Security researchers at the Citizen Lab tested nine cloud keyboard apps and found that eight of them sent what people typed across the internet in a form that anyone on the same network could read. They estimated that up to one billion users were exposed. The keyboard is the one part of your device that sees every password, every ID number, and every bank login in plain text, before your encryption, your password manager, or your bank's own security ever get a turn.
What your keyboard does that you never agreed to
A keyboard, whether it is the app on your phone or the device on your desk, reads every character you enter before it reaches whatever you are typing into. That position is the point. Your messaging app encrypts the chat after you have written it, and your bank protects your login after you submit it, but the keyboard sits upstream of all of that and handles your input while it is still readable.
On phones, many keyboards send what you type to a server to sharpen their word prediction. These are called input method editors, or IMEs, and the cloud feature is where the leak begins. The Citizen Lab report, published in April 2024, found that eight of nine cloud keyboard apps it examined transmitted keystrokes in a way an eavesdropper could decrypt, and Samsung's own keyboard used no encryption at all. That study looked at Chinese-language keyboards, so it is not a verdict on every keyboard you might install, but the mechanism is not unique to them. Any keyboard that ships your typing to a server can leak it if that channel is weak, and anyone on the same wifi, your internet service provider, or a virtual private network (VPN) sitting in the path can read what comes through.
The permission that makes this possible is in plain sight. When you install a third-party keyboard on an iPhone and enable Full Access, iOS warns you that the developer can transmit anything you type, including things you typed earlier. On Android, keyboard apps routinely ask for network access alongside the microphone and your contacts. GO Keyboard, with more than 200 million users, was caught sending user data to advertising networks, and Microsoft's SwiftKey collects the words and phrases you type when its cloud feature is switched on. Most people grant Full Access for a theme or an emoji pack and never think about it again.
A keyboard does not even need a network connection to give you away. In 2023, researchers at several British universities trained a model to recognise laptop keystrokes by sound, reaching 95% accuracy from a phone microphone placed nearby and 93% over a Zoom call. A meeting with your microphone open, while you type a password into another window, is enough to hand your typing to anyone running that recording through the model.
Wireless keyboards add their own exposure. In December 2023, researcher Marc Newlin disclosed a Bluetooth flaw, CVE-2023-45866, that let an attacker within range inject keystrokes into Android, Linux, macOS, and iOS devices by impersonating a paired keyboard, with no confirmation from the user. The same researcher had shown in 2016, in work he called MouseJack, that wireless keyboards and mice from 17 vendors could be sniffed or hijacked over the air. Each of these defeats a different assumption: that the app boundary protects your input, that an offline keyboard is safe, that a device you paired once stays trustworthy. The keyboard layer is the part of your security that almost everyone trusts without checking, which is the one thing a zero trust approach tells you not to do.
Why this matters more in South Africa
South Africa runs on mobile, most people bank from a phone, and that is where the keyboard risk and the fraud risk meet. The South African Banking Risk Information Centre (SABRIC) reported that 65.3% of fraud incidents recorded in 2024 came through digital banking platforms. The method behind a large share of that mobile fraud is keystroke capture. Android banking trojans such as Klopatra and Sturnus, and the long line of malware descended from Cerberus, abuse Android's Accessibility Services to log every key a victim presses and read everything on the screen. Security firm Kaspersky recorded a 196% rise in mobile banking trojan attacks during 2024. Here, a leaking keyboard is the working method of fraud that is already draining accounts.
There is a POPIA angle most businesses have not mapped. Under the Protection of Personal Information Act (POPIA), the keystrokes your staff enter become personal information the moment they include a client's identity number, a banking detail, or anything you process on a client's behalf. If a staff member's phone runs an unvetted keyboard that harvests input, or a trojan that logs it, the responsible party under POPIA is your business, and the duty to apply reasonable safeguards and to report a confirmed breach to the Information Regulator runs against you, not the app developer. For a KZN business where staff use personal phones for work email, accounting, and WhatsApp, the keyboard on a personal device is part of your security perimeter whether you decided that or not.
What to do this week
- Use the built-in keyboard on any device that touches business data, and remove the novelty ones. On an iPhone, open Settings, then General, then Keyboard, and turn off Full Access or delete third-party keyboards entirely. On Android, review which keyboards are installed and what permissions each one holds. The keyboards from Apple and Google are the safer default, and a keyboard that arrived bundled with a theme pack is the first thing to drop. Should you wish to use an aftermarket keyboard, FUTO Keyboard is a privacy first option
- Stop typing your most sensitive details by hand. Turn off cloud prediction and sync where the option exists, and use a password manager that fills in your credentials so they are never keyed in character by character. What you do not type cannot be logged on the way in.
- Patch everything, then deal with Bluetooth. The fixes for the Bluetooth keystroke-injection flaw shipped in operating system updates and keyboard firmware, so update your phones, laptops, and any wireless keyboard you own. Switch Bluetooth off when you are not using it.
- Treat an open microphone as a recording device. On video calls, mute yourself when you are not speaking, and avoid typing passwords or banking details while your microphone is live.
- Audit the staff devices that reach your business data. Look for keyboards nobody recognises and for apps holding broad Accessibility permissions, which is the access banking trojans abuse. Treat any device with an unknown keyboard or an unexplained Accessibility grant as compromised until it is cleaned, and write down what personal information that device can reach so your POPIA position is defensible.
Where Ubuntu Guard fits
If you are not sure which devices in your business run keyboards or apps you have never vetted, or what those devices can reach, that is what our cybersecurity assessment covers. We go through your phones, laptops, app permissions, and the POPIA obligations that sit behind them, and we give you a plain-language report with a prioritised list of what to fix and in what order. No jargon, no pitch for tools you do not need.
Not sure what your team's devices are sending out? WhatsApp us and we will walk you through the first step: wa.me/27791595040. Or reach us at [email protected].
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za