DFIR Tech Blog – an AI playground

Deutsch English
Foto von Franck auf Unsplash.com

eSIM Hijacking: Forensics Against the Invisible SIM Swap

20.07.2026 sim-swapesimmobile-forensicsaccount-takeover

From the Storefront to the Cloud API

For years, SIM swapping followed a predictable script: a fraudster shows up with a forged ID at a phone store, or talks a call center agent into porting a victim’s number to a new physical SIM. That script is disappearing. As carriers migrate to eSIM, the entire attack moves into remote provisioning — a QR code or a self-service portal is enough to move a number to an attacker’s device in minutes, no store visit required. Physical SIM theft is becoming irrelevant, while remote provisioning has made number transfers faster, quieter, and easier to socially engineer.

How real this threat has become was underlined by a case decided by a California arbitrator: in March 2025, T-Mobile was ordered to pay $33 million after a SIM swap attack enabled thieves to steal roughly $38 million in cryptocurrency, with attackers bypassing T-Mobile’s “NOPORT” security flag by convincing a call center agent to issue a remote eSIM QR code despite the victim having extra security measures on the account. The ruling set an important precedent on carrier liability — and demonstrates that eSIM is not inherently more secure as long as the human on the other end of the line remains the weakest link.

The criminal side is just as current: only weeks ago, Polish authorities, supported by the FBI and Homeland Security Investigations, arrested four members of a gang that used specialized software and social engineering to gain unauthorized access to the infrastructure of companies partnering with telecom operators, as well as to employee email accounts, using the stolen data to execute SIM-swap attacks that cloned and took over victims’ phone numbers to intercept SMS messages and email. The haul: more than $5 million.

When the Attack Starts Inside the Chip Itself

Even more troubling for investigators is a second development: security researchers have demonstrated structural weaknesses in the eUICC chips that manage eSIM profiles. A researcher first needed physical access to a Kigen eUICC to steal the private cryptographic key that authenticates the eSIM to its mobile network, from which he could download arbitrary eSIM profiles in cleartext and extract keys to install malicious applets over-the-air without triggering any security alert. This pushes the attack surface down from social engineering to chip firmware — a scenario in which traditional carrier logs may show nothing suspicious at all.

Forensic Reconstruction: A New Chain of Evidence

For incident responders, this shifts where the evidence lives. The core timeline reads: service loss → SIM/port change → login/reset events → withdrawals, with carrier notices and logs anchoring that timeline and helping prove causation — that control of the number enabled password resets, SMS 2FA interception, or account recovery. In practice, this means:

Bottom Line

For organizations with exposed executives, the takeaway is clear: SMS-based 2FA must be treated as inherently compromisable, MDM systems should alert the moment a managed device reports a new IMSI, and forensic runbooks need to trigger carrier-side evidence preservation on day one — before telecom log retention windows close the door on a defensible chain of evidence.

← Back to overview