USB malware: why you should never plug in a drive you did not buy
Malware / security. Updated 2026-09-13. About 5 minutes to read.
Do not plug in a USB drive or cable you did not buy yourself, and if you already have, disconnect from the internet and scan or reset the computer before logging in to anything important.
A USB drive left in a car park or posted in a nice gift box is one of the oldest tricks in security, and it still works. In a study published in 2016, researchers dropped 297 USB drives around a large university campus. They estimated that 45 to 98 percent were picked up and plugged in, and the first one was connected in under six minutes. Most people said they were trying to find the owner.
Criminals use the same kindness. In January 2022 the FBI warned that the FIN7 group was mailing malicious USB devices to US companies, disguised as parcels from the US health department and Amazon. This guide explains how these attacks work and what to do if you have already plugged one in.
How USB attacks work
Malicious files: the drive holds a file that looks like a document or folder but runs a program when opened, often a shortcut file with a misleading icon.
Keyboard impersonation, often called BadUSB: the device tells the computer it is a keyboard and types commands in seconds. The FIN7 devices worked this way, and the typed commands can install ransomware.
Hidden hardware: cables and adapters can contain tiny chips that do the same as a malicious keyboard while looking like an ordinary charging cable.
Destructive devices: some USB devices are built to send a power surge that damages the computer's hardware.
Antivirus may not stop a keyboard-style attack. To the computer it looks like a person typing, not a file being run.
Why the lure works, and how it is delivered
The 2016 campus study found that a drive's appearance did not make people more likely to plug it in. Curiosity and a wish to return lost property did. Drives with labels like keys or photos got the same treatment as plain ones.
The FBI said FIN7's packages imitating the US Department of Health and Human Services came with letters about COVID-19 guidelines, and the fake Amazon ones came in a decorative box with a thank-you letter and a counterfeit gift card. The goal is always to make plugging it in feel normal.
If you find a USB drive or receive one you did not order
Do not plug it into any computer, TV, car stereo or games console.
At work, hand it to your IT or security team and tell them where you found it or how it arrived.
In public places, hand it to staff or the lost property desk.
If it arrived by post from a company or government agency, contact that organisation on a number from its official website and ask whether they sent it.
If you want to throw it away, put it in electronic waste. Do not try to check it on a spare laptop, because some devices attack hardware or spread over networks.
If you already plugged it in
Unplug the device and turn off Wi-Fi or unplug the network cable.
Write down what you saw: windows opening by themselves, text typing on its own or a program you did not start.
On Windows, open Windows Security, then Virus and threat protection, Scan options, and run a Microsoft Defender Offline scan. On a Mac, run the security tool you use and make sure macOS is up to date.
If you saw typing or windows opening on their own, treat the computer as compromised. Back up your personal files, then reset or reinstall the operating system.
From a different, trusted device, change the passwords for your email, banking and password manager, and sign out other sessions.
At work, report it to IT immediately, even if nothing seemed to happen. Early reports stop attacks spreading.
If money or accounts are affected, report it: ReportCyber at cyber.gov.au in Australia, Report Fraud in the UK at reportfraud.police.uk, and ic3.gov in the US.
Use your own USB drives safely
Keep automatic updates and built-in antivirus turned on.
In Windows File Explorer, turn on file name extensions so a program cannot pretend to be a document. In Windows 11 this is under View, then Show.
Turn off AutoPlay for removable drives in Windows settings.
Encrypt drives that carry personal files, using BitLocker To Go on supported Windows editions or an encrypted format on a Mac.
Do not lend drives to others or plug your drive into shared computers at print shops or hotels.
Use your own charger and plug at public charging points. A charge-only cable or adapter blocks data if you must use a public USB port.
For small businesses: stop USB attacks before they start
Tell staff the rule in one sentence: unknown USB drives, cables and gadgets go to IT, never into a computer.
Tell whoever handles the mail that unexpected USB devices, gift boxes with drives and letters asking you to plug something in go straight to IT unopened.
Use device control in your security or device management software to block unapproved USB storage on work computers.
Issue approved encrypted drives to staff who genuinely need removable storage, and keep a list of who has them.
Run a short reminder after any news of USB attacks, and thank people who hand drives in.
Frequently asked questions
Can a USB drive infect my computer without me opening anything?
Keyboard-style devices can act the moment they are plugged in, without you opening a file. Older autorun tricks are mostly blocked on modern systems, but a malicious keyboard device does not need them.
Is it safe to plug a found USB drive into a Mac or Chromebook?
No. Keyboard-style attacks can target any operating system, and some devices damage hardware. Hand it in instead.
Are public USB charging stations dangerous?
Government agencies have warned about them, although confirmed real-world cases are rare. Using your own charger in a power socket or a charge-only cable removes the risk completely.
What if the USB came from my own workplace?
Check with IT before using any drive you did not receive directly from them. Attackers imitate internal deliveries, and IT would rather check a real drive than clean up an infection.
My child found a USB stick at school. What should we do?
Praise them for asking, then hand it to the school office without plugging it in. Explain that a stick that looks lost can be bait, just like a link in a message from a stranger.