?
Use a wall outlet with your own charger, carry a power bank, or make the cable itself safe: a data-blocker adapter, a charge-only cable, or a switchable cable that physically disconnects its data lines while charging. If your phone asks whether to trust the connected device, choose "charge only."
Does a switchable cable stop juice jacking?
A cable whose data lines are physically disconnected leaves no data path between the port and the device, so data cannot be read from or written to the device over that connection - regardless of what the port on the other end is doing. Lion Cables add an illuminated indicator so the protected mode is visible at a glance.
Has anyone actually been juice-jacked, or is it all hype?
No confirmed real-world case has ever been publicly documented. The FCC's consumer guide - now archived - said the agency was "not aware of any confirmed instances," and journalists who went looking for victims came up empty. The technique itself is real and repeatedly demonstrated as a proof of concept. We would rather tell you that plainly than sell you fear.
If attacks are that rare, why would I need this at all?
Maybe you don't - if a wall outlet is always within reach, use it. The case for hardware protection is asymmetry: a tampered port looks identical to a clean one, peer-reviewed 2025 research showed your device's own permission prompts can be defeated, and flipping a switch takes a second. Rare risk, low-cost, physical protection - that's the honest pitch.
My phone asks before sharing data - isn't that enough?
It helps, but it's the weakest layer. In 2025, peer-reviewed "ChoiceJacking" research showed a malicious charger can approve its own connection - spoofing the taps and gaining data access on devices from eight vendors, including the top six by market share. The fastest variant took 133 milliseconds, less than a blink. Vendors are patching. A physically disconnected data line shows no prompt to spoof.
Are iPhones already protected from juice jacking?
Partly. iOS asks before allowing a data connection - a real safeguard. But the 2025 ChoiceJacking paper confirmed its attack principle on iOS as well as Android, and Apple is among the vendors that acknowledged the findings and are integrating mitigations. Software defenses keep improving - and keep needing to. A cut data line doesn't depend on your update status.
How would I even know if I'd been juice-jacked?
You very likely wouldn't know. A tampered port or cable looks identical to a clean one, and the 2025 ChoiceJacking attacks leave at most a brief flicker on the screen - the fastest completed in 133 milliseconds. There's no simple sign an ordinary user can check afterward, which is why the practical defenses are preventive: an outlet, a power bank, or a physically severed data line.
What is ChoiceJacking?
ChoiceJacking is a 2025 attack class, demonstrated by Graz University of Technology researchers, in which a malicious charger spoofs your own taps to approve a data connection - defeating the USB trust prompt on devices from eight vendors, including the top six by market share. Full explainer: /learn/choicejacking.