Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do eSIMs not eliminate SIM swap fraud…
Threats, Abuse & Incident Response

Why do eSIMs not eliminate SIM swap fraud even when there is no removable card?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Threats, Abuse & Incident Response

eSIMs remove the physical card, but the fraud problem is usually remote, not physical. Attackers still try to take over the phone number through social engineering, carrier account changes, or other identity checks that fail at the point of reassignment. The security question is whether the authentication and verification process can resist remote manipulation, not whether a card can be pulled out.

Why the Missing Card Is Not the Security Boundary

An eSIM changes the form factor, not the trust model. sim swap fraud succeeds when an attacker convinces or coerces a carrier process to move a subscriber number to a different device, so the real control point is the reassignment workflow and its identity checks, not whether the old SIM can be removed.

That is why eSIM adoption can reduce one physical attack path without eliminating the underlying account takeover problem. If the carrier can be manipulated remotely, the number can still be transferred, and once the number is reassigned the attacker may receive calls, texts, and one-time codes intended for the victim.

For a broader case study on how social engineering and credential theft can enable telecom-account abuse, see Caesars Entertainment Breach 2023, Scattered Spider.

Where eSIM Helps, and Where It Does Not

eSIM can remove some practical friction for thieves who relied on stealing a physical card, but most modern SIM swap attempts are not limited by access to the handset. They exploit customer-support workflows, weak account recovery steps, or poor challenge design that accepts information an attacker can obtain, guess, or socially engineer.

  • If the carrier uses weak verification, the attacker only needs enough personal data to pass the reassignment check.
  • If the carrier allows low-friction number porting or device replacement, the fraud path remains open even without card theft.
  • If downstream services still treat SMS as a strong factor, a successful swap can cascade into email, banking, and payment account compromise.

The more durable answer is to harden number-change controls, not to assume that eSIM alone neutralises a number-based fraud path. For teams that need a control-oriented view of access and secret handling, the OWASP Non-Human Identity Top 10 is useful for thinking about credential abuse, while the NIST Cybersecurity Framework 2.0 helps anchor governance, protection, detection, response, and recovery around the exposed identity path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernCarrier swap risk is a governance and trust-control problem for number reassignment.
PR.AA — Identity Management, Authentication, and Access ControlSIM swaps succeed when authentication for number reassignment is weak.
DE.CM — Continuous MonitoringMonitoring can reveal suspicious number changes and account recovery abuse.
Recommendation — Define ownership for number-change risk and enforce carrier verification requirements. Strengthen reassignment verification before allowing a phone number transfer. Monitor for SIM swap indicators and alert on high-risk account changes.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential LifecyclePhone-number takeover often leads to abused one-time codes and recovery secrets.
NHI-04 — Identity Lifecycle and OffboardingThe subscriber record lifecycle is the asset being manipulated in a swap attack.
NHI-08 — Third-Party and Supply-Chain TrustCarrier support and porting dependencies create the external trust boundary attackers abuse.
Recommendation — Reduce SMS reliance and rotate recovery paths after suspected number compromise. Lock down number-change workflows and revoke stale recovery paths quickly. Review third-party number-change trust paths and add stronger verification.

Practitioner Guidance

What to prioritise: Treat phone-number takeover as an authentication weakness, not a hardware problem. The question is whether the carrier and any relying service will still trust the number after an unauthorised reassignment.

What to verify: Test the actual swap process, including support escalation, out-of-band recovery, port-out freezes, and how quickly a number change propagates to high-value services. If SMS remains a recovery method, the residual risk stays material even with eSIM.

Common mistake: Assuming “no removable card” means “no swap risk.” That shortcut misses the fact that the attacker’s target is the subscriber record and its verification flow, not the plastic.

Practitioner takeaway: eSIM reduces one theft vector, but SIM swap resilience depends on the strength of remote identity verification, carrier governance, and the downstream services that still trust the phone number as proof of control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org