Back to all guides

Using eSIM

Is an eSIM secure? Security, hacking and SIM swaps

Learn how secure an eSIM is, which risks such as phishing and SIM swaps remain, and how to protect activation codes, accounts and your device more safely.

Updated: July 26, 20266 min read
Smartphone showing a digital lock as a symbol of account and eSIM security.

An eSIM is secure in normal use: the profile is downloaded to built-in eSIM hardware through a protected process and cannot simply be copied as a separate file. An eSIM does not prevent phishing, account takeover, SIM swaps or theft of an unlocked phone. Your provider account, email account or activation code is often the weakest link.

Key advice: treat the eSIM QR code as a one-time digital key, protect your provider and email accounts with strong unique passwords and multifactor authentication, and share codes only through a trusted support channel.

How is an eSIM technically secured?

The mobile profile is stored in a secure element called the eUICC. The phone retrieves the profile from an SM-DP+ platform and verifies cryptographic identities during delivery. The GSMA explains that the consumer architecture uses certificates and protected connections to authenticate the components involved.

A 2026 GSMA security analysis assesses the protocol as sufficiently protected against network attackers when endpoints are trustworthy. No system is risk-free: compromised endpoints, weak account security and user deception remain possible attack routes.

eSIM, physical SIM and account security compared

RiskeSIMPhysical SIMMain protection
Removing the card from the phoneNot possiblePossibleDevice lock and SIM PIN
Requesting a profile remotelyPossible through provider processReplacement SIM possibleStrong account verification
Stolen QR codeActivation may be abusedNot applicableKeep the code secret
PhishingStill possibleStill possibleVerify sender and domain
Unlocked phone is stolenProfile may remain accessibleSIM can also be usedEnable lost mode and provider block immediately

An eSIM therefore changes the form of the SIM, not every risk involving identity, accounts and telecom fraud.

Can an eSIM be hacked?

Hacking can mean different things. Copying an eSIM profile directly from its secure chip is different from convincing a provider to move your number to a new profile. For consumers, phishing, stolen credentials and social engineering are generally more relevant than a direct attack on the eUICC.

The GSMA explains that an eSIM profile is placed in a secure eUICC over HTTPS and that PKI certificates support mutual authentication. See the GSMA explanation of mobile security.

What is an eSIM SIM swap?

In a SIM-swap attack, a criminal persuades a provider to move your mobile service to another SIM or eSIM. The attack mainly targets account and identity checks rather than physically copying your current chip. Sudden loss of service combined with unfamiliar account notifications is a warning sign.

Which information should you keep secret?

Never publish or openly share:

  • the QR code or complete activation code;
  • a provider confirmation code;
  • passwords or recovery codes;
  • one-time SMS or authenticator codes;
  • photos that show order and account details together.

An EID, ICCID and IMEI are not ordinary passwords, but they are unique identifiers. Share them only with the provider or device manufacturer when support specifically requests them. Read EID, ICCID and SM-DP+ explained to understand the difference.

Secure your eSIM in 8 steps

  1. Use a strong screen passcode with at least 6 digits or an alphanumeric code.
  2. Enable biometric unlocking and the device-finding feature.
  3. Protect your email and provider accounts with unique passwords.
  4. Use multifactor authentication that does not rely solely on the same phone number.
  5. Set an account PIN or port-out lock if your provider offers one.
  6. Hide sensitive notifications on the lock screen.
  7. Keep order details and support contacts outside the phone as well.
  8. Install system updates promptly.

Is a SIM PIN still useful?

A SIM PIN can stop a mobile line from becoming available immediately after a restart, depending on the phone and provider. Do not confuse it with the screen passcode. Never use a publicly known default PIN; change it only when you are certain of the current code, because repeated incorrect entries can block the line.

Recognising phishing around eSIM activation

Be suspicious of unexpected messages claiming that your eSIM is expiring, must be verified again or needs an immediate transfer. Open the provider portal through your own bookmark or app instead of the link. Check the domain, sender and order details.

A genuine support agent does not need your password or full authentication code. Share a QR code only in a secure channel when the provider clearly explains why it is required. For scanning problems, first follow eSIM QR code not working.

What should you do after a suspected SIM swap or account takeover?

Use another secure device and contact the mobile provider immediately. Ask it to block the line and unauthorised transfer, change the passwords for your email and provider accounts, and inspect recovery details. Alert your bank and other critical services if SMS codes may have been intercepted.

Create a timeline of notifications, loss of service and account changes. Do not delete the eSIM profile as your first step: deletion does not reverse an account takeover and may complicate investigation or recovery.

Sources and editorial review

The technical security information was checked against GSMA material. Practical protection still depends on provider procedures, device software and your account settings. This article cannot guarantee protection against fraud and does not replace incident support from a provider, bank or police. Last editorial review: 26 July 2026.

Frequently asked questions

Is an eSIM safer than a physical SIM card?

An eSIM cannot be removed from a phone and inserted into another device, which is a practical advantage. Both types remain vulnerable to account takeover, phishing and provider-level SIM swaps. Protect the device, provider account and connected email account regardless of SIM type.

Can someone copy my eSIM using the QR code?

The QR code can start a profile download and must therefore remain secret. After successful installation, it often cannot be used again, but do not rely on that. Never share it publicly, and report a leaked code that has not yet been used to the provider immediately.

Can a VPN protect my eSIM against a SIM swap?

No. A VPN encrypts certain internet traffic between your device and the VPN service, but it cannot stop an attacker from deceiving your provider into moving your number. Use provider PINs, strong account protection and multifactor authentication that does not depend on SMS where possible.

How can I tell whether my number may have been transferred?

Suddenly losing service while other people still have coverage, an unfamiliar change email or an unexpected new-SIM confirmation can be warning signs. Check ordinary outages and settings first, but contact your provider from another device immediately when several signals appear together.

Should I delete my eSIM after a security incident?

Not automatically. First let the provider or incident team establish whether the line, account or phone was affected. Deletion can make recovery harder and does not remove stolen account access. Ask the provider to block the line if necessary and preserve evidence of unauthorised changes.