Are eSIMs secure? eUICC protection, SIM swap risks, and travel eSIMs

An eSIM stores a mobile subscription inside an eUICC and installs it through GSMA Remote SIM Provisioning, where the device's Local Profile Assistant authenticates with an SM-DP+ server before loading the profile.
So the short answer - yes, eSIMs are secure at the profile-storage and delivery layers, but they do not prevent carrier-account takeover, phishing, compromised devices, or weak provider controls. We will separate the protections built into the standard from the risks that occur when buying and using an eSIM.
eSIM security measures
The same consumer provisioning architecture supports carrier-issued subscriptions and travel eSIMs like Ohayu, Airalo, Holafly, and Saily. The storefront can be different, but compatible profiles still depend on the eUICC, Local Profile Assistant, and SM-DP+ infrastructure.
Profile isolation inside the eUICC
The eUICC is a secure programmable component that stores operator profiles. Each profile contains subscription identifiers, authentication material, and network settings used to register with a mobile network.
Normal phone applications can't export these credentials through standard operating-system APIs. The eUICC controls profile installation, activation, deactivation, and deletion in an isolated environment. GSMA's consumer eUICC protection profile targets Common Criteria EAL4+, and it requires an independent evaluation of its security functions and attack resistance.
This is a security boundary, but not a proof that every product is free from implementation defects.
Authenticated profile installation
Consumer eSIM is usually installed through a provider app, a QR code, or manual entry of an activation code. The QR code contains information needed to request a profile.
The process has four main steps:
The Local Profile Assistant connects to the SM-DP+.
The provisioning components authenticate through the GSMA certificate infrastructure.
The SM-DP+ prepares a protected profile package for the target eUICC.
The eUICC verifies and installs the profile.
TLS protects the server connection. The provisioning protocol adds certificate checks and profile-specific protections. According to GSMA analysis, the protocol meets its stated security goals against a network attacker when the participating entities are honest, and their keys remain secure.
Operating-system permissions
On Android, the Local Profile Assistant is a system application. A carrier app can use EuiccManager to download, switch, or delete subscriptions only with the required system permission or carrier privileges stored in the profile metadata.
These controls restrict access to profile management. They do not inspect every action performed by an active operator profile or the provider's backend.
eSIM security risks
So, can an eSIM be hacked?
Yes, but almost never by breaking into the chip itself. The physical chip inside the phone is extremely secure, so attackers rarely try to crack its encryption directly. Instead, they target the weaker links around it, like phone software, carrier accounts, or backend management systems.
In 2025, the GSMA issued this guide to prevent misuse of profile-management keys and installation of malicious Java Card Applications on compatible eUICCs. That application note concerns implementation and profile-management risks.
SIM swapping and carrier-account takeover
SIM-swap fraud usually targets the carrier's identity checks, not the profile in the victim's phone. An attacker impersonates the subscriber and asks the carrier to move the number to another physical SIM or eSIM.
An eSIM prevents someone from removing a card and inserting it into another phone. It cannot stop a carrier from approving a fraudulent transfer. Once the number is reassigned, the attacker can receive calls and verification SMS.
Carrier-account PINs, unique passwords, and non-SMS multi-factor authentication reduce this risk.
QR-code and account phishing
Activation codes should be treated as credentials. They can leak through screenshots, forwarded emails, shared storage, or a fake provider login page.
A QR code does not normally bypass the phone's eSIM installation controls. The realistic risks are stolen activation details, fraudulent storefronts, and provider-account compromise.
Users should not assume every code is reusable or permanently single-use. Reinstallation depends on the provider's policy and whether the SM-DP+ received the correct profile-state updates.
Reseller access and traffic routing
A travel eSIM purchase can involve a retailer, white-label platform, SM-DP+ operator, MVNO, roaming partner, and local mobile network. The company taking the payment may not operate the underlying infrastructure.
A 2025 USENIX study found reseller platforms that exposed profile identifiers and management functions, including EIDs, ICCIDs, profile status, lifecycle controls, static IP assignment, and remote-management options. Researchers also observed traffic from some travel eSIMs leaving through third-party networks outside the user's physical country.
The findings were provider-specific. They do not show that every travel eSIM uses the same routing or reseller permissions. They do show why privacy policies should identify infrastructure partners and international data processing.
Silent SIM Toolkit activity
An active profile can use SIM Application Toolkit functions for operator services and network-triggered actions. In a test of three travel eSIM profiles, USENIX researchers observed proactive activity in two. One opened, used, and closed a data channel; another retrieved an unsolicited SMS without a normal user-facing prompt.
The researchers did not demonstrate arbitrary device control, premium USSD execution, or silent installation of another profile. The verified concern is narrower: some profile-level communication can occur below the normal eSIM settings interface.
Disabling or deleting an unused profile prevents it from remaining active on the mobile network.
What eSIM security does not cover
An eSIM authenticates a subscription. It does not provide a VPN, malware protection, phishing protection, or end-to-end encryption for every application.
HTTPS and application encryption protect content between an app and its server. Mobile networks and infrastructure partners can still process subscriber identifiers, connection times, data volume, cell information, destination IP addresses, and routing data.
A VPN changes the public IP address seen by websites. It does not hide the device from the mobile network providing the connection.
eSIM vs physical SIM security
The eSIM advantage is resistance to physical removal and card replacement. Both formats remain exposed to weak carrier authentication, stolen account credentials, and compromised devices.
How to use a travel eSIM securely
Buy from the provider's verified website or app.
Keep QR codes and activation details private.
Use unique passwords and enable multi-factor authentication.
Avoid SMS as the only protection for sensitive accounts.
Install operating-system and modem security updates.
Check profile-transfer and reinstallation rules.
Review the provider's infrastructure and privacy disclosures.
Disable or delete profiles that are no longer needed.
Contact the carrier after an unexplained loss of service.
To sum up
eSIMs use secure hardware, authenticated profile delivery, and restricted management APIs. Their clearest advantage over physical SIM cards is protection against card removal. The remaining risks are carrier-account recovery, provider infrastructure, activation-code handling, implementation defects, profile-level communication, and traffic routing.