Yes. An eSIM can be SIM swapped, because a SIM swap attack never targets the chip in your phone. It targets your carrier account and the phone number attached to it. If an attacker convinces your carrier to move that number, it does not matter whether the number was living on a plastic SIM or an embedded eSIM profile: the number moves, and every SMS verification code your accounts send now lands on the attacker's device.
The honest version of the answer has three parts: what the attack actually is, what genuinely changes with eSIM (some things get better, one gets worse), and which category of eSIM is exempt because there is no number to steal.
What a SIM swap actually attacks
A phone number is an entry in your carrier's subscriber database, mapped to whatever SIM credentials the carrier says it is mapped to. A SIM swap is an attacker rewriting that mapping. The common routes:
- Social engineering the carrier. The attacker calls support with your name, address, and a few leaked data points, claims a lost phone, and asks to activate the number on a new SIM.
- Port-out fraud. Instead of swapping the SIM at your carrier, the attacker ports your number to a different carrier entirely.
- Insider access. Paid-off retail or support staff process the swap directly. Prosecuted cases in the US have repeatedly involved carrier store employees.
Notice that none of these steps touch your device. That is why moving your number from plastic to eSIM does not, by itself, protect it.
What changes with eSIM
Two things improve, one gets worse.
Better: no physical chip to steal or clone. A stolen phone's plastic SIM can be popped into another device and start receiving your codes immediately (unless you set a SIM PIN). An eSIM profile cannot be removed from a phone by hand, so casual theft no longer hands over your number with the hardware.
Better: no store swap needed for you. Legitimate eSIM transfers happen through authenticated carrier flows on your own device, which is one less in-person process for an impostor to exploit at a retail counter.
Worse: the swap itself gets faster. Once an attacker has access to your carrier account (a phished password, a reused credential), some carriers let them provision a new eSIM profile to their own device in minutes, entirely online. No store visit, no human to convince. The account login becomes the whole attack, which is why carrier account hygiene now matters more than SIM format.
Data-only travel eSIMs are a different case
A travel eSIM like the plans VoidMob sells for 180+ destinations is data only. There is no MSISDN in the sense that matters: no voice line, no SMS inbox, nothing an attacker can port to receive your verification codes. You cannot SIM swap a line that has no number worth stealing.
The flip side is that a data-only eSIM cannot receive 2FA codes either, so it does not replace the number your accounts verify against. Your main carrier number keeps that job, and keeps the risk. What a data eSIM does change is how much identity is attached to your connectivity, which is a separate question covered in how anonymous is your eSIM.
How to protect the number that can be swapped
- Turn on your carrier's number lock. US carriers offer a free port/SIM-change freeze (Verizon Number Lock, AT&T Wireless Account Lock, T-Mobile SIM Protection). FCC rules adopted in 2023 also require carriers to verify identity before processing a swap and to notify you when one is requested (FCC SIM swap order), though the rollout ran late, so treat the lock as the real control.
- Get SMS 2FA off accounts that matter. NIST has classified SMS as a restricted authenticator since 2017 precisely because the number can be transferred. Use passkeys or an authenticator app on email, banking, and crypto.
- Separate your verification number from your public number. Codes you cannot move off SMS can go to a number nobody associates with you. A dedicated non-VoIP carrier number works across most platforms and is not the number printed on your business card, so it is not the number an attacker researches.
- Harden the carrier account itself. Unique password, a support PIN, and no SMS-based recovery on the carrier login, since that would make the number the key to the account that controls the number.
The full playbook, including what to do in the first hour after a swap, is in SIM swap attacks target crypto.
1Is an eSIM safer than a physical SIM against SIM swapping?
Marginally, and only against physical theft: there is no chip to move to another phone. Against the actual fraud, which is social engineering or account takeover at the carrier, both formats are equally exposed because the attack moves the number, not the chip.
2Can someone steal my eSIM remotely?
Not the profile itself, but they do not need to. An attacker with access to your carrier account can request your number be provisioned to a new eSIM on their device. Protecting the carrier login and enabling the carrier's number lock closes that route.
3Does a data-only travel eSIM protect me from SIM swapping?
It cannot be swapped, since there is no phone number to port. But it also does not protect your main number, which still receives your verification codes and still needs a port freeze and non-SMS 2FA.
4How do I know if I have been SIM swapped?
Your phone suddenly shows no service in an area with coverage, calls and texts stop arriving, and password-reset emails you did not request start appearing. Contact your carrier from another line immediately and lock your email account first.
Keep verification codes off your public number
Non-VoIP carrier numbers for one-time codes, multi-day rentals, or a dedicated monthly line.