When you hold a new iPhone in your hand and are faced with two choices—your familiar physical SIM or an “invisible” eSIM—the question that worries many people most is usually: can an eSIM be hacked? The short answer is that it can be attacked in certain scenarios, but by design eSIMs have very high security, meet Common Criteria EAL4+ standards, and are safer than physical SIM cards in most real-world use cases. This article will help you understand how eSIM protection works, compare it with traditional SIM cards, look at possible attack methods, and show you how to protect your device and mobile account.
Is a secure eSIM safe?

Yes. eSIM is considered secure thanks to three important layers of protection: the eUICC chip meets Common Criteria EAL4+ augmented AVA_VAN.5 + ALC_DVS.2, the GSMA SGP.25 Protection Profile, and the eSA program, or eUICC Security Assurance, used to certify manufacturers’ security. This EAL4+ level is higher than most typical banking apps, which are usually at EAL3+, and it also means the profile and encryption keys cannot be accessed from outside the chip.
However, for eSIM to maintain this level of safety, users need to meet a few basic conditions. The device should be genuine, not jailbroken or rooted; the Apple ID, Google account, or Samsung account should have two-factor authentication enabled; and the eSIM should be purchased from a reputable provider with eSA certification. When these conditions are met, eSIM is one of the best security options available today for personal mobile connectivity.
To better understand the international standards behind eSIM, you can also read the article on the GSMA eSIM standard.
Why is eSIM considered secure?
You can think of eSIM as a small safe welded inside your phone. Unlike a physical SIM that can be removed, eSIM security comes from multiple technical mechanisms designed to protect the device, the profile, and the encryption keys.

First, the eUICC chip is permanently soldered to the motherboard, so thieves cannot remove the SIM and insert it into another phone like a physical SIM. The eSIM profile is also encrypted end to end when it is downloaded from the SM-DP+ server to the device, so the data between the carrier and the chip cannot be read even if the transmission is intercepted.
In addition, the security keys are stored in the Secure Element, a hardware area separated from the operating system. This means the keys cannot be extracted from the chip by ordinary software. Each profile on an eSIM also has independent permissions, so if you install multiple profiles—for example, one Vietnamese profile and one foreign profile—they cannot interfere with one another. If the device is lost, the user can also request the carrier to delete or deactivate the profile remotely, preventing the finder from continuing to use that number.
The carrier-side backend architecture is explained in more detail in the article What are SM-DP+ and SM-DS. In simple terms, eSIM is like a safe inside the phone body: only the carrier with a valid key can load or remove a profile, while outsiders cannot access it directly.
EAL4+ and Common Criteria
Common Criteria, officially named ISO/IEC 15408, is an information security evaluation system recognized by many countries through the Common Criteria Recognition Arrangement, or CCRA. This system is divided into 7 Evaluation Assurance Levels, from EAL1 as the basic level to EAL7 as the highest. The eUICC chip in eSIM reaches EAL4 augmented with AVA_VAN.5 and ALC_DVS.2, commonly referred to simply as EAL4+.
To make it easier to imagine, many typical banking apps and credit cards reach about EAL3+. Microsoft once announced that Windows reached EAL4+ augmented ALC_FLR.3 in 2005, while the Secure Element on premium devices or government smart cards can reach from EAL5+ to EAL7. Therefore, eSIM at EAL4+ is classified as having stronger security than most common financial apps people use every day.
The two extensions AVA_VAN.5 and ALC_DVS.2 are important for eUICC security. AVA_VAN.5 is the highest vulnerability-analysis level in Common Criteria, requiring the chip to be able to resist highly capable attackers in the smart card field and similar devices. ALC_DVS.2 focuses on security processes during chip manufacturing, requiring the factory to follow strict control standards. You can learn more about how GSMA built this standards system in the article GSMA eSIM standard.
SGP.25 Protection Profile and GSMA eSA Scheme
If EAL4+ is seen as the overall “security score,” then SGP.25 is the “specialized exam” that the eUICC chip must pass. This is the Protection Profile dedicated to eUICC in both the Consumer and IoT sectors, specifying in detail the security requirements that manufacturers must meet. The official document code is PP-0100 on the Common Criteria portal and is an important reference source during product certification.
Alongside SGP.25, GSMA also runs the eSA program, short for eUICC Security Assurance. This is a common security certification framework for eUICC software developers. Products that have passed certification are listed on the GSMA eSA Certified Products page, allowing users and businesses to check before buying a device or using eSIM from a specific provider.
For users in Vietnam, the practical check is quite simple. When buying a genuine iPhone, Apple Watch, or Samsung Galaxy device, the eUICC chip inside usually already has eSA certification. Users can also verify by matching the model number on gsma.com/eSA-certified-products. For international travel eSIMs from providers such as SIMPM, the profile is downloaded through an SM-DP+ server that complies with SGP.22, so the security level is equivalent to that of eSIMs from major carriers.
eSIM vs traditional physical SIM security comparison

The question of whether eSIM or physical SIM is safer is often raised when changing phones or preparing to use eSIM for the first time. On important security criteria, eSIM has a clear advantage in most everyday use cases.
| Criteria | eSIM | Physical SIM |
|---|---|---|
| Protection against SIM swap fraud | 5-10 times harder | More vulnerable |
| Protection against physical loss or SIM theft | Cannot be removed | Can be removed |
| Protection against stealth replacement | Requires passcode and biometrics | SIM can be changed more easily |
| Profile encryption | End-to-end qua SM-DP+ | Mainly encrypted during transmission |
| Recovery when the phone is lost | Can be remotely wiped | Need to report to carrier and lock the SIM |
| Removing the SIM when the phone is seized | Not possible | Can be removed |
Across the 6 criteria above, eSIM has the advantage in 5 criteria and is only weaker than a physical SIM in one special situation: when the user needs to remove the SIM from a device that has been seized or severely hacked. For around 95% of normal personal usage needs, eSIM is the more secure choice. For dedicated IoT devices, the difference is even clearer because many devices do not have a screen or a traditional SIM tray. This topic is analyzed further in the article What is eSIM IoT.
5 types of attacks that can happen with eSIM
No security system is absolutely perfect. Understanding attack scenarios in advance is not meant to create worry, but to help users know how to prevent them properly. With eSIM, there are 5 attack types to watch out for.
First is SIM swap fraud. An attacker may impersonate the subscriber to request that the carrier transfer the profile to their own device. With eSIM, this is harder to carry out than with a physical SIM because it usually requires multiple verification steps, but it cannot be ruled out completely.
Second is an SS7 attack, which exploits weaknesses in telecommunications network protocols to intercept SMS 2FA. This is not a problem unique to eSIM, because both eSIM and physical SIM can be affected if the carrier system is compromised.
Third is malware on the device. If the phone is infected with malicious software, attackers may steal the QR code, login credentials, or profile-related data. In this case, the risk comes from the compromised device, not from the eSIM itself.
Fourth is social engineering. This is a common attack method in which scammers trick users into scanning a fake carrier QR code sent via Zalo, Facebook, or email. In Vietnam, this is one of the most important threats to watch for when using eSIM.
Fifth is a supply chain attack. In theory, the eUICC chip could be tampered with in the supply chain, but the likelihood is very low because the ALC_DVS.2 security process requires strict manufacturing controls.
According to the FBI Internet Crime Complaint Center, in 2023 alone in the US there were 1.075 SIM swap fraud cases with total losses of 48,8 million USD. That figure fell from 72,6 million USD in 2022 thanks to carriers tightening verification procedures. Real-world attacks and how to handle them are discussed in more depth in the article Can eSIM be hacked.
See more: Can eSIM be hacked? 7 real attack scenarios + warning signs
6 ways to protect yourself when using eSIM
To reduce risks when using eSIM, users should maintain 6 basic security habits. These methods are also useful for physical SIMs, but they are especially effective when combined with the built-in protections of eSIM.
First, enable two-factor authentication for all important accounts such as Apple ID, Google Account, Samsung Account, banking apps, and e-wallets like Momo or ZaloPay. When possible, prefer authentication apps such as Google Authenticator or Microsoft Authenticator instead of relying only on SMS OTP.
Next, set a strong passcode for the device and enable Face ID or Touch ID. A 6-digit passcode is much harder to guess than a regular 4-digit code. Users should also buy eSIM from reputable sources with eSA certification and check the information on gsma.com/eSA-certified-products if they are using an unfamiliar device or provider.
Also, do not jailbreak an iPhone or root Android, because this can break many layers of operating system security and reduce the protection provided by the eUICC chip. Before scanning an eSIM QR code, carefully check the sender. Only scan QR codes from the official email of the carrier or a trusted provider, and be extremely cautious with QR codes sent via Zalo, Facebook, or unknown accounts. Finally, enable Find My iPhone on iOS or Find My Device on Android so you can locate, lock, or remotely erase the device when needed.
For users in Vietnam, if you lose your phone, contact your carrier’s hotline immediately to request a temporary suspension of the subscriber line. The official hotline numbers include Viettel 198 when calling from a Viettel number or 1800 8098 when calling from another network, VNPT VinaPhone 18001091 and MobiFone 9090. The response time in the first 30 minutes is very important, because that is the window needed to prevent misuse of the line by bad actors.
Real-world eSIM security incidents and lessons learned
Since Consumer eSIM launched under the SGP.22 standard in 2017 together with Apple Watch Series 3, there has been no publicly disclosed zero-day vulnerability directly targeting the eUICC chip itself. Most eSIM-related attacks actually target carrier procedures, such as SIM swap through call centers, or user accounts and behavior, such as being tricked into scanning a fake QR code. This shows that the risk usually lies more in processes and people than in GSMA’s technical standard.
The FBI IC3 report in 2023 g recorded 1.075 SIM swap fraud cases in the US with losses of 48,8 million USD, down 33% from 2022. The main reason is that carriers have tightened verification procedures when handling profile transfer requests. For eSIM users, the SIM swap success rate is 5-10 times lower than with physical SIMs because eSIM transfer usually requires multi-layer verification through the carrier’s official app.
In Vietnam, the more common scam is impersonating a carrier via Zalo, Facebook, or email to send fake QR codes, often under the guise of “free eSIM 5G upgrade” or “bonus 4G data.” The Authority of Information Security under the Ministry of Information and Communications has repeatedly warned users to carefully check the domain after scanning the QR code, not to provide account information, and to verify the source before proceeding. With eSIM, the key rule to remember is that any legitimate transfer or reissue request should be done through the carrier’s official app or directly at a store.
eSIM security in Vietnam
The three major carriers—Viettel, VNPT VinaPhone, and MobiFone—have all deployed consumer eSIM according to the GSMA SGP.22 standard since 2019. Viettel launched eSIM on 1 2, 2019, VinaPhone officially deployed it on 11 3, 2019, while MobiFone also rolled it out in the same period. As a result, Vietnamese users now have access to a level of security similar to eSIM users in the US, Japan, or Europe.
The eSIM activation process in Vietnam usually requires verifying the subscriber’s information using a citizen ID card (CCCD) or identity card (CMND). This is an important step that helps reduce the risk of SIM swap fraud compared with markets that have looser verification processes.
Hotlines for temporary subscriber suspension when a phone is lost
If you lose your phone or suspect that your line has been attacked, contact your carrier immediately to request a temporary suspension. The hotline numbers to save include:
| Carrier | Support hotline |
|---|---|
| Viettel | 198 when calling from a Viettel device or 1800 8098 when calling from another network |
| VNPT VinaPhone | 18001091, free for 24/7 |
| MobiFone | 9090 for all services or 18001090 for complaints |
After the line is temporarily suspended, you need to bring your CCCD to the carrier’s store to verify your identity and reissue a new eSIM. The whole process usually takes about 30 minutes to 1 g hour. The most important rule is to lock the subscriber line as soon as possible, ideally within the first 30 minutes after discovering the device is lost.
See more: eSIM vs physical SIM 2026: Comparing 12 criteria for Vietnamese users
Frequently asked questions about eSIM security
Is eSIM safer than a physical SIM?

Yes. eSIM is safer than a physical SIM on 5 of 6 important criteria, including protection against SIM swap fraud, protection against physical SIM loss, protection against stealth replacement, end-to-end encryption, and remote recovery when the phone is lost. A physical SIM only has one advantage in a special situation: it can be removed from the device when needed.
Can eSIM be hacked?
Yes, eSIM can still be attacked, but the likelihood is low and it usually comes from 5 main directions: SIM swap fraud, SS7 attack, malware on the device, QR code scams, and supply chain attacks. Since the SGP.22 standard was introduced in 2017, there has been no publicly disclosed zero-day vulnerability directly targeting this standard.
Can eSIM be affected by SIM swap fraud?
Yes, but it is about 5-10 times harder than with a physical SIM because eSIM transfer usually requires multi-layer verification through the carrier’s app or official channels. The FBI recorded 1.075 SIM swap cases in 2023, but most incidents still targeted physical SIMs more than eSIMs.
If I lose my phone, will my eSIM be exposed?
No, if you have enabled a passcode, Face ID or Touch ID, and turned on Find My iPhone or Find My Device. The eSIM security keys are stored in the Secure Element, separate from the operating system, so anyone who finds the phone cannot access the eSIM profile directly if the device is properly protected.
Is eSIM on iPhone highly secure?
Yes. eSIM on iPhone has a high level of security thanks to the eUICC chip compliant with Common Criteria EAL4+, combined with iOS Secure Enclave and Apple ID two-factor authentication. This is a protection setup stronger than most standard banking apps on smartphones.
Will resetting the phone remove the eSIM?
Yes. When you factory reset the entire device, the eSIM is usually deleted and must be reactivated with a new QR code from the carrier. For security reasons, the eSIM is encrypted and tied to the device, so it cannot remain intact after a reset. Before resetting, users should contact the carrier for instructions on reissuing the eSIM.
How can you protect an eSIM from attacks?
You can protect your eSIM in 6 main ways: turn on two-factor authentication for important accounts, set a strong passcode and enable biometrics, only buy eSIMs from reputable sources with eSA certification, do not jailbreak or root the device, carefully check the QR code before scanning it, and enable Find My iPhone or Find My Device to lock the phone and erase data remotely when needed.
If you are preparing to travel or go on a business trip to South Korea, Australia, or Europe and need a GSMA-standard secure eSIM solution, you can check out SimPM’s South Korea eSIM or Australia eSIM plans. All profiles are downloaded through an SM-DP+ server compliant with SGP.22 standard, support quick activation with an official QR code, and include a Vietnamese hotline 24/7 to handle security issues when they arise.






