Thieves Getting More Creative, Latest Data Theft Method Is Truly Unexpected
In the current digital era, charging cables can be misused by irresponsible parties to steal personal data. Unfortunately, many people remain unaware and casually borrow cables from others without realising the potential risks. This habit of borrowing cables typically occurs when someone is in a public place, such as an airport or hotel. Passengers or guests often borrow a cable from a stranger or staff member, considering it a practical solution when their device’s battery is nearly depleted. However, cybersecurity experts strongly advise against this action as it is extremely dangerous for device security. Borrowing a cable from an unknown party is considered a major mistake that could become a gap for stealing important data from a phone or tablet. ‘There are certain things in life you shouldn’t borrow,’ said Charles Henderson, Global Managing Partner and Head of X-Force Red at IBM Security. He analogised a charger cable to underwear. When you forget to bring underwear on holiday, the solution is to buy new underwear, not borrow from someone else. This principle should be applied to charger cables. Henderson runs a team of hackers hired by clients to break into their computer systems to uncover vulnerabilities. He said hackers have found a way to plant malware in charger cables that can hijack devices and computers remotely. At the annual DEF CON hacking conference in Las Vegas, Henderson recounted how a hacker nicknamed ‘MG’ demonstrated a modified iPhone Lightning cable. After using the cable to connect an iPod to a Mac computer, MG could access the cable’s IP address remotely and take control of the Mac. He could also remotely ‘kill’ the implanted malware and erase all evidence of its existence. Although dangerous, Henderson said the risk of fraud using the method of planting malware in charger cables is not yet widespread. Typically, this method is used to deceive targeted victims, meaning it is not random. ‘But just because we haven’t seen a widespread attack doesn’t mean we won’t see it,’ Henderson said. ‘The technology is very small and very cheap. It can be so small that it looks like a regular cable but has the capability and intelligence to plant malware on its victim. These products will become cheaper to produce, and this is not something the average consumer will track to know when the product can be used on a mass scale,’ he explained. Currently, Henderson said, a greater threat than malware-laden charger cables is the USB charging stations seen in public places like airports. ‘We have seen several examples where people modify charging stations. I’m not talking about power outlets, I’m talking about when there is a USB port at a charging station. Be careful what you plug into your device,’ Henderson said.