Honey Stick Project - Phase 1 Results
This report summarizes the findings from Phase 1 of the Honey Stick Project. For background on the project and its methodology, see the project overview.
Methodology
Twenty USB flash drives were prepared with a tracking beacon - a small HTML file that, when opened, sends a GET request to our monitoring server with a unique identifier, timestamp, and the requesting IP address. No executable code was placed on the drives. Each drive also contained several decoy files (fake spreadsheets, text documents) to make the drive appear legitimate.
Drives were distributed across five location categories:
- Corporate office parking lots (4 drives)
- Coffee shops near business districts (4 drives)
- Conference venues during security events (4 drives)
- Public transit stations (4 drives)
- University campus common areas (4 drives)
Each drive was labeled with one of four categories: "Confidential", "Salary Info Q3", "Photos", or no label.
Results Summary
Overall Access Rate
Of the 20 drives dropped, 13 (65%) were plugged into a computer and had at least one file accessed. The remaining 7 drives either were not picked up, were picked up but not plugged in, or were turned in to a lost-and-found without being accessed.
Access by Label
- "Confidential" - 4 out of 5 accessed (80%)
- "Salary Info Q3" - 4 out of 5 accessed (80%)
- "Photos" - 3 out of 5 accessed (60%)
- No label - 2 out of 5 accessed (40%)
Access by Location
- Corporate parking lots - 3 of 4 accessed, average 2.1 hours to first access
- Coffee shops - 3 of 4 accessed, average 3.4 hours
- Conference venues - 2 of 4 accessed, average 6.2 hours
- Transit stations - 3 of 4 accessed, average 4.8 hours
- University campuses - 2 of 4 accessed, average 1.9 hours
Network Analysis
Based on reverse DNS and IP geolocation of the beacon requests:
- 8 of 13 accesses came from corporate networks
- 3 came from residential ISP addresses
- 2 came from university networks
Notable Observations
The conference venue results were particularly interesting. These drives were dropped at a security conference - an event attended primarily by IT security professionals. Even in this audience, 50% of the drives were accessed. This suggests that awareness of the threat does not reliably translate to changed behavior.
The corporate network access pattern is concerning. These drives were not just plugged in at home out of curiosity - they were brought into corporate environments and connected to machines on internal networks. In a real attack scenario, this would provide an attacker with an initial foothold inside the corporate perimeter.
Zero people who accessed a drive reported it to their organization's IT security team during the monitoring period.
Recommendations
- Security awareness training should include hands-on demonstrations, not just slides. Show people what happens when a malicious USB is plugged in.
- Organizations should implement USB device controls that prevent unauthorized storage devices from being mounted.
- Endpoint detection solutions should monitor for new USB device connections and flag unknown devices.
- Regular social engineering testing - including USB drop campaigns - should be part of an organization's security assessment program.
- Create a simple, non-punitive reporting process for employees who find unknown devices. The current "do not plug it in" message is not working. Give people a positive action to take instead.
Next Steps
Phase 2 of the Honey Stick Project will expand the experiment to include more locations, test the effectiveness of different security awareness interventions, and measure whether organizations that have completed awareness training show lower access rates than those that have not.