By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Unknown USB Flash Drive I Refused to Plug In—It Might Have Saved My Computer
Disclaimer: This story is fictional but inspired by real cybersecurity techniques and social engineering tactics. It is written to educate readers about safe USB practices and cybersecurity awareness.
It Looked Like Someone Had Simply Dropped It
It was an ordinary Tuesday morning.
I arrived at the office earlier than usual because I wanted to finish preparing a vulnerability assessment report before the day’s meetings began.
As I walked through the parking lot, something caught my eye.
Lying on the ground near the entrance was a small black USB flash drive.
No label.
No company logo.
No key holder.
Just a plain USB stick.
At first, I walked past it.
Then curiosity got the better of me.
I turned around, picked it up, and looked at it more closely.
It felt almost new.
There were no scratches or signs of damage.
Someone must have dropped it recently.
My First Thought Was Completely Innocent
Like many people, my first reaction wasn’t fear.
It was curiosity.
I wondered:
“Maybe someone important lost this.”
Perhaps it belonged to a colleague.
Maybe it contained office documents.
Or family photographs.
Or university assignments.
For a brief moment, I even considered plugging it into my work laptop to identify the owner.
After all…
How dangerous could a simple USB flash drive really be?
Then my cybersecurity training kicked in.
A Colleague Had a Different Idea
As I entered the office, one of my colleagues noticed the USB drive in my hand.
He smiled and asked,
“What’s that?”
I explained that I had found it outside.
Without hesitation, he replied,
“Plug it into your laptop. Let’s see what’s inside.”
Several people nearby agreed.
One even joked,
“Maybe there’s Bitcoin on it.”
Everyone laughed.
To most people, it sounded like harmless curiosity.
To me…
It sounded like a potential cybersecurity incident waiting to happen.
Why I Said “No”
I looked at the USB drive.
Then I looked at my laptop.
Finally, I replied,
“I’m not plugging this into any computer.”
My colleague looked surprised.
“Seriously?”
I nodded.
“Yes. We have no idea where this USB drive came from.”
The room became quiet.
One person asked,
“But it’s just a flash drive.”
That’s exactly the point.
Most cyberattacks don’t begin with something that looks dangerous.
They begin with something that looks completely ordinary.
Curiosity Is a Powerful Tool
One thing I’ve learned as a cybersecurity consultant is that attackers don’t always rely on advanced hacking techniques.
Sometimes…
They rely on human curiosity.
Think about it.
If you found:
- A USB drive in a parking lot.
- A memory stick in an airport.
- A flash drive in your office reception.
- A USB device in a conference room.
Would you want to know what’s on it?
Most people would.
Cybercriminals understand that.
And they know curiosity can sometimes be more powerful than technology.
I Remembered a Cybersecurity Awareness Exercise
Years ago, during a security awareness workshop, an instructor shared a story that stayed with me.
He explained how organizations had conducted experiments by placing clearly marked USB drives in public areas around office buildings.
The drives weren’t harmful.
They were part of an internal security awareness exercise.
The goal was simple.
To see how many employees would plug an unknown USB device into a company computer.
The results surprised everyone.
A significant number of employees connected the drives out of curiosity.
Not because they wanted to break the rules.
Not because they were careless.
Simply because they wanted to know what was inside.
That story immediately came back to me as I stood in the office holding the flash drive.
It Wasn’t About Being Afraid
Some people think cybersecurity professionals avoid everything.
That’s not true.
We still use technology every day.
We still download software.
We still connect USB drives.
The difference is that we try to make informed decisions.
The issue wasn’t the USB drive itself.
The issue was that I knew absolutely nothing about it.
I didn’t know:
- Who owned it.
- Where it had been.
- What was stored on it.
- Whether it had been modified.
- Whether it had simply been lost—or intentionally left there.
Without that information, plugging it into my laptop wasn’t worth the risk.
The Office Debate Began
Within minutes, almost everyone in the room had an opinion.
One colleague believed I was being overly cautious.
Another agreed with my decision immediately.
Someone else suggested using an old computer that wasn’t connected to the company network.
The conversation quickly turned into an unexpected cybersecurity awareness session.
What surprised me most was how divided people’s opinions were.
Half the room saw an ordinary USB flash drive.
The other half saw a potential security risk.
That discussion reminded me of something important.
Cybersecurity isn’t always about complicated technology.
Sometimes it’s about making a simple decision before taking the next step.
And in this case…
That simple decision was not to plug in an unknown USB device.
What happened next completely changed how everyone in the office viewed something as ordinary as a USB flash drive.
(Continue in Part 2, where we’ll explore how attackers can use unknown USB devices in social engineering attacks, why this technique is often called “USB baiting,” and the safe ways to handle a found USB drive.)







