A USB drive found in the car park: what do you do with it?
An unknown USB drive looks harmless, but it's a classic trick to get inside your systems. What you should and shouldn't do — without the panic.
It sounds like something from a film, but it really happens: someone finds a USB drive in the car park, in the lobby, or in the toilet of a shared office building. Curiosity wins, the drive goes into a laptop, and a few seconds later there's a problem. In this post we explain why that's more dangerous than it looks, what you should do instead, and how to agree on a simple approach with your team without making it feel like a big deal.
Why a found USB drive is a risk
A USB drive looks like a passive little storage device, but the moment it's plugged into a computer, all sorts of things can happen. Some drives pretend to be a keyboard and type commands at lightning speed. Others contain files with names like "Salaries 2026.xlsx" — designed precisely to be clicked on. And then there are ones that damage the computer through a power surge.
This attack even has a name: USB drop. Research by universities and security firms shows that somewhere between 45 and 90 percent of found drives actually get plugged into a computer. People want to help, or they're simply curious. That's human — and exactly what the attacker is counting on.
The three most common scenarios
1. The "curious finder"
An employee finds a drive, wants to know who it belongs to, and plugs it into their work laptop to track down the owner. The drive contains a document with an enticing name. One click — and software is silently installed in the background.
2. The "helpful reception desk"
Someone drops off a drive at the front desk: "I think this belongs to one of your colleagues." The receptionist wants to help and opens it on the reception PC to take a look. That PC often has access to the internal network.
3. The targeted attack
At companies that make attractive targets (law firms, financial services, engineering, construction with major clients) a drive like this is sometimes left behind deliberately. Often in an envelope with a logo on it, or with a sticker reading "confidential." That only increases the chance of someone plugging it in.
What should you do if you find one?
- Don't plug it into a computer. Not even "just quickly on an old laptop." Old laptops are usually still connected to your network too.
- Set it aside in an envelope or drawer, with a note: where and when it was found.
- Report it internally. To the office manager or whoever handles IT. One central point of contact stops three people from going off and experimenting on their own.
- Ask around whether anyone has lost it. More often than not, it's simply a colleague who dropped their own drive. If so: great, hand it back to the owner.
- Nobody comes forward? Then the safest option is to physically destroy the drive (cut it in half — it's surprisingly easy). Throwing it in the bin is just an invitation for the next round.
What if it has already happened?
Someone has already plugged the drive in. Don't panic, but do act quickly:
- Disconnect the laptop from the network (turn off Wi-Fi, unplug the cable).
- Leave it switched on — don't turn it off or restart it. Some attacks wipe their traces on reboot.
- Write down exactly what was clicked and at what time.
- Call someone who knows what they're doing. An IT partner can check the logs to see whether anything has happened.
- Change the passwords for any accounts that were active on that laptop, from a different device.
Prevent it from happening in the first place
You don't need to write a complex security policy. Three simple agreements are enough:
- Don't plug in unknown USB devices. Full stop. Not a "freebie" from a trade show, not a charging cable from a stranger.
- Use the cloud for file sharing instead of physical drives. A shared folder or a link with an expiry date is safer and easier to track down later.
- Block USB ports where possible. Nobody needs to plug a drive into reception PCs, printers, or shared workstations. Windows and macOS can block this centrally.
Bring this up at a ten-minute team meeting. That's worth more than a lengthy policy document nobody reads.
What about chargers?
One more for when you're on the go: a USB charging cable or power bank that you "borrow" from a stranger, or find on a train, falls into the same category. There are cables that look identical to a standard Apple or USB-C cable but secretly contain a tiny computer. Buy your own charger, and in public spaces use only a mains socket with your own adapter.
In short
A found USB drive isn't something to panic about, but it's not something to casually plug into your laptop either. Report it, set it aside, and agree with your team that unknown hardware doesn't get plugged in anywhere. That one simple agreement can save you a huge amount of trouble on a bad day.
Want to know who has access to your systems and whether anything could do with being tidied up? Take a look at our access check, or read how we approach website security for businesses without their own IT department.
Volledige gids: Security for SMBs without an IT department: what should you do this quarter?
Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.
Lees de pillar →