// In-Person Report August 20, 2026 2 Findings · Airport Scams

In-Person Scam Watch — August 20, 2026

Two TSA-confirmed airport scams targeting travelers at US airports — juice jacking at USB charging stations and fake "evil twin" WiFi networks. Both are standing threats active right now at airports nationwide. Free to read, no subscription required.

High Alert Juice Jacking

Public USB Charging Ports at Airports Can Silently Install Malware on Your Phone — TSA Warns: Use a Wall Outlet or Your Own Power Bank Instead

One High-Alert Airport Scam confirmed active and flagged by TSA at airports nationwide: Those convenient USB charging stations at your departure gate may not be what they appear. A technique called "juice jacking" allows criminals to tamper with public USB ports so that when you plug in your phone or tablet to charge, the port silently installs malware or extracts your data — including contact lists, text messages, passwords, and financial credentials — without you seeing or feeling anything unusual. The TSA warns travelers specifically against plugging directly into public USB ports at airports. The solution is simple and costs nothing: bring a wall adapter and use a standard power outlet, which cannot be tampered with the same way, or carry your own portable power bank. If a USB port is the only option available, use a USB data blocker — a small device that allows power through but physically blocks data transfer — to charge safely.
How This Scam Works

Modern USB ports serve two functions simultaneously: power delivery and data transfer. Airports, airlines, and terminal operators install USB charging stations as a passenger convenience — but a criminal who gains physical access to one of these stations can insert a small modified component or pre-loaded malware that exploits the data-transfer function. When you plug in your phone to charge, the compromised port establishes a data connection alongside the power connection. Depending on the malware loaded, attackers can silently copy your contact list, access saved passwords, intercept authentication tokens, capture keystrokes, or install persistent malware that remains after you unplug. The entire process is invisible and takes only as long as your device is connected. Your phone appears to charge normally throughout.

The FBI has noted that juice jacking is difficult to detect and that victims typically have no idea their device has been compromised until they notice unauthorized activity later — often days or weeks after travel. High-traffic airports during peak summer and holiday seasons are the environments where tampered ports are most likely to be encountered, simply because the potential victim pool is largest.

How to Spot a Risky Port
What To Do
// The Defense That Matters Most

Bring your own wall adapter and use a standard power outlet. Wall outlets cannot be juice-jacked — only USB ports carry the data-transfer risk. A $15 portable power bank charged at home eliminates the risk entirely for most trips.

Sources: TSA (tsa.gov) — standing advisory warning travelers against airport USB charging stations; FBI consumer guidance on juice jacking; AAA Travel safety guidance — Mandatory Sources #1 and #2
High Alert Fake WiFi

Fake "Evil Twin" Airport WiFi Networks Intercept Everything You Type — Including Passwords, Credit Card Numbers, and Login Credentials

One High-Alert Airport Scam confirmed active and flagged by TSA at airports nationwide: Criminals set up rogue WiFi hotspots in airport terminals with names nearly identical to the airport's legitimate free network — sometimes just one letter different, sometimes an exact copy of the official name. When you connect to the fake network, the attacker can see everything you transmit: usernames, passwords, credit card numbers, banking app data, and any personal information you enter on any site or app. You have no way to tell from inside a browser or app that your connection is compromised. The TSA warns travelers not to trust free airport WiFi for any activity involving personal or financial information. Use your phone's cellular data connection instead, or enable a VPN before connecting to any public WiFi.
How This Scam Works

An attacker sits in the terminal with a laptop and a portable WiFi router, broadcasting a network with a name like "Airport_WiFi_Free" or "DEN-Free-WiFi" — close enough to the real network that travelers connect without questioning it. Once connected, all of your unencrypted traffic passes through the attacker's equipment. Even on encrypted HTTPS sites, attackers running a "man in the middle" setup can intercept authentication tokens, session cookies, and login credentials. A traveler who opens their banking app, checks work email, or makes any purchase on a fake network can have their credentials captured in real time — while appearing to browse normally.

The risk is highest at large, busy airports during peak travel periods, when passengers are hurried, tired, or distracted, and when legitimate networks are congested enough that connecting to any network that "works" is tempting. Flight delays are a particularly high-risk moment — passengers stranded for hours are more likely to connect to anything available and less likely to notice subtle network name differences.

How to Spot a Fake Network
What To Do
// The Defense That Matters Most

Use your phone's cellular data, not airport WiFi, for anything involving passwords, banking, or personal information. If you need WiFi, enable a VPN first — it encrypts your traffic even on a compromised network. Free airport WiFi is safe for reading news; it is not safe for logging in to anything.

Sources: TSA (tsa.gov) — standing advisory warning travelers against unsecured public WiFi; AAA Travel safety guidance — Mandatory Sources #1 and #2