
Is an eSIM Safe to Use? The Security Facts, Explained
Yes — an eSIM is not less secure than a physical SIM, and in several ways it is more secure. eSIM profiles are locked to a single certified chip (the eUICC) using GSMA's SGP.22 remote-provisioning standard, so a profile cannot be copied onto another device the way a removable SIM card is sometimes swapped or cloned by a bad actor with physical access.
#How Does eSIM Security Actually Work?
An eSIM (embedded SIM) is a small chip soldered into the device rather than a removable card. It stores one or more carrier "profiles," but only one is active at a time. GSMA, the mobile industry's global standards body, publishes the security analysis behind its Remote SIM Provisioning specification, which governs SGP.22: every profile download runs over mutually authenticated TLS between the phone's eUICC chip and the carrier's SM-DP+ server, using device-specific certificates neither side can forge.
The chip itself carries its own certification. GSMA's eUICC Security Assurance (eSA) scheme evaluates eUICC hardware and software against Common Criteria security profiles through independent, licensed labs — the same evaluation approach used for payment card and passport chips, before a chip can even ship in a phone.
A data-only eSIM like co:sim's Japan eSIM is provisioned through this same SGP.22-compliant pipeline: the QR code you scan after checkout triggers a certificate-authenticated handshake between your phone's eUICC and the supplier's SM-DP+ server, not a plain file transfer. Every co:sim plan page also lists the underlying network and the install deadline, so you know exactly what you are connecting to before you buy.
#Is SIM-Swap Fraud Easier or Harder With an eSIM?
Neither format changes the actual weak point. The FTC's guidance on SIM-swap scams explains that a swap happens when a scammer convinces your carrier to move your number onto a device they control — a social-engineering attack on the carrier's identity check, not a technical flaw in the SIM hardware itself. An eSIM cannot be physically pulled out and reinserted elsewhere, which removes theft-from-a-dropped-phone as a vector, but it does not stop someone from talking their way past a carrier's support line.
Data-only plans sidestep this particular fraud entirely: co:sim eSIMs carry no phone number, so number-porting SIM-swap fraud, which targets the voice line tied to your account logins, has nothing on a co:sim eSIM to target. If you use text-message codes for two-factor authentication on your primary number, protecting that number (an authenticator app instead of SMS, a carrier PIN) matters far more than which SIM format you use.
#What Happens to Your Data if You Lose Your Phone?
Losing the device is a bigger risk than losing the SIM. Apple's guidance for a stolen iPhone or iPad recommends marking the device as lost immediately through Find My, which locks it with Activation Lock and requires your account password to reactivate — and warns against removing it from Find My, since that strips the lock and makes the phone resellable. Android's equivalent is Find My Device with the same lock-and-locate logic.
Neither remote-erase feature disables a SIM at the network level, physical or embedded, so contacting your carrier to suspend service stays a required step either way. For an eSIM specifically, that carrier-side suspension is the only way to disable it, since there is no physical card to remove. Log into your co:sim account dashboard any time to see your active eSIM's status; the plan itself never carries a phone number or payment details that a thief could use directly.

#FAQ
#Can someone clone or copy my eSIM profile onto another phone?
Not in practice. An eSIM profile is downloaded once, over a mutually authenticated TLS session, and bound to your device's specific eUICC chip identifier under GSMA's SGP.22 standard: there is no file a thief can lift and load onto a second device the way old-style SIM cloning attacks worked against some early, poorly secured SIM cards decades ago. The GSMA's own security review confirms the protocol's security goals hold against network attackers, meaning an outside party intercepting the download traffic cannot extract a usable copy of your profile. The realistic risk sits one layer up, with a compromised carrier account or provisioning server rather than the eSIM itself — the same class of risk that also applies to a physical SIM. That is why co:sim's provisioning runs through this certified pipeline rather than emailing a plain configuration file, and why the plan page states exactly which network and supplier is behind each eSIM before you buy.
#Is eSIM safer than a physical SIM card for SIM-swap fraud?
It removes one specific risk: a thief cannot pop out an eSIM and reuse it in another device, since physically there is nothing to remove. But the FTC's own guidance on SIM-swap scams makes clear the main attack targets your carrier's identity-verification process, not the SIM hardware itself, so both physical and embedded formats remain equally exposed to that particular fraud path. A scammer who talks a carrier's support agent into moving your number can do so whether you carry a plastic card or an eUICC chip. Data-only eSIMs like co:sim's sidestep the issue differently: they carry no phone number at all, so the number-porting fraud that SIM-swap attacks depend on has nothing on a co:sim eSIM to hijack in the first place, even though the underlying carrier-authentication risk still applies to your primary phone line.
#What eSIM security standard do providers have to follow?
GSMA's SGP.22 defines the Remote SIM Provisioning architecture that every consumer eSIM provider uses to download, store, and switch between carrier profiles, requiring mutually authenticated, encrypted sessions between the device's eUICC and the provisioning server so neither side can be impersonated. The physical chip storing those profiles is certified separately, under GSMA's eUICC Security Assurance (eSA) scheme, which applies Common Criteria-based evaluation through independent, GSMA-licensed laboratories before any eUICC ships inside a phone. Together, the two layers cover both ends of the process: SGP.22 secures how a profile travels from supplier to device, and eSA certifies the hardware that stores it once it arrives. Any eSIM provider co:sim works with, and every phone manufacturer supporting eSIM, builds on this same two-layer standard rather than a proprietary alternative.
#Should I remove my eSIM before selling my phone?
Yes. Fully erase the device in Settings first, which clears eSIM profiles along with every other setting and account, then separately contact your carrier to cancel or transfer the underlying plan, since a factory reset alone does not always cancel service at the network level — the profile can remain provisioned even after the phone itself is wiped. Apple's stolen-device guidance, built for lost or stolen phones, applies just as well to a voluntary resale: confirm any lost-mode flags are cleared, sign out of your Apple ID or Google account, and check that the device shows as fully erased before handing it over. That sequence keeps the next owner from seeing your carrier profile, provisioning history, or any co:sim account details tied to the old device, and keeps your number or data plan from following the phone to its new owner.
#Does losing my phone cancel my eSIM data plan automatically?
No — losing the device does not cancel the underlying plan by itself. The eSIM profile stays provisioned on the (now missing) eUICC chip until you or your carrier actively cancel it, which is exactly why contacting your provider to suspend service is a required step after a loss or theft, the same as it would be with a physical SIM. There is no remote "kill switch" built into the eSIM standard itself that a lost-device owner can trigger without carrier involvement. co:sim plans are data-only and prepaid with no ongoing contract or recurring bill to stop, so there is no billing risk from a lost phone the way there can be with a postpaid voice line. You can still check a plan's status, review its install deadline, or ask for help at any time through the co:sim account dashboard, independent of the device it was originally installed on.
Ready to travel with a data plan built on this same security standard?


