Skip to content
FRP-148 Fraud & Financial Crime

Should I plug an unknown USB device into a computer?

No. An unknown USB device should not be plugged into an ordinary computer merely to see what it contains.

Avoid this assumption: A USB device behaves only as storage. It may present itself as a keyboard, network adapter, installer, security token or other device capable of changing the computer immediately.

It may contain malware, scripts, booby-trapped documents, encryption or software designed to exploit automatic behaviour.

Connecting it can create access times, system logs, security alerts, recent-file entries and other investigator-generated records.

It may also modify the USB device itself.

Do not use a personal, office or operational computer for testing.

Record the device’s appearance, markings, serial number, capacity, switches, adapters and condition.

Preserve where it was found and who controlled it.

If the device must be examined, use an approved specialist process designed to protect both the evidence and the examination system.

Do not assume antivirus scanning makes ordinary connection safe. Detection may be incomplete, and the scan itself may alter access records or files.

Where the device was supplied by a victim or witness, explain that it should not be reconnected elsewhere while awaiting examination.

If an unknown USB device has already been connected, record the computer, port, time, account, visible prompts, security alerts and any change in behaviour.

Seek specialist support if malware, data transfer or unauthorised input is suspected.

Operational takeaway

Do not connect an unknown USB device to an ordinary computer; preserve it as found and use a controlled specialist process for any examination.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.