Malicious USB cables and chargers
A USB cable can contain a tiny computer. One commercial example is the O.MG cable. It looks and works like an ordinary charging and data cable, but it can also tell a connected device that it is a keyboard.
This is a real capability. It is also a targeted physical access risk. There is no good evidence that malicious cables are common in Australian homes or that ordinary public charging ports are routinely stealing people's data.
If someone close to you has access to your home, car, bag or desk, the useful question is simple: do you know where your cable and charger came from? A cable that was given to you or quietly swapped is a more relevant concern than a random cable at an airport.
The strongest protection is to use a charger and cable that you obtained yourself and kept under your control. Do not accept or keep gifted cables, chargers or adapters when their source concerns you. Carry a power bank when you may need it. Use a wall power socket with your own charger instead of an unknown USB port. A trusted charge-only cable or USB data blocker is a useful fallback. Keep your phone or computer locked while it charges. These habits also avoid many ordinary faults and privacy mistakes.
Safety timing: If you are worried about a current or former partner, family member or carer, do not make sudden changes if that could put you in danger. Removing access can alert the other person and may escalate their behaviour. Use a safer device to contact a support service first. The order is safety, support, evidence, then cleanup. eSafety gives the same warning about technology-facilitated abuse.
Before you change anything, please read this
If someone is monitoring you, the moment they lose that access is often the moment things get more dangerous. Family violence services see this pattern often enough that it shapes all of their advice.
So, three things before you touch a setting:
- Do not uninstall an app you suspect, and do not factory reset your phone, as your first move. It can tell the other person that you know.
- Removing it also removes the proof. If you might ever want to go to the police, that proof matters.
- Talk to someone first. 1800RESPECT is free, confidential and open 24 hours, on 1800 737 732. If a call is not safe, you can text 0458 737 732 instead. Use a phone you trust rather than the one you are worried about.
None of this means you have to keep a phone you do not trust. It means the order matters, and the safest order starts with a plan and a person, not with a delete button.
One more thing worth knowing now. Talking about this near the phone can be enough. If monitoring software is running, it may be able to hear the room. Have this conversation somewhere else, or on another device.
What this page will not do
This page will not teach you how to operate a malicious cable. It does not include payloads, commands, setup steps or buying instructions.
It will not give you a visual checklist for identifying one. A well-made implanted cable can look exactly like a normal cable. A normal phone app cannot inspect the electronics hidden inside a moulded plug, and a dormant implant can still pass through ordinary charging and data. Visual inspection may find a damaged or crude fake, but it cannot clear a cable as safe.
There is no useful app that can promise your cable is genuine. Specialist test equipment exists, but that is not a realistic home safety plan. Replacing an unknown cable with one you control is simpler and more reliable.
DSRA receives no money, commission or other benefit from any vendor named on this page.
What an O.MG cable is
The O.MG cable is a USB cable with an electronic implant hidden inside a plug. Hak5's current product page describes it as a handmade cable for authorised security testing, red teams, teaching and training. The O.MG product line was created by a security researcher known as MG and is made by Mischief Gadgets. The current retail listing names Hak5 LLC as the manufacturer. It is sold openly rather than restricted to governments or specialist laboratories. Hak5 documents the product and manufacturer, while its official O.MG collection identifies Mischief Gadgets as the maker.
As checked on 29 August 2026, the basic cable was listed from about US$150 and some versions cost more. That price can change. The important point is that this class of hardware is commercially available at consumer electronics prices. You do not need to assume that a person has rare equipment or a large budget.
When its implant is dormant, the cable can still charge a device and carry normal USB data. That is why appearance and ordinary use do not reveal it.
How the cable works
The connected device accepts a keyboard
The core technique is called keystroke injection. The implant can present itself to the connected device as a USB keyboard and then send pre-written key presses. Computers include standard drivers for ordinary USB keyboards, so they usually do not need a separate vendor driver. Microsoft documents the built-in keyboard driver, and the Australian Signals Directorate describes malicious USB devices emulating a trusted keyboard.
Those key presses have the same practical reach as a person typing on that device at that moment. On an unlocked laptop, they may open menus, type text and act within the signed-in user's session. The exact result depends on the operating system, the screen that is open, security prompts, permissions and any protection software.
Being accepted as a keyboard does not automatically grant administrator rights. It does not automatically unlock a device, reveal files or bypass every confirmation. A pre-written sequence can also fail if the expected app, keyboard layout, timing or screen state is different.
Wireless control and triggers
The cable can create its own short-range Wi-Fi access point. An authorised tester can use a web browser to control it without touching the target device. Supported models also offer stored actions, Wi-Fi triggers, scheduled or startup triggers, and geofencing based on nearby wireless signals. This does not mean the cable contains a GPS tracker. It also does not mean the cable automatically has internet access. These are ways to decide when the implant should act. The current O.MG feature table lists its control and trigger functions.
The advertised self-destruct feature is a logical cleanup function. It erases stored material and leaves the implant inert. The manufacturer's page says it can be recovered with a separate programmer. It does not physically destroy the cable.
Keylogging is limited to particular models and keyboards
The Elite model advertises a hardware keylogger for compatible full-speed USB keyboards with detachable cables. In that use, the cable sits in the path between an external keyboard and the computer and records key traffic passing through it.
That feature does not record typing on a laptop's built-in keyboard. It does not record taps on a phone's on-screen keyboard. A cable used only for charging is not automatically seeing every password you type. These limits follow from where the hardware sits: it can record supported USB keyboard traffic that actually passes through the cable.
Locked phones and computers are harder targets
A locked device is a much harder target because normal keyboard input reaches a lock or sign-in screen rather than an open user session. The cable cannot invent a passcode it does not know. Locking is still a risk reduction rather than a guarantee. A previously approved connection can remain active, and security flaws may exist in particular device and software versions.
For this attack, an unattended and unlocked laptop or desktop is usually softer than a current phone. A computer presents a large keyboard-driven desktop and may accept a standard keyboard immediately. A current phone has a smaller interface, tighter USB data controls and more accessory prompts. Neither is immune.
On an iPhone or iPad, allowing a wired accessory and trusting a computer are separate decisions. Apple's current default requires you to unlock before a new wired accessory can communicate. If a computer asks for trust, approving it allows that computer to sync and access categories of content on the device. Choosing "Don't Trust" blocks that computer's content access. A keyboard-like accessory does not gain all of a trusted computer's data access merely because it can send keys. Apple explains wired accessory access and what the trust decision grants.
Android behaviour varies by phone maker and version. Android's normal file transfer flow requires you to unlock, open the USB notification and select file transfer. A charging-only choice restricts ordinary file transfer, but it is a software setting rather than a physical break in the cable's data wires. Do not treat it as permission to use a cable you do not trust. Google documents the Android USB file transfer flow.
Researchers have also shown why prompts should not be described as perfect protection. A 2025 peer-reviewed study called ChoiceJacking demonstrated malicious charging equipment that could manipulate the input and connection process on tested phones. Most tested attacks required an unlocked phone. Two tested vendor implementations allowed file extraction while locked. The researchers disclosed the problems, and vendors were adding mitigations when the paper was published. This research proves technical feasibility on particular tested versions. It does not establish that public charging attacks are common. The ChoiceJacking paper was published at USENIX Security 2025.
The wider family of malicious USB hardware
An O.MG cable is one form of a broader physical access problem.
- A keystroke injection USB stick looks like storage to a person but presents as a keyboard to the computer. The commercially sold USB Rubber Ducky is a well-known authorised testing example. Its manufacturer describes the keyboard behaviour.
- A hardware keylogger can sit between an external keyboard and a computer, or be hidden in a keyboard cable. It records keystrokes that pass through that connection.
- A malicious adapter can contain the same type of implant while still passing through normal USB functions. The O.MG Adapter is a current commercial example.
- A charger, USB hub or dock can hide modified electronics. Security researchers have demonstrated attacks through altered chargers and hubs. The result depends on the design, the connected device and its safeguards. An unfamiliar dock or adapter deserves the same treatment as an unfamiliar cable.
The practical defence is the same across these shapes: control the small hardware between your device and power, data or an external keyboard.
Public charging warnings need proportion
"Juice jacking" is the name commonly given to stealing data or compromising a device through a public USB charging connection. Official warnings have been repeated for years. For example, the Los Angeles County District Attorney issued a warning in 2019, and US cyber agencies have advised travellers to carry their own charger and cable.
The public evidence is much thinner than the warnings suggest. In 2023 the US Cybersecurity and Infrastructure Security Agency published an article whose author wrote that he had seen no evidence juice jacking was even occurring, and noted that the US Federal Communications Commission was not aware of any confirmed cases. That is one agency article rather than a formal finding, which is itself the point: the warnings are far louder than the evidence behind them. Our search through 29 August 2026 did not find a primary police, court or incident-response report documenting an ordinary traveller as a victim at a public charging station. That is a statement about the public record, not proof that it has never happened. CISA explains the gap between possibility and evidence.
The underlying techniques are real. Researchers demonstrated a malicious iPhone charger in 2013 against the iOS protections of that time. The 2025 ChoiceJacking work demonstrated newer attacks against tested current-era phones. These were controlled security studies, not reports of widespread public-port crime. That work was published under the name Mactans.
For you, this means public USB ports are easy to avoid without panic. Use your own wall charger or power bank. The more relevant family violence scenario is a cable, adapter or dock that a person with motive and physical access gives you or swaps into your home, car or workplace.
Australian advice supports that approach. The Australian Signals Directorate says to use trusted wall chargers and avoid cables, chargers or other devices that were gifted or were briefly in an untrusted person's possession. Its travel guidance also says never to use someone else's peripherals, including chargers and cables. Read the ASD business leader guidance and travel security tips.
As checked on 29 August 2026, we found no dedicated eSafety Commissioner or Scamwatch advisory about malicious USB cables or juice jacking. eSafety does provide the relevant safety-planning and evidence advice for technology-facilitated abuse. Australian technical advice on cables comes from ASD's Cyber.gov.au.
Settings and habits that help
Menus change with software updates and phone brands. Search Settings for the named control if your path differs. Make changes only when it is safe to do so.
iPhone and iPad
- Open Settings > Privacy & Security > Wired Accessories.
- On a current USB-C iPhone or iPad, choose Always Ask for the strongest prompt, or keep the default Automatically Allow When Unlocked. Lightning models offer fewer choices. Older articles may call this protection USB Restricted Mode or place an Accessories switch under Face ID and Passcode.
- If you see Trust This Computer? for a computer you do not control, tap Don't Trust.
- To clear old computer trust decisions, use Settings > General > Transfer or Reset [Device] > Reset > Reset Location & Privacy.
- Keep the device locked while it charges.
Apple's current instructions say an ordinary USB power adapter can charge a locked device without a data connection. Some accessories may not communicate or charge until you unlock. Check Apple's current menu and option descriptions before relying on an older guide.
Android
- With the phone connected to a charger or computer you control, unlock it and open the USB notification. It may say Charging this device via USB or USB preferences.
- Under Use USB for, choose No data transfer or leave it on charging only. The wording varies. Do not select file transfer for an unknown computer or cable.
- If Developer options are already visible, open Settings > System > Developer options. Check that USB debugging is off. Under Default USB configuration or Select USB Configuration, choose No data transfer or Charging only. Paths vary, and some brands put Developer options elsewhere. You do not need to enable Developer options just for this check. Android documents the standard developer option path and USB choices.
- On a supported Pixel 6 or later running Android 16 or later, you can consider Settings > Security & privacy > Other settings > Advanced Protection > Device protection. Google's USB Protection blocks new USB data connections while the phone is locked. Existing connections can continue after re-locking, and availability varies by manufacturer. Google documents Advanced Protection and USB Protection.
- Keep the phone locked while it charges.
Software choices help, but your own cable and charger remain the primary defence. A genuine charge-only cable or a trusted USB data blocker physically leaves out or blocks the normal USB data connection. It can be useful when a USB power source cannot be avoided. Buy that simple safety item from a source you trust, and test that it charges without offering file transfer. A data blocker does not make an unknown electrical supply safe from every possible fault, so your own wall charger or power bank is still preferable.
Laptops and desktops
Lock the screen whenever you step away, even at home or in a shared office. On Windows, press Windows key + L. On a Mac, use Control + Command + Q or choose Apple menu > Lock Screen.
On a Mac laptop with Apple silicon, macOS can ask before a new or unknown USB, Thunderbolt or SD accessory connects. Check System Settings > Privacy & Security > Allow accessories to connect. Apple's default is to ask for new accessories. Charging continues if you do not allow data access. Apple documents this Mac control.
Replace unknown keyboards, hubs, docks, adapters and cables. If you cannot replace a work device yourself, ask your IT or security team to inspect and replace it. Do not reconnect a suspicious item merely to test it.
If a cable in your home may not be yours
Do not confront the person you suspect. Do not immediately throw the cable away if it may be evidence. Removing it or changing access can show the other person that you know.
From a device the other person has not had access to, contact a family violence service or police and make a safety plan. Ask how to preserve the item. If it is safe, write down where and when you found it and photograph it in place without plugging it into anything. Store copies of notes or photos somewhere the other person cannot access. eSafety warns that removing a tracking or monitoring device may alert an abuser and recommends getting advice before acting. Its evidence guide explains the safe order.
If you are in immediate danger in Australia, call 000. For confidential family, domestic or sexual violence support, call 1800RESPECT on 1800 737 732, 24 hours a day. WESNET's technology safety resources for survivors and workers are at techsafety.org.au.
After you have safety and evidence advice, cleanup may include replacing unknown cables and accessories, changing important passwords from a safer device, reviewing account sessions, updating devices, and asking a qualified service to check a computer. The right order depends on your situation. You do not need to prove exactly what a cable is before choosing to stop using it.
Where to get real help
- In immediate danger: call 000.
- 1800RESPECT: 1800 737 732. Free, confidential, 24 hours. If a call is not safe, text 0458 737 732, or use the online chat or video call at 1800respect.org.au. For anyone affected by domestic, family or sexual violence.
- Police assistance line: 131 444, for threats to your safety that are not an emergency.
- WESNET Safety Net Australia: techsafety.org.au. Specialists in technology and family violence. If you use an Android phone and you think spyware may be on it, they ask people to contact them from a safe device.
- eSafety Commissioner: esafety.gov.au. The national regulator. It has legal powers to help with serious online abuse, including image-based abuse.