Is an eSIM safe? What can and can't be hacked, and how to protect yours

How secure an eSIM really is, why SIM-swap fraud targets your carrier account, why eSIM QR codes are secrets, and what a travel eSIM provider can see.

· 10 min read

Yes, an eSIM is at least as safe as a physical SIM, and in a few ways safer. The chip that stores it is a certified secure element that nobody can pull out of a stolen phone, and profiles are delivered over an encrypted, authenticated channel defined by the GSMA. The realistic risks sit around the eSIM rather than in it: someone talking your carrier into moving your number, a leaked activation code, or a phishing message dressed up as your provider.

What an eSIM actually is, in security terms

An eSIM is two things: a chip soldered into the phone, called the eUICC (embedded Universal Integrated Circuit Card), and one or more profiles stored on it. A profile holds the same secret keys a plastic SIM holds. Those keys prove to the mobile network that you are you. (The non-security basics are in what is an eSIM.)

The chip is a tamper-resistant secure element, the same class of hardware used in bank cards. The keys are generated and used inside it and are not designed to be read out, including by iOS or by apps on your phone.

Profiles are delivered by a process the GSMA calls Remote SIM Provisioning (specification SGP.22 for consumer devices). Three safeguards matter:

  • Mutual authentication. The phone's eUICC and the server issuing the profile (the SM-DP+) each prove their identity with certificates that chain back to GSMA-approved certificate issuers. A fake server can't push a profile to your phone, and a fake phone can't pull one from a real server.
  • Encryption. The profile is encrypted for your specific chip while in transit.
  • Certified hardware and sites. The GSMA requires eUICC chips and their software to pass security certification, and audits both the factories that make them and the provisioning platforms that issue profiles under its Security Accreditation Scheme (SAS).

None of this makes an eSIM unhackable. Researchers at Aalto University in Finland published a security analysis of the provisioning protocol in 2024, and the GSMA welcomed it and its suggested improvements. What such research doesn't show is a practical way for a stranger to copy the eSIM out of your phone.

eSIM vs physical SIM: where each is weaker

RiskPhysical SIMeSIM
Thief removes the SIM and puts it in another phonePossible in secondsNot possible; the chip is fixed
Thief keeps your number working to receive codesPossible with the removed SIMOnly by getting past your phone's passcode
SIM-swap fraud via the carrierPossiblePossible, same method
Cloning the SIM's keysVery hard on modern SIMsVery hard; keys stay in the secure element
Leaked activation detailsNot applicableA risk until the profile is installed
Phishing for your carrier loginPossiblePossible

The one clear win for eSIM is physical theft. When a phone with a plastic SIM is stolen, the thief can pop the SIM into another handset and start receiving your bank's text codes. Apple's own support page puts it plainly: an eSIM "is more secure than a physical SIM because it can't be removed if your iPhone or iPad is lost or stolen." Apple's deployment guide adds that eSIM profiles can't be exported from one eUICC to another under the GSMA specification, and that reusing a stolen phone's SIM to receive one-time passcodes "isn't possible" with an eSIM.

SIM-swap fraud is about your account, not your chip

SIM-swap fraud is the risk most people have in mind when they ask whether an eSIM can be hacked. It works like this: a criminal convinces your carrier, usually by phone or in a store, that they are you and have a new phone. The carrier moves your number to a SIM or eSIM the criminal controls. From then on, your calls and SMS codes go to them.

Nobody touched your phone or your eSIM. The attack goes through the carrier's customer service, which is why switching to an eSIM neither causes nor prevents it.

In the United States, the FCC adopted rules in November 2023 requiring carriers to use secure methods to authenticate customers before moving a number to a new SIM or a new provider, and to notify customers of those requests. Carriers elsewhere have their own controls. What you can do yourself:

  • Turn on your carrier's SIM and number locks. They're free and usually off by default. As of September 2026, Verizon offers SIM Protection (blocks SIM changes) and Number Lock (blocks transfers to another carrier), AT&T has Wireless Account Lock in the AT&T app, and T-Mobile has SIM Protection for postpaid customers plus separate port-out protection. Outside the US, ask your carrier for an account PIN or passcode.
  • Remember to switch the lock off before a new phone. A lock blocks your own legitimate transfers too. Turn it off, move your line, then turn it back on.
  • Use a strong, unique password on your carrier account, with two-factor login.
  • Move important accounts off SMS codes where you can. Authenticator apps, passkeys and bank-app approvals don't depend on your phone number.
  • Treat a sudden "No Service" at home as a warning sign. If your home line drops and won't come back while others nearby have signal, call your carrier from another phone.

What about eSIM Quick Transfer?

eSIM Quick Transfer moves your line from an old iPhone to a new one. Apple requires both phones to be signed in to the same Apple Account, nearby with Bluetooth on, and the old iPhone unlocked with its passcode, and you confirm the transfer on the old phone. That's why it isn't the same thing as a SIM swap, which is someone else persuading the carrier to move your number without your devices involved. T-Mobile notes that its SIM Protection doesn't block eSIM transfers between Apple devices, precisely because of the security steps already built into that process.

QR codes and activation codes are secrets

This is the one risk that is specific to eSIM, and it's easy to overlook.

When you buy an eSIM, the provider gives you an activation code, often shown as a QR code, sometimes as an SM-DP+ address plus a matching code. That code points to a profile waiting to be downloaded. Until the profile is installed, anyone who has the code can try to install it on their own phone first.

Most profiles can only be downloaded once. If someone else uses your code before you do, the profile ends up on their phone and your install fails. On a data-only travel plan, that means lost data. On a carrier eSIM tied to your real number, it could mean losing your line until the carrier reissues it.

So:

  • Don't post screenshots of an eSIM QR code or activation details, including in travel forums asking for help. Crop them out or describe the error instead.
  • Don't forward them in group chats or to an email address you don't control.
  • Delete screenshots once the eSIM is installed.
  • Prefer in-app installation. Cabin Mode installs the eSIM directly from the app, so most people never see a QR code at all. See how to install an eSIM on iPhone.

Phishing: the attack that actually works

Most people who lose an account don't lose it to cryptography. They lose it to a convincing message. Patterns worth knowing:

  • "Your eSIM needs to be reactivated, scan this QR code." A QR code from a stranger can direct your iPhone to install a profile from a server you didn't choose, or open a fake login page. Only scan eSIM codes that you requested, from the provider you paid.
  • "Confirm your eSIM transfer" texts or calls. Your carrier won't ask you to read out a code it has just sent you. If someone asks for one, hang up.

Before an eSIM installs, iOS asks you to confirm adding the plan. If anything on that screen isn't what you expected, cancel.

What a travel eSIM provider can and can't see

A travel eSIM provider sits between you and the networks abroad. Here is what that position allows, using Cabin Mode as the concrete example.

What Cabin Mode can see:

  • Your email address and what you bought, when, and what you paid. Card details go to Stripe; Cabin Mode never receives the full card number.
  • The identifiers of the eSIM issued to you, including its ICCID, plus its status, validity dates and data used, as reported by the network operator one to three hours after the fact.
  • Basic product analytics, such as which screens you open in the app, linked to an account ID rather than your name or email.

What Cabin Mode can't see:

  • What you browse, send or stream. There is no technical access to the traffic itself.
  • Your location. Cabin Mode doesn't collect it.
  • Your home number, calls or SMS. The travel eSIM is data only and has no number.

What the networks can see: like any mobile connection, including roaming on your home SIM, the networks carrying your data handle network-level identifiers and can see which servers you connect to. They can't read the content of encrypted connections, and almost everything on a modern iPhone, from banking apps to iMessage, WhatsApp and HTTPS websites, is encrypted end to end or in transit.

The full details are in the privacy policy.

A short checklist before you travel

  1. Set an account PIN or number lock with your home carrier.
  2. Make sure your iPhone has a passcode, and that Find My is on.
  3. Move your most important logins to an authenticator app or passkey where the service allows it.
  4. Install the travel eSIM from the app, not from a shared screenshot.
  5. Keep your home line on for bank codes, with Data Roaming off. Keeping WhatsApp and bank codes abroad covers the setup.
  6. If your phone is lost or stolen abroad, mark it as lost in Find My and contact your home carrier to suspend the line, as Apple advises.
  7. When you sell or give away an iPhone, erase it with Settings › General › Transfer or Reset iPhone › Erase All Content and Settings and choose to delete the eSIM, so the next owner doesn't inherit your line.

Frequently asked questions

Can an eSIM be hacked?

Not in any practical way that affects ordinary users. The eSIM's keys live in a certified secure element and profiles are delivered encrypted and authenticated under GSMA specifications. The realistic threats are SIM-swap fraud through your carrier, leaked activation codes and phishing, all of which you can guard against.

Is an eSIM safer than a physical SIM?

In one important way, yes: a thief can't remove an eSIM and put it in another phone to receive your text codes. Against SIM-swap fraud they're equal, because that attack targets your carrier account, not the chip.

Can someone steal my eSIM with a QR code?

If they get hold of your activation code before you install the profile, they can try to install it first. That's why you shouldn't share screenshots of eSIM QR codes. Once the eSIM is installed on your phone, the code can't be used to take it.

Can a travel eSIM provider see my browsing history?

Cabin Mode can't. It sees your purchase, the eSIM's identifiers and how much data you've used, but has no access to the content of your traffic. Networks carrying the data can see network-level information, as with any mobile connection, but not the content of encrypted apps and websites.

Does an eSIM protect against SIM swapping?

No. SIM swapping happens when someone convinces your carrier to move your number, and that works the same for eSIM and physical SIM. Protect yourself with a carrier account PIN or number lock and by moving important logins away from SMS codes.

What should I do if my phone with an eSIM is stolen?

Mark it as lost in Find My, then contact your home carrier to suspend the line so nobody can use your number. The eSIM can't be pulled out and used in another phone, which buys you time. For a data-only travel eSIM there's no number to protect; email the provider if you want to discuss the remaining plan.