What it is
A USB drop is an attack where USB drives or other devices are deliberately left where someone will find and plug them in: car parks, offices, events. They may contain malware or pose as a keyboard that types commands by itself.
How it works
- 1The attacker prepares devices with enticing labels such as “Salaries” or “Photos”.
- 2They leave them in places the victim frequents or hand them out as giveaways.
- 3Someone plugs them in out of curiosity or to find the owner.
- 4The malware runs or the device types commands within seconds, and the attacker gains access to the computer and the network.
How to spot it
- A drive or cable you did not buy or ask for
- Curious or tempting labels
- The computer reacts at once to the insertion with windows or commands
- Unexpected tech giveaways at fairs or meetings
How to defend
- Never plug in USB devices of unknown origin
- Hand what you find to IT or security
- Where possible, block unauthorised USB ports and disable autorun
- To charge in public places use a USB data blocker or a power outlet
- Train teams: curiosity is the real way in
If you think you have been hit
- Disconnect the computer from the network at once
- Alert IT and stop using that computer until it is checked
- Change passwords from another device
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026