What the warnings say, and what the record shows
The FBI, the FCC, and the TSA have all issued public warnings about juice jacking, a theoretical attack where a compromised public USB charging port or cable steals data or installs malware while your phone charges. The term dates back to 2011, when security researchers first demonstrated the concept at the DEF CON hacker conference. Since then, researchers have built working proof-of-concept attacks from time to time, including a 2013 Georgia Tech demonstration that installed malware on an iPhone within one minute.
The record doesn’t match the warnings. An Ars Technica investigation found no documented cases of juice jacking on modern iOS or Android devices, and Apple told the outlet it was unaware of any real-world attacks. A separate review of police records, court cases, and cybersecurity incident reports turned up zero confirmed juice jacking cases outside of controlled research demonstrations. The FCC itself has said it hasn’t found any real-world attacks since it started tracking the issue in 2019.
Why a real capability produced no real victims
The gap here isn’t that juice jacking is fake. Researchers have proven the technique works in a lab. The gap is between technical possibility and practical exploitation. A malicious charging station would need to sit undetected in a public location, and if it started compromising phones at scale, security researchers would likely spot it fast, given how much attention the concept already gets. Apple and Google have also added protections over the years: modern phones now require you to confirm data access when a USB connection is made, a step that blocks the simplest version of this attack outright.
That said, the arms race hasn’t stopped. A 2025 study on a technique called ChoiceJacking demonstrated a way around those confirmation prompts, restoring at least part of the original threat on unpatched devices. Researchers keep finding new angles. None of those angles have yet produced a documented victim.
The practical takeaway
You don’t need to treat every airport charging station like a trap, but the fix costs little enough that there’s not much reason to skip it. Carry your own charging cable and a wall adapter, or a small USB data blocker that only allows power through, and plug into an outlet instead of a public USB port when you can. Keeping your phone’s operating system updated matters too, since that’s where the newer protections against techniques like ChoiceJacking get patched in.
Absence of documented cases doesn’t guarantee absence of risk going forward, given researchers keep finding new bypass techniques. But it’s a real reason to worry less than a decade of headlines might suggest, and to treat this as a low-cost precaution rather than an emergency.
References
Communications of the ACM, “Juice Jacking.” https://cacm.acm.org/news/juice-jacking/
Malwarebytes, “Juice jacking warnings are back, with a new twist.” https://www.malwarebytes.com/blog/news/2025/06/juice-jacking-warnings-are-back-with-a-new-twist
Wikipedia, "Juice jacking." https://en.wikipedia.org/wiki/Juice_jacking
PwnDefend, "A threat to sanity, Cyber Myth: Juice Jacking." https://www.pwndefend.com/2025/10/16/a-threat-to-sanity-cyber-myth-juice-jacking/
ESET, "Juice Jacking: Real Threat or Cybersecurity Myth?" https://www.eset.com/blog/en/home-topics/privacy-and-identity-protection/juice-jacking-real-or-myth/

Top comments (0)