Anyone buying their first eSIM asks a version of the same question: is this actually safe, or am I handing my phone over to something I don't understand? It's a fair thing to ask about a technology that arrives as an email with a code in it. The short answer is yes, and in one specific way an eSIM is harder to steal than the plastic SIM it replaces. But that answer is only useful with the reasoning attached, so this guide covers where the profile is actually stored, how it gets onto your phone, what an eSIM does and does not protect you from, and the part most articles skip: the risk that matters is the company you bought from, not the standard itself.
The short answer, and what safe actually means here
An eSIM is not a different kind of mobile connection. It's the same kind of SIM credential that has always identified you to a network, stored in a chip that's built into the phone instead of a card you slide into a tray. The security model underneath is the one the mobile industry has used for decades.
Against the most realistic threat to a traveller, which is someone getting hold of your phone, an eSIM is genuinely better. A plastic SIM can be removed in seconds by anyone holding your handset. An eSIM cannot be removed at all.
Where people get confused is in expecting an eSIM to protect them from things no SIM protects anyone from. It doesn't encrypt your browsing, it isn't a VPN, and it doesn't stop the fraud most people are actually worried about, which happens at your carrier's customer service desk rather than on your device.
So it's worth separating three different questions that usually get asked as one: is the technology sound, does it change your exposure compared with a physical SIM, and is the particular company selling it to you trustworthy. The first two have clear answers. The third is the one to spend your attention on.
Where an eSIM profile actually lives
The profile sits in a component called an eUICC, an embedded version of the same secure element that has always been inside a SIM card. It's a small tamper-resistant chip soldered onto the phone's board, designed so that the keys it holds stay inside it.
That design goal matters more than it sounds. The authentication keys that prove to a network that you are you are generated and stored inside the secure element, and normal operation never exposes them to the operating system, to apps, or to anything you could reach over a cable. Requests go in, cryptographic answers come out, the secret itself stays put.
This is the same principle as the chip in a bank card, and it's why cloning a modern SIM is not a practical consumer attack. It isn't a matter of copying a file. Extracting keys from a hardened secure element is laboratory work against a chip you'd need to physically possess, and it is not something that happens to travellers.
One phone can hold several stored profiles at once, which is how you can keep your home line and a travel plan side by side. They're kept separate inside the chip, and a travel data profile has no ability to read or interfere with your carrier line.
How the profile gets onto your phone
The delivery mechanism is a published GSMA specification called Remote SIM Provisioning, and understanding it removes most of the unease people feel about the process.
The install link or QR code you receive is not the profile. It's an address and a one-time activation code, and nothing else. The format is literally the letters LPA, then the address of the provisioning server, then your activation code. Anyone reading that code learns where to ask and what to ask for, and nothing about your identity.
When you tap install, software on your phone called the Local Profile Assistant contacts that server, and the two sides authenticate each other using certificates before anything is transferred. The profile is then delivered over an encrypted channel directly into the secure element. Your phone verifies it's talking to a genuine provisioning server, and the server verifies it's talking to a genuine eUICC.
This is also why an activation code stops working after it's used. The code entitles one profile to be downloaded once. Redeem it and it's spent, which is the mechanism behind an eSIM only installing on a single device.
eSIM versus physical SIM: which is more secure?
On the attack that actually happens to travellers, the eSIM wins clearly. If someone steals a phone with a plastic SIM in it, they can eject the tray, drop your SIM into a cheap handset, and immediately start receiving calls and texts sent to your number, including verification codes. It takes no skill and about thirty seconds.
With an eSIM there is nothing to eject. The profile is locked inside a chip that's soldered to the board, and getting at it means getting past your lock screen first. That's a meaningful upgrade for anyone who has ever had a phone taken in a crowded place.
The same property cuts the other way, and it's only fair to say so. Because the profile can't be moved by hand, you can't move it either. A travel eSIM that has been activated can't be transferred to a different phone, so if your handset dies mid-trip, the plan doesn't simply pop out and go into a replacement.
Everything else is close enough to be a draw. Both use the same authentication, both sit on the same networks, and neither one encrypts what you send. If you're comparing purely on security, the removability difference is the one real distinction.
SIM swap fraud, and why a travel eSIM isn't a target
This is the fraud people are usually thinking of when they ask whether eSIMs are safe, and it's worth being precise, because it isn't an attack on the SIM at all.
In a SIM swap, the attacker never touches your hardware. They contact your mobile carrier pretending to be you, pass whatever identity checks that carrier uses, and ask for your number to be moved to a SIM they control. The carrier does the swapping. Your phone simply loses service, and your number, and any text message sent to it, now arrive on their device.
eSIM technology neither causes this nor prevents it. It's a weakness in how carriers verify the person on the phone. The defences are the same as they have always been: set an account PIN or passcode with your carrier if they offer one, and move important two-factor codes off SMS onto an authenticator app, so that losing your number doesn't mean losing your accounts.
A travel eSIM sits outside this entirely, and this is the reassuring part. It's a data-only plan with no phone number attached to it. There is no number on it to steal, it can't receive your verification codes, and nobody can social-engineer a carrier into transferring something that was never issued. It carries internet traffic and nothing else.
Can your provider see what you do online?
This deserves a straight answer rather than a marketing one. Any mobile network can see connection metadata: that your device attached to the network, which cell it attached through, how much data moved, and which servers you connected to. That's inherent to how mobile networks route traffic, and it's equally true of your home carrier, a local SIM bought at the airport, or roaming.
What a network does not see is the content of encrypted traffic. Nearly all web and app traffic now travels over HTTPS, which is encrypted between your device and the service you're using. The network can see that you connected to a particular service; it can't read your messages, your passwords or the pages themselves.
A travel eSIM is not a privacy product and shouldn't be sold as one. It doesn't hide anything from the network beyond what encryption already hides, and it isn't a VPN. If your goal is to conceal which services you use from the network you're on, a VPN is the tool for that, and it works over an eSIM connection perfectly well.
There is one place where mobile data is the more private option, and it's a practical one while travelling. An open public WiFi network in a hotel or a cafe puts you on a shared network with strangers and is trivially easy to impersonate with a lookalike hotspot name. A mobile connection is a direct link to a licensed carrier, with no shared local network and nobody able to fake it. For a lot of trips, that's the strongest security argument for carrying data at all.
Beyond the network, the question is what the seller keeps about you as a customer, and that's a matter of their privacy policy rather than the technology. It's worth a minute to read one before buying.
The real risk is the seller, not the technology
The standard is public and implemented the same way by everyone, which means the variable in this transaction is not the eSIM. It's the company you're handing your card details and your email to, and that's where a careful buyer should be looking.
The most useful signal is who is processing the payment. If checkout runs through Apple Pay, Google Pay, or a known processor such as Stripe, your card details go to that processor and not to the seller, and you keep the chargeback protection your card gives you. A site that asks you to type card numbers into its own plain form has taken on a responsibility it probably shouldn't have.
After that, look for signs of an actual business behind the website: a registered company rather than an anonymous storefront, a refund policy that says something specific about eSIMs, and a support channel you can reach before you buy rather than only after. It's also a good sign when plan pages name the actual carrier networks a plan will use, because vague coverage claims are the easiest thing in this industry to write and the hardest to check.
The red flags run the other way. Prices far below everyone else in the market usually mean an unauthorised reseller of somebody else's inventory, which is fine right up until the day support is needed. Unlimited offers with no fair-use terms anywhere on the page are describing something that doesn't exist. And no company information at all is the clearest signal of the lot.
For transparency about where we stand on our own checklist: Lumbus is a UK-registered company, payments run through Stripe under Apple Pay, Google Pay and card, we don't store full card details, and our plan pages name the local networks each plan runs on. Those are the same things we'd tell you to check on any competitor's site.
A short security checklist for travelling
Most of what actually protects you abroad has little to do with which kind of SIM you're carrying. It's the ordinary hygiene that becomes more important when you're tired, in an unfamiliar place, and using your phone for everything.
The single highest-value habit is moving two-factor authentication off SMS and onto an authenticator app before you travel. It removes your phone number as a single point of failure, which protects you against SIM swap, against losing your phone, and against being somewhere with no signal when a code is needed.
The rest is short, and worth doing before you fly rather than after you land.
- Use a strong lock screen code, not a four-digit one, and turn on biometrics
- Move two-factor codes from SMS to an authenticator app
- Set an account PIN with your home carrier if they offer one
- Prefer mobile data over open public WiFi for anything involving money
- Install a VPN before you travel if you need one, and test it at home
- Buy eSIMs from sellers with a real company behind them and a known payment processor
- Turn on Find My or its Android equivalent, and check it works
- Keep a note of your eSIM order email, so support can identify you if your phone is lost
Frequently asked questions
Are eSIMs safe?
Yes. An eSIM uses the same authentication that physical SIM cards have used for decades, stored in a tamper-resistant secure element built into the phone. Against the realistic threat of a stolen handset it's safer than a plastic SIM, because there's nothing to remove and put in another phone. It doesn't encrypt your browsing, and it isn't a defence against SIM swap fraud, which happens at your carrier rather than on your device.
Can an eSIM be hacked?
Not in any way that affects ordinary travellers. The authentication keys are generated and held inside a hardened secure element and aren't exposed to the operating system or to apps during normal use. Extracting them would mean specialist physical attacks on a chip an attacker would first have to possess. The practical risks around eSIMs are buying from a dishonest seller or losing an unlocked phone, not the cryptography.
Is an eSIM more secure than a physical SIM?
In one important respect, yes. A physical SIM can be ejected from a stolen phone in seconds and used in another handset to receive your calls and texts. An eSIM is soldered in and can't be removed, so a thief has to defeat your lock screen first. In every other respect the two are broadly equivalent, since they use the same underlying authentication and run on the same networks.
Can someone steal my eSIM?
Not physically, which is the main point in its favour. There's no card to take. The realistic ways to lose access are having your phone taken while unlocked, or someone gaining access to the account you bought the plan through, which is why a strong device passcode and a decent account password matter more than anything about the SIM itself.
Can a travel eSIM be used for SIM swap fraud?
No, because there's nothing to swap. A travel eSIM is data-only and has no phone number attached, so it can't receive calls or text messages and can't receive your verification codes. SIM swap fraud targets your home carrier account and your phone number. The defences are an account PIN with your carrier and moving two-factor codes onto an authenticator app.
Can my eSIM provider see my browsing?
Any mobile network sees connection metadata: that you connected, through which cell, how much data you used and which servers you reached. That's true of your home carrier and a local SIM too. It cannot read the contents of encrypted traffic, and nearly all web and app traffic today is encrypted with HTTPS. If you want to hide which services you use from the network itself, that's what a VPN is for.
Is it safe to buy an eSIM online?
It's safe to buy from a seller you've checked, and buying online is the only way eSIMs are sold. Look for a registered company rather than an anonymous storefront, checkout through Apple Pay, Google Pay or a known processor such as Stripe so your card details never reach the seller, a refund policy that specifically addresses eSIMs, and support you can contact before purchasing. Be wary of prices far below the rest of the market.
Is it safe to scan an eSIM QR code?
Yes, when it came from the provider you bought from. An eSIM QR code isn't a program and can't install anything by itself. It contains a short text string: the letters LPA, the address of the provisioning server, and a one-time activation code. Your phone uses it to request a profile. Treat it like a password rather than a public link, since anyone who redeems it first gets the plan.
Do I still need a VPN if I use an eSIM?
They solve different problems. An eSIM gives you a mobile connection instead of relying on public WiFi, which already removes the most common risk while travelling. A VPN hides which services you're connecting to from the network carrying your traffic and helps with region-restricted services. If you'd use a VPN at home, use one abroad; it works normally over an eSIM connection.
What happens to my eSIM if my phone is stolen?
The thief can't remove it and use it elsewhere, and if your phone is locked they can't reach it at all. Report your home line to your carrier so your number can be suspended. For a travel plan, contact the provider with the email you ordered with; what can be done depends on how much of the plan is left and whether it was activated, so keeping that order email accessible is genuinely useful.
Can an eSIM track my location?
Not in the way the question usually implies. Any mobile network knows roughly where a connected device is, because it knows which cell tower is serving it. That's how mobile networks function and applies identically to physical SIMs, local SIMs and roaming. An eSIM has no additional tracking ability, and it isn't GPS. Apps with location permission know far more about your location than the network does.
Is public WiFi or an eSIM safer abroad?
A mobile connection through an eSIM is safer. Open public WiFi puts you on a shared network with strangers, and it's very easy to set up a lookalike hotspot named after a hotel or cafe to capture traffic from whoever joins it. A mobile connection is a direct link to a licensed carrier that can't be impersonated that way. If you must use public WiFi, use a VPN with it.