Warning: Malicious SIM Cards Can Take Over Your Phone and Smart Devices
SIM cards installed in mobile phones harbour a serious security vulnerability that has long been overlooked. Research from the University of Birmingham, presented at the USENIX WOOT 2026 conference in Baltimore, warns that modified or hacked SIM cards can be used to take over smartphones, electric vehicle (EV) chargers, and various Internet of Things (IoT) devices. The researchers found that a standard feature called Proactive SIM allows the SIM card to send special commands directly to the device’s modem. One of its features can execute AT commands (Attention commands), a type of modem control command that has been in use since the 1980s. This feature enables a malicious SIM card to exploit the system without the user’s awareness. In tests on 26 devices, comprising 18 smartphones and eight cellular IoT modules, hackers exploited this vulnerability to force phones to downgrade their connection from secure 4G networks to vulnerable 2G networks, download sensitive data, send messages, make calls, and even disable cellular communications. On recent Android devices, a malicious SIM card was able to force the phone to open a malicious website without any user interaction, even while the screen was locked. Marius Muench, Assistant Professor of Computer Science at the University of Birmingham, explained that this threat stems from the technical standards of mobile communications themselves. ‘Other researchers, cybersecurity experts, and leaked intelligence documents have demonstrated some of the dangers of malicious SIMs before us. However, the resulting risks have not been fully mitigated. This is potentially because malicious SIMs are not included in most threat models; although we are slowly seeing a promising shift here,’ said Muench. The risk arises through four scenarios: remote hacking of SIM software, physical replacement of the SIM card, misuse of remote management features by a compromised operator, and supply chain manipulation during the manufacture or distribution of SIMs or eSIMs. The threat endangers not only personal mobile phone users but also industrial infrastructure and connected vehicle systems that rely on cellular IoT modules. The researchers assess that many Proactive SIM features are legacy technology designed with the assumption that all SIM cards are secure, whereas the cyber threat landscape has evolved rapidly. University of Birmingham researcher Tomasz Piotr Lisowski stressed that the potential vulnerabilities from problematic SIM cards remain vast. ‘The attacks we found only scratch the surface of what is possible with malicious SIM cards,’ said Lisowski.