• News/
  • https://www.bleepingcomputer.com/news/security/sim-swappers-now-stealing-phone-numbers-from-esims/

SIM swappers now stealing phone numbers from eSIMs

BleepingComputer
·
Bill Toulas
·
Published Mar 14, 2024
·
Updated

SIM swappers have adapted their attacks to steal a target's phone number from an eSIM card, a rewritable SIM chip present on many recent smartphone models. Embedded Subscriber Identity Modules (eSIMs) are digital cards stored on the chip of the mobile device and serve the same role and purpose as a physical SIM card but can be remotely reprogrammed and provisioned, deactivated, swapped, deleted. A user can typicall add an eSIM to a device supporting the functionality by scanning a QR code from the service provider. The technology is becoming increasingly popular among smartphone makers because eSIMs eliminate the need for a SIM card slot and can offer cellular connectivity on small wearables. Russian cybersecurity firm F.A.C.C.T. reports that SIM swappers in the country as well as worldwide have been taking advantage of this shift to eSIMs to hijack phone numbers and then bypass protections to access bank accounts. "Since the fall of 2023, analysts from F.A.C.C.T.'s Fraud Protection have recorded more than a hundred attempts to access the personal accounts of clients in online services at just one financial organization," reads the press release. "To steal access to a mobile number, criminals use the function of replacing or restoring a digital SIM card: transferring the phone from the victim's 'sim card' to their own device with an eSIM." To do that, the attackers hijack the user's account for the service provider's platform or app, which allows them to initiate the procedu...

Read full article

Affected Software

1 affected component
Microsoft Azure
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how SIM swappers have started stealing phone numbers from eSIMs, which are rewritable SIM chips used in modern smartphones.

2

What security implications are discussed in the article?

The article highlights the security risks associated with eSIMs, as attackers adapt their methods to exploit vulnerabilities in digital SIM technology.

3

What products or software are affected by this new SIM swapping technique?

The article specifically mentions that Microsoft Azure may be affected due to the reliance on eSIM technology in some devices.

4

How do SIM swappers target eSIMs compared to traditional SIM cards?

SIM swappers target eSIMs remotely by exploiting vulnerabilities in the digital card system, whereas traditional SIM cards require physical access.

5

What can users do to protect themselves against eSIM swapping attacks?

Users can enhance their security by enabling two-factor authentication and contacting their mobile carrier for additional protective measures against unauthorized swaps.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203