Security Market Segment LS
Saturday, 30 April 2016 14:03

66% of USB Flash Drives infected – don’t trust a stray Featured


USB Flash drives left around offices in government, education, enterprise or given away at trade shows are the easiest way for cyber criminals to gain backdoor access.

Security vendor Sophos tested USB keys purchased at a lost property auction and found 66% had malware or virus.

To complicate the matter, a new study from the University of Illinois has found that of nearly 300 abandoned flash drives ‘planted’ at the University campus, 48% inserted the drive and looked at the contents with a median time of 6.9 hours – the first was opened 6 minutes after being found.

A recent experiment by CompTIA littered four US cities – Chicago, Cleveland, San Francisco and Washington, D.C. – with 200 unbranded, rigged drives, leaving them in high-traffic, public locations to find out how many people would do something risky. About 20% of users plugged in the drives and proceeded to engage in several potentially risky behaviours: opening text files, clicking on unfamiliar web links, or sending messages to a listed email address.

And the recent Australian Cyber Security Centre (ASC) conference, 12-14 April in Canberra, imposed tight new regulations on USB usage, with presenters prohibited from bringing slides in on the devices. USBs were not able to be included in satchel bags nor handed out at booths, in the interest of cyber security.

So that is the bad news – no more stray USB drives, please.

Of those who did engage in risky USB insertions

  • 16% scanned the drive with their anti-virus software.
  • 8% believed that their operating system security features would protect them, e.g., ‘I trust my MacBook to be a good defence against viruses’
  • 8% sacrificed a personal computer or used university resources to protect their personal equipment.

There are a few things you can do to protect your computer from USB hijack.

  • Turn off ‘auto-play’ to prevent any executable files or batch files from launching
  • Format the device immediately on insertion – never open any files
  • Consider encryption for any files you put on the device
  • Use a reputable antivirus/malware program like Sophos that automatically checks USB drives

Sophos security expert Bruce Schneier asks which is more idiotic: plugging in a potentially malware-laced USB key, or designing them to be this dangerous?

“People get USB sticks all the time. The problem isn’t that people are idiots, that they should know that a USB stick found on the street is automatically bad and a USB stick given away at a trade show is automatically good. The problem is that the operating system trusts random USB sticks. The problem is that the OS will automatically run a program that can install malware from a USB stick. The problem is that it isn’t safe to plug a USB stick into a computer unless you are absolutely sure of its pedigree.”


Australia is a cyber espionage hot spot.

As we automate, script and move to the cloud, more and more businesses are reliant on infrastructure that has high potential to be exposed to risk.

It only takes one awry email to expose an accounts payable process, and for cyber attackers to cost a business thousands of dollars.

In the free white paper ‘6 steps to improve your Business Cyber Security’ you will learn some simple steps you should be taking to prevent devastating malicious cyber attacks from destroying your business.

Cyber security can no longer be ignored, in this white paper you will learn:

· How does business security get breached?
· What can it cost to get it wrong?
· 6 actionable tips



iTWire can help you promote your company, services, and products.


Advertise on the iTWire News Site / Website

Advertise in the iTWire UPDATE / Newsletter

Promote your message via iTWire Sponsored Content/News

Guest Opinion for Home Page exposure

Contact Andrew on 0412 390 000 or email [email protected]


Ray Shaw

joomla stats

Ray Shaw [email protected]  has a passion for IT ever since building his first computer in 1980. He is a qualified journalist, hosted a consumer IT based radio program on ABC radio for 10 years, has developed world leading software for the events industry and is smart enough to no longer own a retail computer store!



Recent Comments