Blog

Post-Trip Device Hygiene: What to Do When Crew Return From High-Risk Regions

Headshot of David Gillies, Head of Android Research at iVerify

David

Gillies

·

TL;DR

A device compromised during travel to a high-risk region can carry that access back into the corporate environment invisibly, so post-trip checks matter as much as pre-trip precautions. The risks are current and well documented: the FBI confirmed in February 2026 that Salt Typhoon's telecom intrusions, affecting more than 80 countries, remain "still very, very much ongoing," and zero-click spyware tools like Pegasus and Paragon Graphite continue to surface in active investigations. Jailbreak checks and app scans don't catch OS-level, memory-resident compromise, so "nothing looks wrong" isn't reassurance. A practical post-trip process, telecom exposure review, device integrity re-verification, and credential rotation, closes that gap.

The Trip Isn't Over When the Device Comes Home

Most travel security guidance focuses on the outbound leg: what to do before departure, what to avoid while abroad. The return leg gets far less attention, and it's arguably the more consequential half. A device that picked up a compromise during a trip to a high-risk region doesn't necessarily show any sign of it once the traveler is back. It reconnects to corporate Wi-Fi, syncs with email and internal systems, and whatever access an attacker established during the trip comes along for the ride, invisibly, unless something is specifically checking for it.

What Can Actually Happen to a Device During High-Risk Travel

Rogue or foreign telecom infrastructure and IMSI catchers

Traveling internationally means connecting to telecom infrastructure the traveler's home security team has no visibility into and no control over. That's not a hypothetical concern. The FBI's Michael Machtinger, deputy assistant director for cyber intelligence, said in February 2026 that the threat from Salt Typhoon, the telecom intrusion campaign linked to Chinese state actors, "is still very, very much ongoing," with intrusions now affecting more than 80 countries and continuing to exploit basic infrastructure vulnerabilities rather than exotic ones. A traveler's device sits on that same telecom infrastructure the moment it connects to a foreign network, whether that network is a rogue substitute for the real thing or the real thing itself, compromised upstream.

Definition: An IMSI catcher is a fake base station that induces nearby phones to connect to it so it can identify, locate and, in some configurations, intercept or downgrade them.

Compromised hotel, conference, or airport Wi-Fi

Hotel networks, conference Wi-Fi, and airport hotspots in high-risk regions carry the same exposure any shared, unmanaged network does, compounded by the fact that these are exactly the networks a traveling executive or crew member connects to routinely and without much scrutiny, since doing so is simply part of getting through the trip.

Targeted spyware requiring no user interaction

Zero-click spyware remains an active, documented category of threat, not a historical one. In 2026, Citizen Lab confirmed that Pegasus infected the device of Stelios Kouloglou, a former European Parliament member who had served on the committee investigating spyware abuse, with at least three infections occurring while he held that role. Separately, Paragon's Graphite tool, described by reporting on a 2024 ICE contract as capable of hacking a phone "without the user knowing or even clicking a link," has been documented targeting journalists and activists in multiple countries, and WhatsApp identified more than 90 users targeted with Paragon spyware across its platform. While neither example is aviation-specific, they're included here to show what zero-click tooling looks like in active use.

Why "Nothing Looks Wrong" Isn't Reassuring

A device that passes a jailbreak check and shows no unfamiliar apps can still be actively compromised. Jailbreak detection and app scanning were built to catch a different, older category of threat: unauthorized OS modifications or malicious apps installed through unofficial channels. Modern zero-click exploitation doesn't require either. It operates inside trusted system processes, which is exactly why "the device looks fine" isn't the same thing as "the device is fine." Confirming device integrity after high-risk travel requires visibility into OS-level behavior, not just the surface-level checks a jailbreak scan performs.

"Jailbreak detection is enough" is worth retiring specifically in a post-travel context, because it's the exact scenario where the assumption fails most visibly. A traveling device is precisely the one most likely to have encountered a zero-click tool built to leave no jailbreak, no rogue app, and no obvious trace behind. Treating a clean jailbreak scan as clearance to reconnect the device to corporate systems without further checks is where the myth turns into an actual gap rather than just an outdated assumption.

A Practical Post-Trip Checklist For Travel In/Through High-Risk Regions

A workable post-trip process doesn't need to be exhaustive to be useful; it needs to cover a few specific things consistently. 

  1. Review the device's telecom and network exposure history from the trip: what networks it connected to and whether any are known or suspected risks. 

  2. Re-verify device integrity at the OS level rather than relying on a jailbreak check alone, specifically looking for process-level anomalies that indicate compromise. 

  3. Rotate credentials for anything accessed during the trip, treating any account or system touched on that device as a candidate for a fresh credential rather than an exception to skip because nothing looked unusual.

The first item on that list is usually the hardest to act on without the right telemetry, since most security teams have no record of which telecom networks a traveling device actually touched. iVerify's telecom and location intelligence capability addresses that gap directly, flagging exposure to suspicious or adversary-controlled telecom infrastructure, so a security team reviewing a trip isn't starting from nothing. Combined with continuous, OS-level device integrity monitoring, that turns the post-trip check from a manual, best-effort exercise into something a security team can actually verify rather than assume.

Building This Into Standard Ops

The checklist above is only useful if it runs every time, not just after a trip that already raised concerns. Building post-trip device review into standard operating procedure, the same way pre-trip briefings already are for many organizations, means the process doesn't depend on someone remembering to flag a specific trip as high-risk after the fact. For gov/defense personnel, executives, and internationally operating crew alike, the return leg deserves the same standing process as the departure leg, not a judgment call made case by case.

Get Our Latest Blog Posts Delivered Straight to Your Inbox

Get Our Latest Blog Posts Delivered Straight to Your Inbox

Subscribe to our blog to receive the latest research and industry trends delivered straight to your inbox. Our blog content covers sophisticated mobile threats, unpatched vulnerabilities, smishing, and the latest industry news to keep you informed and secure.

Subscribe

Subscribe