Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

You found a USB drive at work. Curiosity can wait

An unknown USB drive may belong to a colleague, but plugging it into a computer is not a safe way to identify its owner. Here is what to do instead.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
5 September 2026
READING TIME
7 min read
TOPIC
Human Security
You found a USB drive at work. Curiosity can wait

A USB drive is sitting beside the printer, in a meeting room or in the company car park. The most natural thought is, “I’ll plug it in for a moment and look for the owner’s name.” The intention is helpful, but an unknown device does not become safe because it looks ordinary.

It may genuinely have been lost by a colleague. It could also contain an infected file, have been left deliberately or come from a computer whose condition is unknown. You do not need to decide which story is true. You only need to avoid moving that uncertainty onto your own computer.

Do not plug it in “just for a second”

Do not insert the drive into a work laptop, a personal computer or the reception desk PC. Do not browse the files, attempt your own antivirus scan or take the drive home. Safe analysis does not mean choosing a computer you mind losing less.

Record or remember where and roughly when you found it. Then hand it to IT, the security team, building security or the contact named in your organisation’s procedure. If no route exists, tell your manager and agree on one controlled place for unknown devices.

Avoid posting a photograph with every detail in a public channel. Someone pretending to be the owner should not receive all the information they need to describe “their” lost property convincingly.

What if somebody says the drive is theirs?

Returning a drive to its genuine owner still deserves care. Ask them to describe its appearance, where they lost it and, for company equipment, its asset label. Do not feed them the answers. The handover should go through reception, security or IT rather than happen anonymously in a corridor.

If the owner confirms that the device held work information, the organisation needs to consider more than the possibility of malware. Losing removable media can also expose its contents to an unknown person. Recovering the drive does not tell you whether somebody copied the data earlier.

A client or conference USB still needs a process

Known provenance reduces uncertainty, but it does not replace a policy. A new promotional drive, files supplied by a client or a service engineer’s device may all be legitimate, yet they should not go straight into a computer with access to sensitive systems.

An organisation can define whether removable media is allowed, who may use it and where files are checked. An approved cloud service is often easier for exchanging documents. Where removable devices are necessary, company-issued encrypted drives and a specific permitted purpose reduce avoidable exposure.

If you already connected it

Do not try to hide the mistake. Disconnect the drive without exploring further and contact IT or security immediately. Tell them:

  • which computer it was connected to;
  • approximately when;
  • whether the system opened a window, file or program;
  • what you did afterwards;
  • where the drive is now.

Do not shut down the computer or delete anything unless the incident handler asks you to. The team may need to isolate the device from the network, preserve evidence and establish what actually happened. Connecting a USB drive is not itself proof of infection, but a delayed report makes an honest assessment harder.

A useful procedure removes the need to improvise

Staff should know where to take an unknown device, and the person receiving it should know how to record and store it. The policy should also make clear that ordinary workstations are not test machines. If the organisation analyses unknown media, a designated specialist should do so in a controlled environment.

The central rule fits in one sentence: do not connect an unknown device to discover whether it is safe.

Source and the limits of our conclusions

In “The Risks of Using Portable Devices”, the US Cybersecurity and Infrastructure Security Agency advises never connecting found media to a PC and instead giving it to nearby security or IT staff. The source supports the core response and the general risks of portable devices.

The suggested lost-property handover, limiting public details and encouraging blame-free reporting are Breachroad recommendations. For a historical example of removable media crossing an apparently isolated boundary, read our article on Stuxnet. Teams can practise confident, practical responses through Breachroad’s cybersecurity awareness training.

SHARE / COPY