The USB Drop That Changed Pen Testing: Steve Stasiukonis's Credit Union Experiment, Revisited

Twenty years ago, a handful of booby-trapped thumb drives in a parking lot became one of the most-cited social-engineering case studies in security history. What actually happened, and why it still matters.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: several plain black USB thumb drives scattered across weathered asphalt in a parking lot
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Pen tester Steve Stasiukonis conducted a USB drop attack against an unnamed credit union approximately two decades ago.
  • Stasiukonis seeded rigged thumb drives across the credit union's parking lot, then monitored which employees plugged them in.
  • The engagement produced documented results that circulated widely across the security community.
  • Dark Reading revisited the test in episode 18 of its Dark Reading Confidential podcast.

A parking lot. A handful of thumb drives. A pen tester watching from a distance.

That was the entire apparatus of what became arguably the most-repeated anecdote in social-engineering history. Steve Stasiukonis, a penetration tester, scattered USB drives loaded with tracking payloads across a credit union's parking lot. Curious employees found them, some plugged them in, and the results weren't flattering to the institution.

No phishing kit. No zero-day, no elaborate pretext. The attack exploited something far simpler: the human instinct to pick up something that looks useful and see what's on it.

What does this tell defenders about physical attack surfaces today?

The honest answer is: everything the test revealed still applies.

USB-based attacks have grown more capable since Stasiukonis ran his engagement. Firmware-injecting devices and keyboard-spoofing hardware have expanded the threat surface considerably, but the core vulnerability is unchanged. Endpoint controls that block unauthorized removable media remain one of the few technical countermeasures addressing the problem at its root, and adoption stays inconsistent even inside regulated industries like financial services.

The credit union sector falls under National Credit Union Administration oversight in the United States, with data-security obligations that have tightened substantially since the early 2000s. Whether the specific institution Stasiukonis tested ever filed a breach notification isn't part of the public record; the engagement predates most modern notification frameworks.

What entered the public record was the methodology. The test circulated through security conference talks and trade coverage, eventually hardening into standard red-team doctrine. Drop attacks now appear explicitly in MITRE ATT&CK under initial-access techniques.

The physical dimension of that threat is active today. We covered Silent Ransom Group sending actors posing as IT support into law firm offices to insert storage devices into employee computers on 30 May 2026, a reminder that walk-in device insertion hasn't stayed theoretical.

Should you still train employees on this?

Yes, and the training checklist is short. Disable AutoRun and AutoPlay at the group-policy level. Enforce application allowlisting so unknown executables can't run from removable media. Include USB-drop scenarios in awareness programmes, not as gotcha exercises, but as demonstrations of how little friction an attacker actually needs.

Twenty years on, the Stasiukonis test endures because it proved something most security teams already suspected but hadn't documented: curiosity is a reliable attack vector, and a thumb drive in a car park is often all the pretext an attacker needs.

© 2026 Threat Vectr