USB Baiting
What is USB Baiting?
USB Baiting relies on curiosity and trust rather than sophisticated technical tricks. Attackers may leave USB drives in offices, schools, parking lots or other public places, sometimes labeling them with names such as “Confidential,” “Salary Data” or “Photos.” A person who finds one may be tempted to plug it into their computer to discover what is inside.
Once connected, a malicious USB drive may attempt to install malware, steal information or exploit vulnerabilities on the device. In some cases, the drive may contain files designed to trick the user into opening them or running malicious software. The attack can be particularly dangerous because the victim may believe they have simply found a lost storage device.
The safest approach is simple: never connect an unknown USB drive to your computer or phone. If you find a suspicious device at work or in a public place, hand it over to the appropriate staff or security team instead of testing it yourself. Using trusted storage devices, keeping your operating system updated and maintaining reliable security software can also help reduce the risk.
Sample Story


