A disturbing new report from CompTIA shows that people do not use any common sense to avoid plugging a random USB they found on the road into their computer, exposing themselves to a multitude of unknown threats.
The report is based on a survey where 1,200 full-time employees in the US were asked about their own security practices and those of their employer.
Despite the fact that similar studies have been commissioned by many other IT security companies, this one, in particular, was accompanied by an interesting social experiment.
According to the report, 200 USB sticks were left loose in high-traffic locations in four US cities: Chicago, Cleveland, San Francisco and Washington.
17% of the people who found and took the USBs blindly connected them to their computers, ignoring any common sense that could tell them that a USB could carry a virus.
The USB devices used in the experiment contained a text file that included instructions asking the user to send an email to a specific address or click through to a trackable URL.
This allowed CompTIA to know how many people actually plugged in the USB and then started opening files and indirectly putting their computers at risk.
Some of the people who did it were in their workplace, with some of the observing users being at the International Airport of San Francisco and at some other multinational companies.
Aside from the social experiment, the report that was compiled also included the responses of the survey of 1,200 employees. Some of the most interesting findings are:
- 63% of employees use their company mobile device for personal activities
- 94% of employees connect laptops and mobile phones to public Wi-Fi networks
- 49% of employees have at least 10 different credentials
- 34% of employees have at least 10 unique different credentials
- 37% of employees change their passwords only on an annual basis
- 41% of employees do not know what two-factor authentication is
- 27% of Millennials have fallen victim to interception of their personally identifiable information in the last 2 years
- 19% of employees have fallen victim to interception of their personally identifiable information in the last 2 years
- 45% of employees do not receive any training regarding cybersecurity from their employers
- 57% of employees used paid antivirus software

