Key Takeaways

  • Malicious SIMs can support surveillance, device disruption and command execution, not only phone-number theft.
  • SIM swapping can turn control of a mobile number into access to corporate and personal accounts.
  • Enterprises can reduce exposure by replacing SMS authentication for sensitive accounts and tightening recovery controls.

The SIM card is easy to overlook. It sits inside a phone, router, vehicle or connected device and quietly handles access to a cellular network. Yet new research indicates that a hostile or compromised SIM can do considerably more than redirect a phone number. It can become a foothold inside the device itself.

University of Birmingham researchers reported in August 2026 that malicious SIMs could exfiltrate device identifiers, initiate calls or messages, force a connection from 4G down to 2G and shut down a device. Under some conditions, they could also enable arbitrary command execution on the communication processor, the component responsible for managing cellular communications.

That expands the risk well beyond conventional SIM swapping. The researchers identified four routes through which attackers could obtain malicious or compromised SIM and eSIM capabilities: remote software exploitation, physical replacement or implants, compromise of operator remote-management systems and supply-chain tampering.

The distinction matters. SIM swapping, also called SIM hijacking, typically involves persuading or tricking a carrier into transferring a victim's number to an attacker-controlled SIM or eSIM. A malicious SIM attack may instead target the hardware and software relationship between the SIM and the host device. One is primarily an identity attack. The other can become a device-compromise problem, although the two risks can overlap.

Why would criminals care about a phone number in the first place? Because businesses and consumers have spent years turning numbers into identity credentials. They are used for password resets, transaction approvals, customer-support verification and one-time passcodes. Once an attacker controls the number, incoming calls and text messages may arrive on the attacker's device rather than the victim's phone.

The Government of Canada Cyber Centre warns that SIM swapping can let an attacker intercept calls, text messages and authentication codes. That access can support email compromise, social-media takeover, identity theft and financial fraud. For an enterprise, the same method could expose cloud applications or corporate accounts if employees rely on personal phone numbers for authentication and recovery.

Multifactor authentication still adds an important layer of protection, but the choice of factor is critical. SMS-based authentication depends on continued control of a mobile number, so a fraudulent transfer can undermine the supposedly separate second factor. Authenticator applications, passkeys and hardware security keys tend to offer stronger protection for privileged, financial and administrative accounts.

The underlying attack surface is also growing. Physical SIMs now share the market with eSIMs and remotely provisioned profiles, while cellular modules appear in industrial equipment, payment terminals, EV chargers and other connected systems. USENIX Security 2024 research examined how attack capabilities can emerge through physical access, remote SIM administration, supply-chain compromise and vulnerabilities in SIM software. In operational technology or unattended devices, even a temporary service loss could create a business problem.

Defence therefore spans several teams. Telecom operators can strengthen subscriber verification, issue rapid SIM-change notifications and support account PINs or port-out locks. Enterprises can inventory where SMS is used, prioritize phishing-resistant authentication for high-risk accounts and prevent help desks from treating access to a phone number as conclusive proof of identity.

Unexpected cellular-service loss deserves attention too. It may be a routine outage, but it can also indicate that a number has been transferred. Employees should know how to contact their carrier and corporate security team through an alternate channel. Security operations teams, meanwhile, can review account resets, new-device enrollments and authentication changes that occur shortly after a reported loss of service.

SIM security is no longer just a carrier issue, requiring coordination across telecom infrastructure, identity management, endpoint security and supply-chain assurance. As organizations connect more accounts and devices to cellular identities, treating the mobile number as a recoverable identifier rather than a trusted credential can help contain the damage when a SIM, eSIM profile or carrier account is compromised.