The SIM Card Hack You’re Not Supposed to Know About: How Your Phone Can Be Spied On Silently
Most of us treat our SIM card as nothing more than a tiny plastic chip that gives our phone a number and connects us to the mobile network. In truth, it’s a sophisticated mini-computer running its own operating system, complete with a CPU, memory, and the ability to execute commands that interact directly with your phone’s hardware.
This hidden capability makes SIM cards far more powerful—and vulnerable—than most people realize. One of the most stealthy and concerning exploits is Simjacker, a vulnerability that allows attackers to track and spy on users without any interaction from them.
Understanding Simjacker: The Invisible Threat
Simjacker was publicly disclosed in 2019 by AdaptiveMobile Security. It takes advantage of an old feature built into many SIM cards called the S@T Browser (SIM Alliance Toolkit Browser), part of the SIM Application Toolkit (STK) system.
Originally designed to let mobile carriers deliver simple services like checking your balance or accessing basic menus, the S@T Browser has a dangerous flaw. It can process specially crafted binary SMS messages sent silently over the network.
Here’s how the zero-click attack typically unfolds:
- The attacker sends an invisible binary SMS to your phone. You won’t see any notification, alert, or message.
- The SIM card’s S@T Browser automatically interprets and executes the embedded commands.
- These commands instruct the phone’s modem (the radio hardware) to gather sensitive information, such as your approximate location via cell towers, IMEI number, and other device details.
- The SIM card then quietly sends this stolen data back to the attacker through another silent message.
The entire process happens outside the main operating system of your iPhone or Android device, making it invisible to both the user and standard security software.
Real-World Scale and Exploitation
Security researchers estimated that over a billion SIM cards worldwide could be vulnerable, particularly in regions relying on older mobile infrastructure. The issue affected networks in dozens of countries across the Americas, Africa, Europe, the Middle East, and beyond.
While not every vulnerable SIM has been targeted, reports indicate that sophisticated actors—including private surveillance firms working with governments—exploited Simjacker for at least two years before its discovery.
Beyond simple location tracking, related techniques can enable fraud, force the phone to make calls, send messages, open browsers, or cause denial-of-service disruptions. Importantly, this is different from traditional SIM swapping, where an attacker tries to hijack your phone number. Simjacker allows direct spying through the SIM itself without transferring ownership.
Why Modern Phone Security Falls Short
Today’s smartphones have strong app sandboxing and permission systems, but the SIM card operates with deep, low-level trust. Commands from the SIM go straight to the baseband processor, bypassing the phone’s main OS entirely. This design dates back decades, when it was assumed the SIM would always be friendly.
Even eSIMs (embedded SIMs) are not automatically safe, as they can inherit the same vulnerable software components. Patching this issue depends almost entirely on mobile operators updating or replacing affected SIM cards—not on phone manufacturers or individual users.
Practical Steps to Protect Yourself
Unfortunately, there is no simple user-level fix for Simjacker, as the vulnerability lives in the SIM and network layer. However, you can reduce your overall risk:
- Switch to app-based two-factor authentication (such as Google Authenticator, Authy, or Microsoft Authenticator) instead of relying on SMS codes for important accounts.
- Avoid sharing your phone number publicly whenever possible.
- Monitor your phone for strange behavior, such as unexpected data usage spikes, sudden signal loss, or account issues.
- Contact your mobile carrier and ask about their SIM security measures, whether they support SIM PIN protection, or if they have deployed updates to mitigate STK vulnerabilities.
- For high-risk individuals (journalists, activists, or business leaders), consider using a dedicated secondary device or number for sensitive communications.
If you suspect your SIM may be compromised, immediately contact your carrier to suspend service, review linked accounts, and change passwords.
The Broader Lesson for Mobile Security
Simjacker is a reminder that your smartphone is actually a collection of semi-independent computers—the main processor, the baseband modem, Wi-Fi/Bluetooth chips, and the SIM—each with its own security assumptions. While everyday hackers may struggle to launch such attacks (often requiring access to SS7 signaling networks), well-funded state actors and advanced surveillance firms have the resources to do so.
Mobile operators can help by filtering malicious binary messages, disabling risky applets, or proactively replacing vulnerable SIMs. Progress has been made since 2019, but many older cards remain in use.
In an era where our phones hold so much personal and financial data, staying informed and minimizing reliance on SMS is one of the smartest defenses. The humble SIM card in your pocket is far more capable—and potentially risky—than it appears. Protect your number, diversify your authentication methods, and keep pressuring carriers for stronger safeguards.