Can an eSIM Be Hacked? 7 Real-World Attack Scenarios

When they receive a strange message impersonating a carrier, or see their banking app report unusual transactions, many people immediately ask: “Can my eSIM be hacked?” The answer is yes in theory, but in practice it is very rare. From 2017 to the present, no public zero-day exploit against the GSMA SGP.22 standard eUICC chip has been disclosed. Most of the risks users face do not come from hackers breaking the eSIM chip, but from methods such as SIM swap, fake QR code scams, identity theft, or abusing the carrier’s verification process. The article below will analyze 7 eSIM attack scenarios, 6 signs to recognize, 5 immediate actions to take when you suspect an attack, and effective ways for users in Vietnam to protect themselves.

Can an eSIM be hacked?

This is a very important question for anyone preparing to switch from a physical SIM to an eSIM. The straightforward answer is: an eSIM can theoretically be attacked, but the chance of it happening in real life is very low. To understand the risk correctly, it is necessary to distinguish between two cases: direct hacking into the eUICC chip of the eSIM and attacks on the processes around the eSIM.

Can an eSIM be hacked?
Can an eSIM be hacked?

To date, no direct hack of an eUICC chip has been publicly confirmed since the eSIM Consumer standard SGP.22 was launched in 2017. However, attacks such as tricking a carrier into moving the eSIM to another device, luring users to scan fake QR codes, or stealing login credentials can still happen. In other words, most of the risk does not lie in eSIM technology itself, but in people, verification processes, and how users protect their accounts.

Understanding this point correctly will help you focus your defenses in the right place. Instead of worrying that the eSIM chip can be “broken” remotely, users should be more cautious of strange messages, QR codes from unknown sources, fake carrier calls, and scams related to OTPs.

Distinguish 3 concepts that are often confused: hacking, SIM swap, and scams

When reading news about “eSIM hacking,” many people tend to lump different types of attacks into the same category. In reality, eSIM hacking, SIM swap, and social engineering scams are three different concepts, with very different mechanisms and levels of prevalence.

ConceptHow it worksLevel of prevalence
Hack eSIMA technical attack on the eUICC chip or the SM-DP+ backend systemVery rare, no confirmed cases since 2017
SIM swap fraudTricking the carrier into moving the eSIM profile or phone number to the attacker’s deviceCommon in the US, the FBI IC3 g recorded 982 cases in 2024
Social engineering scamsLuring users to scan fake QR codes themselves or provide OTPs or personal informationThe most common in Vietnam today

Distinguishing these three concepts is very important. True eSIM hacking requires a technical vulnerability in the chip or eSIM infrastructure, something that is almost never seen in publicly known real-world cases. SIM swap, on the other hand, relies on weaknesses in the carrier’s verification process. Meanwhile, social engineering attacks target users’ psychology directly, causing victims to voluntarily provide information or install a malicious profile themselves.

In Vietnam, the most notable risk right now is not hackers breaking the eSIM chip, but QR code scams via Zalo, Facebook, email, or fake carrier messages. Therefore, users need to be especially cautious of any request to scan a QR code that does not come from an official channel.

7 specific eSIM hacking scenarios

The scenarios below are arranged by real-world relevance, from forms that have already occurred in Vietnam and internationally, to risks that mainly exist in security research or theory.

Common group, has happened in reality

  • SIM swap qua eSIM transfer: The attacker impersonates the subscriber, contacts the carrier’s call center or support channel, and requests that the eSIM be moved to their device. Compared with a physical SIM, an eSIM is harder to take over because the verification process usually has multiple layers, but the risk still exists if the attacker knows a lot of the victim’s personal information.
  • Phishing QR code: This is a fairly common form among Vietnamese users. The attacker sends a fake QR code via Zalo, Facebook, email, or message, then lures the user to scan it on the pretext of “upgrading the eSIM,” “receiving free data,” or “activating 5G”. When scanned, the user may accidentally install a profile controlled by the attacker instead of the official carrier profile.
  • Malware stealing QR codes: Some malicious software on devices can scan emails, screenshots, or storage folders to find valid eSIM QR codes. If the QR code has not yet been activated or is still valid, it can be sent to the attacker’s server for exploitation.

Technically possible group

  • SS7 attack: This is an attack that exploits vulnerabilities in legacy signaling protocols of telecommunications networks to intercept SMS or OTPs. The SS7 attack affects both eSIMs and physical SIMs, because the issue lies in the network infrastructure, not in the eSIM itself.
  • Supply chain attack: In this scenario, the eUICC chip could be tampered with during manufacturing or in the supply chain. However, the likelihood is very low because eUICC chips must comply with strict security standards, including evaluation processes such as ALC_DVS.2 at the chip manufacturing factory.

Group that is mainly theoretical

  • eUICC side-channel attack: The attacker measures the power consumption or electromagnetic radiation from the chip to infer encryption keys. This method requires physical access to the chip, specialized laboratory equipment, and a very high level of technical expertise, so it is almost impossible for remote attacks in everyday life.
  • Bluetooth proximity attack: A hacker exploits a Bluetooth vulnerability on the device, then indirectly affects the eSIM or related accounts. This scenario is very rare and requires the attacker to be near the device within Bluetooth range, usually under 10 meters.

It can be seen that the most practical risks for ordinary users are still SIM swap, fake QR codes, and malware. The remaining scenarios do have a technical basis, but they require very special conditions and rarely occur in practice.

6 signs that an eSIM may have been hacked

The signs below are like early warning signals. A single sign may only be a network or device error, but if two or more appear at the same time, you need to check immediately.

  • Sudden loss of signal for no clear reason: If the phone is in an area with strong signal but suddenly loses service, and restarting still does not restore the connection, this could be a sign that the eSIM profile has been moved to another device.
Sudden loss of signal for no clear reason
Sudden loss of signal for no clear reason
  • Cannot make calls, cannot receive calls or SMS: This is a very clear sign that the phone number or profile has been taken over. Users often only notice when they do not receive OTPs, bank calls, or verification messages.
  • Bank OTPs, Apple ID, or important account codes are sent to a different device: If you do not receive the OTP but the system still says the code has been sent, be especially cautious. In the worst case, the attacker may be receiving the authentication codes instead of you.
  • The banking app reports unusual transactions: Small transactions, international transactions, or transactions occurring at night that you did not make are all signs that need to be dealt with immediately.
  • There is a strange profile in the SIM or mobile settings: Users should periodically check the Settings → Cellular/SIM section on the device. If a strange profile, unusual carrier name, or a profile not installed by you appears, contact the carrier to verify.
  • The bill increases abnormally or mobile data usage is unusually high: If the phone number is abused for paid services, international calls, or unusual data usage, the bill may rise sharply for reasons you do not understand.

When two or more signs appear at the same time, you should treat it as an urgent warning. Take immediate action according to the steps below to limit damage before the attacker continues exploiting your phone number or accounts.

5 things to do immediately when you suspect an eSIM has been hacked

If you suspect your eSIM has been attacked, the most important thing is not to panic. Handle it in the priority order below, especially in the first 30 minutes.

  • 1. Disconnect mobile data and Wi-Fi immediately: Turn on Airplane mode to temporarily isolate the device and limit the attacker’s continued access to accounts or transactions. This should be the first step before changing passwords or contacting related parties.
  • 2. Change the passwords for important accounts: Prioritize changing the passwords for Apple ID, Google Account, Samsung Account, your primary email, and banking accounts. At the same time, enable two-factor authentication with an authenticator app such as Google Authenticator or Microsoft Authenticator instead of relying entirely on SMS OTP.
  • 3. Call the carrier hotline to temporarily block the subscriber line: Contact the carrier immediately to check the eSIM status, temporarily block the line if necessary, and prevent unauthorized profile transfers. Some hotline numbers to keep on hand include: Viettel 198 or 1800 8098, VNPT VinaPhone 18001091, MobiFone 9090 or 18001090.
  • 4. Contact the bank to block cards and check transactions: Request the bank to temporarily block the card, block Internet Banking if necessary, and review all transactions in the last 24 g hours. For unusual transactions, a fraud report should be filed as soon as possible.
  • 5. Report to the police and authorities: You can call hotline 113 or send a report to the Department of Information Security through tingia.gov.vn. If there is financial loss, keep evidence such as screenshots, transaction history, messages, emails, and strange phone numbers for the handling process.

The first thirty minutes are a very important window. A bank transfer can happen in just a few seconds, but after a short period of time, the money may have been moved through many intermediary accounts and become very difficult to trace. After dealing with the emergency, users should go directly to the carrier store with their CCCD to verify their identity and reissue a new eSIM.

When is an eSIM almost impossible to hack?

The risk of eSIM attack drops to a very low level if users meet all of the basic security conditions below.

The device should be a genuine model, not jailbroken or rooted. When the operating system still has its original security layers intact, hackers will find it harder to install malware or deeply interfere with the SIM management system. Users should also prioritize two-factor authentication with an authenticator app instead of SMS OTP, because this reduces the risk from SIM swap and SMS interception attacks.

In addition, never scan unknown QR codes under any circumstances. eSIM QR codes should only come from the carrier’s official email, official app, or directly at the store. When buying an eSIM, choose a provider with GSMA eSA certification, use profiles via an SM-DP+ server that meets the standard, and comply with Common Criteria EAL4+.

In Vietnam, major carriers such as Viettel, VNPT, and MobiFone have all tightened their eSIM transfer procedures with multiple layers of verification. Users should also carefully check the email that sends the QR code and only trust official domains such as @viettel.com.vn, @vnpt.vn, or @mobifone.vn.

When all of the above conditions are met, the risk of eSIM hacking remains only theoretical and is almost impossible under normal use conditions.

8 ways to help prevent eSIM hacking in the long term

To protect the eSIM and related accounts, users should maintain the following security habits during everyday use.

  • Enable 2FA with an authenticator app: Google Authenticator, Microsoft Authenticator, or similar apps are safer than SMS OTP because the verification code does not depend on a phone number.
  • Set a strong passcode for the device: Use a passcode of 6 digits or more, combined with Face ID, Touch ID, or biometrics to reduce the risk of unauthorized access.
  • Do not jailbreak iPhone or root Android: Interfering with the operating system can remove default protection layers, making it easier for malware to operate.
  • Check the QR code carefully before scanning: Only scan eSIM QR codes from the carrier’s official email, app, or store. Do not scan QR codes received via Zalo, Facebook, or strange messages.
  • Enable real-time banking transaction alerts: Real-time notifications help you detect unusual transactions within seconds, so you can lock the account in time.
  • Back up account recovery keys offline: The recovery key for Apple ID, Google Account, or other important accounts should be stored in a safe place, not only on the phone.
  • Update iOS and Android regularly: Operating system updates often patch new security vulnerabilities, helping keep the device safer against known forms of attack.
Update iOS
Update iOS
  • Register for SIM swap protection services if supported by the carrier: Some carriers are deploying additional protection layers for high-risk subscribers, especially those linked to banks or important accounts.

When all of these measures are applied, eSIM becomes a highly secure mobile connectivity method, suitable for personal users, international travelers, and businesses alike.

See also: How does eSIM work? Simple explanation of the 4-step process

eSIM hacking in Vietnam: Real cases and lessons learned

In Vietnam, the two notable risk groups in the 2024 to 2025 period mainly came from QR code scams and SIM swap through verification procedures. Neither of these is a technical vulnerability of the eSIM chip, but they can still cause damage if users are careless.

Fake QR scam for “upgrading eSIM 5G free”

Attackers may send messages via Zalo, Facebook, or email, impersonating Viettel, VNPT, or MobiFone to invite users to “upgrade eSIM 5G free,” “receive 10GB data,” or “re-verify the eSIM.” When the user scans the fake QR code, the device may install a profile controlled by the attacker or be led into an information-stealing process.

This is a classic example of social engineering. The hacker does not need to break eSIM technology; they only need to make the user believe that the QR code comes from the real carrier. Therefore, the most important rule is never to scan eSIM QR codes from unofficial channels.

SIM swap via carrier call center

Some past incidents involved attackers calling the hotline, impersonating the subscriber, and requesting the eSIM be moved to another device. Currently, the eSIM transfer process at Viettel, VNPT, and MobiFone has been standardized and tightened further, especially after the subscriber information standardization phase in 2023.

Normally, users need a chip-based CCCD, portrait photo, electronic signature, video call verification with carrier staff, and an OTP sent to the registered number. According to the original article, Circular 08/2026/TT-BKHCN effective from 15 4 2026 will add a facial biometric step to compare with the national population database.

Although the number of successful cases has decreased, the risk may still exist if the attacker has photos of a CCCD, scanned documents, or a lot of the victim’s personal information. Therefore, users should not send CCCD copies through untrusted channels and should limit sharing identity information online.

Damage and reporting methods in Vietnam

According to aggregated figures for the 2020 to 2025 period in the original article, Vietnam recorded more than 24.000 online scam cases with total losses of about 40.000 billion VND. Cases directly related to eSIM or QR codes account for only a small share, but they have been growing rapidly since 2024.

If users encounter a scam, they should report it through tingia.gov.vn or contact the police hotline 113. Compensation responsibility will depend on the specific cause: the carrier may be liable if there was a verification process error, the bank may be liable if there was a transaction security error, while users may have to bear the loss themselves if they scanned a fake QR code or provided information without checking the source.

See also: The future of 2030 eSIM: 6 trends shaping the global telecom industry

Frequently asked questions about hacked eSIMs

Can an eSIM be hacked remotely?

Theoretically, yes, through attack vectors such as SS7 or malware on the device. However, in practice, this is very rare. To date, no remote eUICC chip hack has been publicly disclosed since 2017. Most cases described as “eSIM hacking” are actually SIM swap fraud or phishing QR codes.

How do hackers hack an eSIM?

Hackers can target an eSIM through 7 main scenarios: SIM swap via eSIM transfer, phishing QR codes, malware that steals QR codes, SS7 attacks, supply chain attacks, side-channel attacks on the eUICC chip, and Bluetooth proximity attacks. Of these, the first three scenarios are the most realistic risks for everyday users.

What signs show that an eSIM has been hacked?

Common signs include sudden loss of signal, inability to make calls or receive SMS, OTPs being sent to another device, banking apps reporting unusual transactions, an unfamiliar profile appearing in the SIM settings, and unexpectedly high bills. If you notice two or more of these signs at the same time, you should act immediately according to the emergency procedure.

What should you do if you suspect your eSIM has been hacked?

Users should take 5 steps in order: disconnect mobile data and Wi‑Fi, change the passwords of important accounts, call the carrier hotline to temporarily suspend the line, contact the bank to freeze cards or accounts, and then report it to the police or the relevant authorities. Acting within the first 30 minutes is very important because money can be transferred away very quickly.

Can an eSIM be cloned like a physical SIM?

No. An eSIM cannot be physically cloned in the same way as a traditional SIM, because the eUICC chip is soldered onto the motherboard and the security keys are stored in the Secure Element, which cannot be exported in the normal way. Fraudsters can only trick the carrier into transferring the profile to another device through SIM swap; they cannot directly copy the eUICC chip.

Has there been any famous eSIM hack?

No famous eUICC eSIM chip hack has been publicly disclosed from 2017 to the present. Vulnerabilities such as Simjacker and WIBattack in 2019 mainly affected older physical SIMs with S@T or WIB Browser and do not directly affect modern eSIMs under the SGP.22 standard.

Can a strong password prevent eSIM hacking?

A strong password combined with two-factor authentication using an authenticator app can significantly reduce the risk from real-world attack scenarios such as SIM swap fraud, SS7 attacks, and social engineering. In particular, when SMS OTP is not used as the primary authentication method, users can reduce the risk of having their code intercepted through their phone number.

If you are looking for a high-security eSIM solution for travel or business trips to South Korea, Australia, or Europe, you can refer to the following plans eSIM South Korea or eSIM Australia from SIMPM. All profiles are downloaded via an SM-DP+ server that complies with the SGP.22 standard, achieves Common Criteria EAL4+, supports activation in about one minute using an official QR code, and provides a Vietnamese-language hotline at 24/7 to help handle security issues when needed.