US Govt. plant USB sticks in security study, 60% of subjects take the bait
thenextweb.com
thenextweb.com
I forget the exact numbers and can't find a link to the report at the moment but a fair proportion of them, at least once over the next couple of weeks, ended up getting plugged into a Windows machine on a network that let the call-home happen. At least one of them seemingly got plugged into a machine at a bank branch (presumably they inferred the machine was at a bank from the address the call home request came from) which is somewhat worrying: bank machines that may have access to sensitive information not being locked down at all so the drive could be plugged in and used, the program could run, and the program could access the internet without restriction from that location. A couple of the drives were seen by the server they called home to multiple times, implying that some fools were using the drives as their own without removing any existing information from them. Very few people contacted the email address, so presumably most of the drives that got to phone home once were swiped, wiped, and claimed by their finder (human nature, don't you just love it).
Obviously there is no saying what happened to the ones that didn't call home - they were either not found, found and handed in somewhere where they still languish, found and binned, not plugged into a machine configured to allowed the autorun and call-home to happen, or so on.
I considered grabbing a bunch of cheap flash drives and repeating the experiment myself in my home town but never actually bothered, mainly because it would mean spending beer money on drives I'd never see again!
(Yes, I've set each to point at the other. Neither has comments yet, same story, different sources, although this submission seems just to be summarising and commenting on that one.)
Otherwise couldn't you plug it in, look at the directory and format it and not be exploited?