In-Person Scam Watch — August 20, 2026
Two TSA-confirmed airport scams targeting travelers at US airports — juice jacking at USB charging stations and fake "evil twin" WiFi networks. Both are standing threats active right now at airports nationwide. Free to read, no subscription required.
Public USB Charging Ports at Airports Can Silently Install Malware on Your Phone — TSA Warns: Use a Wall Outlet or Your Own Power Bank Instead
Modern USB ports serve two functions simultaneously: power delivery and data transfer. Airports, airlines, and terminal operators install USB charging stations as a passenger convenience — but a criminal who gains physical access to one of these stations can insert a small modified component or pre-loaded malware that exploits the data-transfer function. When you plug in your phone to charge, the compromised port establishes a data connection alongside the power connection. Depending on the malware loaded, attackers can silently copy your contact list, access saved passwords, intercept authentication tokens, capture keystrokes, or install persistent malware that remains after you unplug. The entire process is invisible and takes only as long as your device is connected. Your phone appears to charge normally throughout.
The FBI has noted that juice jacking is difficult to detect and that victims typically have no idea their device has been compromised until they notice unauthorized activity later — often days or weeks after travel. High-traffic airports during peak summer and holiday seasons are the environments where tampered ports are most likely to be encountered, simply because the potential victim pool is largest.
- Any USB port in an airport, hotel lobby, shopping mall, or other public transit area — treat all of them as potentially compromised, not just obviously damaged ones
- USB ports that seem to "wake up" your phone screen when you plug in, even with the phone locked — this can indicate an active data handshake rather than just charging
- Ports with unusual add-ons, loose-fitting connectors, or any modifications to the standard port housing
- Any prompt on your phone screen asking you to "Trust This Computer" or requesting data access after connecting — decline immediately and unplug
- Use a standard wall outlet with your own AC adapter — wall electrical outlets cannot be juice-jacked; only USB data ports can be compromised this way
- Bring a portable power bank from home — charge it overnight before travel so you have a full private charge available at the airport without needing any public port
- If you must use a USB port, use a USB data blocker — a "USB condom" device (available for $5–$15 online) passes power through but physically breaks the data pins, making data transfer impossible while still allowing charging
- Keep your phone locked while charging — do not enter passwords or open banking apps while connected to any public port
- If your phone prompts "Trust This Computer?" after plugging in, tap "Don't Trust" and immediately unplug — that prompt means a data connection was established, not just a power connection
Bring your own wall adapter and use a standard power outlet. Wall outlets cannot be juice-jacked — only USB ports carry the data-transfer risk. A $15 portable power bank charged at home eliminates the risk entirely for most trips.
Fake "Evil Twin" Airport WiFi Networks Intercept Everything You Type — Including Passwords, Credit Card Numbers, and Login Credentials
An attacker sits in the terminal with a laptop and a portable WiFi router, broadcasting a network with a name like "Airport_WiFi_Free" or "DEN-Free-WiFi" — close enough to the real network that travelers connect without questioning it. Once connected, all of your unencrypted traffic passes through the attacker's equipment. Even on encrypted HTTPS sites, attackers running a "man in the middle" setup can intercept authentication tokens, session cookies, and login credentials. A traveler who opens their banking app, checks work email, or makes any purchase on a fake network can have their credentials captured in real time — while appearing to browse normally.
The risk is highest at large, busy airports during peak travel periods, when passengers are hurried, tired, or distracted, and when legitimate networks are congested enough that connecting to any network that "works" is tempting. Flight delays are a particularly high-risk moment — passengers stranded for hours are more likely to connect to anything available and less likely to notice subtle network name differences.
- Any free WiFi network that does not ask for your email address to connect — most legitimate airport networks require basic registration
- Networks with names that are close to but not exactly the official airport network — check the airport's website or ask staff for the exact official network name before connecting
- Networks that load pages unusually quickly or that seem to bypass the normal airport login/splash page
- Any network that generates immediate pop-ups or prompts for personal information beyond a basic email address registration
- Use your phone's cellular data for anything involving personal or financial information — turn off WiFi and use LTE/5G when checking banking, email, or making purchases at the airport
- Enable a VPN before connecting to any public WiFi — a VPN encrypts your traffic between your device and the VPN server, preventing an attacker on the same network from reading what you send and receive
- Before connecting, verify the exact network name with airport staff or the airport's official website — do not guess based on what sounds right; ask someone in a uniform or check a posted sign
- Do not open banking, email, or work apps on public airport WiFi — save those for when you're on cellular or a trusted home/office network
- Turn off "auto-connect" to open WiFi networks on your phone — this prevents your device from silently joining a rogue network without you actively choosing it
Use your phone's cellular data, not airport WiFi, for anything involving passwords, banking, or personal information. If you need WiFi, enable a VPN first — it encrypts your traffic even on a compromised network. Free airport WiFi is safe for reading news; it is not safe for logging in to anything.