Short answer: an eSIM is at least as secure as a physical SIM, and in one important way it is safer. But “safe” gets used to mean several different things, so it is worth separating them.
Is the technology itself secure?
Yes, and this is not a marketing claim. An eSIM stores its profile in a dedicated secure element — a tamper-resistant chip designed to resist physical extraction. The whole system is defined by the GSMA, the same industry body behind the SIM standard your phone has used for decades, and profiles are delivered over an encrypted channel and cryptographically signed.
In practice the security model is the same as a physical SIM, implemented in hardware that is harder to get at.
The way an eSIM is genuinely safer
A physical SIM can be stolen. Pop the tray, take the card, put it in another phone, and start receiving the SMS codes that protect the owner’s bank account. It takes seconds and no technical skill.
You cannot do that to an eSIM. There is nothing to remove. An attacker with your phone in their hand cannot transplant your identity into their own device.
The risk that actually matters
SIM swapping is the real threat, and it has nothing to do with which kind of SIM you have.
A SIM swap is a social engineering attack: someone calls your carrier, impersonates you convincingly enough, and has your number moved to a device they control. Your phone goes dead and they start receiving your verification codes. eSIM technology neither causes this nor prevents it — it is a failure of the carrier’s identity checks.
What actually protects you:
- Put a PIN or passcode on your carrier account. Most carriers offer this and most people never enable it. It is the single highest-value thing on this list.
- Stop using SMS for two-factor authentication where you have the choice. An authenticator app or a hardware key cannot be redirected by a phone call to a call centre.
- Treat a sudden loss of signal as suspicious. If your phone drops to “no service” for no reason and stays there, especially alongside unexpected password reset emails, call your carrier from another phone immediately.
What can a travel eSIM provider see?
This is the fair question to ask of any company you buy data from, us included.
Your provider routes your traffic, so it can see the same things any internet provider sees: how much data you use, roughly when, and which network you are attached to. It cannot read the contents of encrypted connections, which today is essentially all of them — every site on HTTPS, every message on WhatsApp or Signal.
What it does hold is the account information you gave it: your email, your payment record, your purchase history. Ordinary customer data, and it should be covered by an actual privacy policy you can read. Ours is here.
If you want to reduce what any network operator can infer from your traffic, use a reputable VPN. That is true whether you are on an eSIM, a hotel Wi-Fi network, or your home broadband.
Buying safely
The weak link is rarely the technology. It is who you buy from.
- Buy from a provider with a real company behind it, a working support address and a published refund policy.
- Be sceptical of resold QR codes on marketplaces and auction sites. A profile can usually be installed once. If someone has already scanned it, you have bought nothing.
- Never install a profile someone sends you unsolicited. A QR code you did not ask for is the eSIM version of an attachment from a stranger.
- Check the plan’s terms before paying, particularly what happens when the data runs out and whether it can be topped up.
The summary
The chip is secure. The bigger risks are the ordinary ones: a carrier account without a PIN, SMS used as a second factor, and buying from someone who will not answer an email when something goes wrong.
Fix those three and an eSIM is one of the least worrying things about international travel.