Finding a USB flash drive in a parking lot, office lobby, coffee shop, library, airport, or conference room may spark curiosity. You might want to identify the owner or see what files it contains. However, plugging an unknown USB device into your computer can expose your device—and potentially your entire home or workplace network—to malware, ransomware, or data theft.
The safest response is simple: Never connect a found USB device to your computer.
Why can a found USB drive be dangerous?
A USB drive may contain malicious files programmed to infect a computer when someone opens them. More advanced USB devices can impersonate a trusted accessory, such as a keyboard, and automatically execute commands after connection.
CISA’s guidance on USB-drive safety explains that attackers can use USB drives to install malware, download malicious code, or steal sensitive information directly from a computer.
An unknown USB device could:
- Install spyware or ransomware
- Steal passwords and browser cookies
- Copy personal or work files
- Record keystrokes
- Create a hidden backdoor
- Download additional malware
- Spread malicious software across a network
- Give an attacker remote access
- Damage the computer’s hardware
The USB drive does not need to look suspicious. A malicious device can look exactly like an ordinary flash drive.
What is a BadUSB attack?
A BadUSB-style device manipulates the trust computers place in USB accessories. Instead of acting only as file storage, the device may identify itself as a keyboard and rapidly type malicious commands.
Some campaigns have used USB devices to open PowerShell, download malware, create remote access, or help deploy ransomware. Reports describing an FBI warning about malicious USB campaigns explain that the FIN7 cybercrime group sent USB devices disguised as gifts or official communications to businesses, hoping recipients would connect them to workplace computers.
Because the computer may recognize the device as a keyboard rather than removable storage, blocking ordinary flash drives or scanning stored files may not stop every attack.
How big is the malware risk?
Malware circulates at an enormous scale. The Microsoft Digital Defense Report 2025 states that Microsoft blocks 4.5 million net-new malware files every day and processes 100 trillion security signals daily.
Not all of that malware spreads through USB devices, but the statistic shows how aggressively criminals develop and distribute malicious software. A found USB drive gives malware a direct physical path to your computer that may bypass email filters, browser warnings, and other online protections.
How does avoiding unknown USB devices make someone safer online?
Refusing to connect an unknown USB device helps someone become safer online because it prevents untrusted hardware from interacting directly with a computer.
This protects:
- Email and social media accounts
- Passwords and passkeys
- Banking and payment information
- Tax and healthcare documents
- Personal photos and messages
- Work files and business systems
- Other devices on the same network
- Cloud accounts connected to the computer
Physical security and online security connect. An attacker does not always need to send a phishing email or hack your Wi-Fi. Sometimes the attacker only needs someone to connect the wrong device.
What should you do with a USB drive found in public?
Do not take the USB home and do not connect it to any personal, school, or work computer.
Follow these steps:
- Do not plug it into anything
Avoid computers, tablets, phones, smart TVs, gaming systems, printers, and USB hubs. - Do not try to identify the owner yourself
Opening the files is not a safe recovery method. - Notify the appropriate person
Give the device to the location’s security desk, lost-and-found office, or property manager. - Contact IT or security at work
If you find the device near your workplace, report its location without connecting it. - Avoid handling it unnecessarily
Place it somewhere secure until authorized personnel can collect it.
CISA specifically advises people who find a USB drive to give it to security personnel or an IT department rather than plugging it in to view its contents or identify the owner. [cisa.gov]
What if you already plugged in an unknown USB?
Do not continue exploring the files. Act quickly:
- Disconnect the computer from Wi-Fi and wired networks
- Remove the USB device
- Do not log in to email, banking, or work accounts
- Run a complete security scan
- Report the incident to workplace IT if applicable
- Change important passwords from a clean device
- Review account activity for unfamiliar logins
- Back up essential files only after confirming they are safe
- Consider professional support if the computer acts strangely
Warning signs may include unexpected command windows, new apps, disabled security software, unusual network activity, missing files, pop-ups, or sudden performance problems.
How should you use your own USB drives safely?
Known drives still require basic security habits.
- Buy USB drives from credible sellers
- Keep personal and work drives separate
- Encrypt drives containing sensitive files
- Scan drives before opening files
- Disable AutoPlay or AutoRun
- Do not lend drives containing private information
- Keep backups in case a drive is lost
- Label drives without including sensitive contact details
- Securely erase old drives before disposal
- Never use a promotional USB from an unknown source
CISA also recommends using passwords and encryption to protect USB data and maintaining backups in case a drive is lost or stolen.
A found USB drive is not a free storage device or a mystery worth solving. It may contain malware, steal information, or behave like a malicious keyboard the moment it connects.


