You have probably heard about the, "Whoops! I dropped my USB stick in the parking lot" penetration test that was performed years ago. If not, here is the short version: pen testers configured a bunch of USB memory sticks so that as soon as those sticks were plugged into a computer, they would immediately run some malicious code that the user was completely unaware of. Anybody who used one of these USB sticks would think it was a blank volume, waiting for them to store documents, pictures, whatever they needed. In the background, however, the USB stick would "phone home" and record when it was plugged in, proving that code can be executed by simply plugging in one of these USB drives.
Then... the pen testers dropped a bunch of these USB sticks in a company's parking lot. This is recalled strictly from my own memory, but the numbers were...