Home Electronics Your SIM Card Could Become a Hidden Door into Your Phone, Car...

Your SIM Card Could Become a Hidden Door into Your Phone, Car or EV Charger

Credit: Unsplash.

SIM cards are normally trusted parts of our phones and other connected devices.

But new research shows that if a SIM card is malicious or compromised, it could become a surprisingly powerful tool for attacking the device that contains it.

Researchers from the University of Birmingham, working with cybersecurity company Fuzzware, investigated how hostile SIM cards could affect smartphones and Internet of Things (IoT) devices.

They presented their findings at the 2026 USENIX WOOT Conference on Offensive Technologies in Baltimore.

The problem involves a technology called Proactive SIM. It allows a SIM card to send certain commands directly to the modem inside a device. Among these are requests to run AT commands, an old system of instructions originally developed to control modems decades ago.

The researchers created a security testing toolkit called CATana to investigate what could happen if these commands came from a hostile SIM.

They tested 26 devices, including 18 smartphones and eight cellular IoT modules. Such modules can be found inside electric vehicle chargers, connected cars, industrial equipment and other devices that communicate through mobile networks.

Several of the tested devices accepted AT commands originating from the SIM. The researchers found that this capability could open the door to serious attacks.

Depending on the device, a malicious SIM could potentially obtain identifying information, send messages or make calls, reactivate debugging features that were supposed to be disabled, shut down cellular communications or even turn off the device. In more serious cases, researchers found ways to execute commands on a device’s communications processor.

A hostile SIM could also force some devices to move from relatively secure 4G networks to older 2G technology, which has weaker security protections.

The researchers say this threat is particularly important for IoT equipment. Devices such as routers, vehicle systems and industrial machines are often deliberately designed with very few ways for outsiders to interact with them. A SIM interface could therefore provide an unexpected route into an otherwise tightly locked-down system.

The risks go beyond controlling communications. During the research, the team discovered that on recent Android devices, a malicious SIM could make a phone open a website controlled by an attacker without the owner touching anything—even while the phone was locked.

There are several ways a SIM could become hostile. Attackers might remotely exploit weaknesses in SIM software, physically replace a SIM, compromise a mobile operator’s remote management systems or tamper with SIMs somewhere in the supply chain.

Part of the problem is historical. Many Proactive SIM features were designed at a time when engineers largely assumed that SIM cards themselves could be trusted. Some of those older features may now create unnecessary risks in modern connected devices.

The researchers reported their findings to the GSMA and affected manufacturers. According to the team, major manufacturers have already released software updates and strengthened device configurations.

The researchers say the work could ultimately improve security across billions of SIM-enabled products, from smartphones and cars to payment terminals, routers, industrial systems and EV chargers. But they also warn that the vulnerabilities discovered so far may represent only a small part of the potential threat posed by hostile SIM cards.