Charging stations have become ubiquitous in public spaces, including malls, hotels, restaurants and parks. AFP
Charging stations have become ubiquitous in public spaces, including malls, hotels, restaurants and parks. AFP
Charging stations have become ubiquitous in public spaces, including malls, hotels, restaurants and parks. AFP
Charging stations have become ubiquitous in public spaces, including malls, hotels, restaurants and parks. AFP

FBI warns against using public charging stations due to malware and 'juice jacking' risk


Alvin R Cabral
  • English
  • Arabic

The FBI has warned against the use of public charging points for electronic devices, saying they can be a gateway for cyber criminals.

Public charging stations heightens the risk of bad actors installing malware and gaining access to devices, the top US law enforcement agency's Denver department said on Twitter.

“Avoid using free charging stations in airports, hotels or shopping centres. Bad actors have figured out ways to use public USB ports to introduce malware and monitoring software on to devices,” the FBI said.

“Carry your own charger and USB cord and use an electrical outlet instead.”

Charging stations have become ubiquitous in public spaces, including malls, hotels, restaurants and parks, providing users a convenient way to power up their devices.

However, the practice has paved the way for what is called “juice jacking”, which simply means using a USB connection to compromise a device.

Aside from bringing personal charging equipment, it is also advised to plan ahead and charge devices before stepping out to prevent any cyber risk that may result from using public charging points.

WHAT%20IS%20'JUICE%20JACKING'%3F
%3Cp%3E%E2%80%A2%20Juice%20jacking%2C%20in%20the%20simplest%20terms%2C%20is%20using%20a%20rogue%20USB%20cable%20to%20access%20a%20device%20and%20compromise%20its%20contents%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20The%20exploit%20is%20taken%20advantage%20of%20by%20the%20fact%20that%20the%20data%20stream%20and%20power%20supply%20pass%20through%20the%20same%20cable.%20The%20most%20common%20example%20is%20connecting%20a%20smartphone%20to%20a%20PC%20to%20both%20transfer%20data%20and%20charge%20the%20former%20at%20the%20same%20time%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20The%20term%20was%20first%20coined%20in%202011%20after%20researchers%20created%20a%20compromised%20charging%20kiosk%20to%20bring%20awareness%20to%20the%20exploit%3B%20when%20users%20plugged%20in%20their%20devices%2C%20they%20received%20a%20security%20warning%20and%20discovered%20that%20their%20phones%20had%20paired%20to%20the%20kiosk%2C%20according%20to%20US%20cybersecurity%20company%20Norton%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20While%20juice%20jacking%20is%20a%20real%20threat%2C%20there%20have%20been%20no%20known%20widespread%20instances.%20Apple%20and%20Google%20have%20also%20added%20security%20layers%20to%20prevent%20this%20on%20the%20iOS%20and%20Android%20devices%2C%20respectively%3C%2Fp%3E%0A

Malware — a programme typically designed to disrupt or gain unauthorised access into a system — constitutes one of the biggest threats in the IT industry.

It is part of the wider cyber crime sector projected to cause global financial damage of about $10.5 trillion by 2025, according to data from Cybersecurity Ventures.

Globally, about 5.5 billion malware attacks took place in 2022, an increase of 2 per cent from 2021 and nearly half the 10.5 billion peak recorded in 2018, data from Statista shows.

Cyber attacks can cause reputational and financial damage to users. The global average cost for a data breach in 2022 was $4.35 million, up from $4.24 million the previous year, according to the latest edition of IBM's Cost of a Data Breach report.

The FBI has similar guidance on its website, covering a variety of topics on internet safety, including warning against conducting sensitive transactions on a public Wi-Fi network.

“Every day tasks — opening an email attachment, following a link in a text message, making an online purchase — can open you up to online criminals who want to harm your systems or steal from you,” the FBI said.

“Preventing internet-enabled crimes and cyber intrusions requires each of us to be aware and on guard.”

It is not clear if the FBI warning is prompted by any specific case, but US authorities have warned about “juice jacking” in the past.

Most recently, the Federal Communications Commission also warned that cyber criminals can gain access to online accounts and even sell them in the dark web through “juice jacking”.

“Cyber security experts have warned that criminals can load malware on to public USB charging stations to maliciously access electronic devices while they are being charged,” the FCC said.

“Malware installed through a dirty USB port can lock a device or export personal data and passwords directly to the perpetrator.”

The Los Angeles County District Attorney’s Office in November 2019 had also cautioned travellers about USB charger scams.

If you go...

Etihad Airways flies from Abu Dhabi to Kuala Lumpur, from about Dh3,600. Air Asia currently flies from Kuala Lumpur to Terengganu, with Berjaya Hotels & Resorts planning to launch direct chartered flights to Redang Island in the near future. Rooms at The Taaras Beach and Spa Resort start from 680RM (Dh597).

CRICKET%20WORLD%20CUP%20QUALIFIER%2C%20ZIMBABWE%20
%3Cp%3E%3Cstrong%3EUAE%20fixtures%20%20%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EMonday%2C%20June%2019%20%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3ESri%20Lanka%20v%20UAE%2C%20Queen%E2%80%99s%20Sports%20Club%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EWednesday%2C%20June%2021%20%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3EOman%20v%20UAE%2C%20Bulawayo%20Athletic%20Club%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EFriday%2C%20June%2023%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3EScotland%20v%20UAE%2C%20Bulawayo%20Athletic%20Club%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ETuesday%2C%20June%2027%20%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3EIreland%20v%20UAE%2C%20Bulawayo%20Athletic%20Club%3C%2Fp%3E%0A
UAE currency: the story behind the money in your pockets
COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3EName%3A%20%3C%2Fstrong%3EQureos%0D%3Cbr%3E%3Cstrong%3EBased%3A%20%3C%2Fstrong%3EUAE%0D%3Cbr%3E%3Cstrong%3ELaunch%20year%3A%20%3C%2Fstrong%3E2021%0D%3Cbr%3E%3Cstrong%3ENumber%20of%20employees%3A%20%3C%2Fstrong%3E33%0D%3Cbr%3E%3Cstrong%3ESector%3A%20%3C%2Fstrong%3ESoftware%20and%20technology%0D%3Cbr%3E%3Cstrong%3EFunding%3A%20%3C%2Fstrong%3E%243%20million%0D%3Cbr%3E%3C%2Fp%3E%0A
Stamp duty timeline

December 2014: Former UK finance minister George Osbourne reforms stamp duty, replacing the slab system with a blended rate scheme, with the top rate increasing to 12 per cent from 10 per cent:
Up to £125,000 - 0%; £125,000 to £250,000 – 2%; £250,000 to £925,000 – 5%; £925,000 to £1.5m: 10%; Over £1.5m – 12%

April 2016: New 3% surcharge applied to any buy-to-let properties or additional homes purchased.

July 2020: Rishi Sunak unveils SDLT holiday, with no tax to pay on the first £500,000, with buyers saving up to £15,000.

March 2021: Mr Sunak decides the fate of SDLT holiday at his March 3 budget, with expectations he will extend the perk unti June.

April 2021: 2% SDLT surcharge added to property transactions made by overseas buyers.

The specs

Engine: 4.0-litre V8 twin-turbocharged and three electric motors

Power: Combined output 920hp

Torque: 730Nm at 4,000-7,000rpm

Transmission: 8-speed dual-clutch automatic

Fuel consumption: 11.2L/100km

On sale: Now, deliveries expected later in 2025

Price: expected to start at Dh1,432,000

UAE currency: the story behind the money in your pockets
Australia tour of Pakistan

March 4-8: First Test, Rawalpindi  

March 12-16: Second Test, Karachi 

March 21-25: Third Test, Lahore

March 29: First ODI, Rawalpindi

March 31: Second ODI, Rawalpindi

April 2: Third ODI, Rawalpindi

April 5: T20I, Rawalpindi

Gulf rugby

Who’s won what so far in 2018/19

Western Clubs Champions League: Bahrain
Dubai Rugby Sevens: Dubai Hurricanes
West Asia Premiership: Bahrain

What’s left

UAE Conference

March 22, play-offs:
Dubai Hurricanes II v Al Ain Amblers, Jebel Ali Dragons II v Dubai Tigers

March 29, final

UAE Premiership

March 22, play-offs: 
Dubai Exiles v Jebel Ali Dragons, Abu Dhabi Harlequins v Dubai Hurricanes

March 29, final

COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3ECompany%20name%3A%3C%2Fstrong%3E%20OneOrder%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%20March%202022%3Cbr%3E%3Cstrong%3EFounders%3A%3C%2Fstrong%3E%20Tamer%20Amer%20and%20Karim%20Maurice%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Cairo%3Cbr%3E%3Cstrong%3ENumber%20of%20staff%3A%20%3C%2Fstrong%3E82%3Cbr%3E%3Cstrong%3EInvestment%20stage%3A%3C%2Fstrong%3E%20Series%20A%3C%2Fp%3E%0A
The Specs

Price, base Dh379,000
Engine 2.9-litre, twin-turbo V6
Gearbox eight-speed automatic
Power 503bhp
Torque 443Nm
On sale now

WHAT%20IS%20'JUICE%20JACKING'%3F
%3Cp%3E%E2%80%A2%20Juice%20jacking%2C%20in%20the%20simplest%20terms%2C%20is%20using%20a%20rogue%20USB%20cable%20to%20access%20a%20device%20and%20compromise%20its%20contents%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20The%20exploit%20is%20taken%20advantage%20of%20by%20the%20fact%20that%20the%20data%20stream%20and%20power%20supply%20pass%20through%20the%20same%20cable.%20The%20most%20common%20example%20is%20connecting%20a%20smartphone%20to%20a%20PC%20to%20both%20transfer%20data%20and%20charge%20the%20former%20at%20the%20same%20time%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20The%20term%20was%20first%20coined%20in%202011%20after%20researchers%20created%20a%20compromised%20charging%20kiosk%20to%20bring%20awareness%20to%20the%20exploit%3B%20when%20users%20plugged%20in%20their%20devices%2C%20they%20received%20a%20security%20warning%20and%20discovered%20that%20their%20phones%20had%20paired%20to%20the%20kiosk%2C%20according%20to%20US%20cybersecurity%20company%20Norton%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20While%20juice%20jacking%20is%20a%20real%20threat%2C%20there%20have%20been%20no%20known%20widespread%20instances.%20Apple%20and%20Google%20have%20also%20added%20security%20layers%20to%20prevent%20this%20on%20the%20iOS%20and%20Android%20devices%2C%20respectively%3C%2Fp%3E%0A
Updated: April 11, 2023, 8:01 AM