SIM & eSIM PRIVACY
Are SIM Cards Encrypted? Encrypted SIM vs Private eSIM
“Encrypted SIM” and “Secure SIM Card” are some of the most searched phrases in mobile privacy. The short answer: every modern SIM is already encrypted. The more useful question is what that encryption protects, and what it leaves exposed.
How a SIM card works
A SIM, or its digital version the eSIM, is a tiny secure chip. It holds two things that matter here: your subscriber identity (the IMSI, or SUPI on 5G) and a secret key known only to the SIM and your mobile network. The key is stored so it can't be read back out of the chip.
When your phone joins a network, the network sends the SIM a random challenge. The SIM answers it using the secret key, which proves it's genuine without ever sending the key itself. On 3G, 4G and 5G this is mutual: the SIM also checks that the network is real. Both sides then work out fresh session keys for that connection.
So are SIM cards encrypted?
Yes. Those session keys encrypt the radio link between your phone and the mobile mast. The algorithms depend on the generation:
- 2G (GSM): the older A5 ciphers, such as A5/1 and A5/3. A5/1 was broken years ago, which is one reason 2G is being switched off.
- 3G: KASUMI and SNOW 3G.
- 4G (LTE): SNOW 3G, AES and ZUC.
- 5G: the same three families, with 128-bit keys.
5G adds one real privacy improvement: on networks that enable it, your permanent identity is sent encrypted (the SUCI), so fake phone masts, known as IMSI catchers, can't simply read who you are.
An eSIM uses exactly the same security as a plastic SIM. It's downloaded over an encrypted, authenticated connection and then works the same way.
What SIM encryption doesn't protect
- It stops at the network. The encryption covers the air between your phone and the mast. To secure yourself further, use a VPN like Mullvad, which encrypts your traffic all the way from your phone to the VPN server, so your mobile network can't see what you do online.
- It doesn't hide who you are if the SIM is in your name. A SIM registered with your ID links every connection back to you. To prevent this, get a Privacy eSIM from Privacy First, which requires no ID.
- Phone numbers are a weak point. Calls and SMS can be intercepted or redirected, and a number can be stolen with a SIM swap, a common way into bank and email accounts.
- Your IP address can reveal your location. Websites and apps can log it and use it to profile you.
No SIM can encrypt your messages end to end. Beware of any “encrypted SIM” that claims it does: end-to-end encryption comes from the apps you use, such as Threema.
What makes a private eSIM different
A private eSIM (also called a privacy SIM) keeps the same network encryption, but removes what ties the connection to you:
- No identity verification, no contract and no credit check.
- Data-only, with no phone number, so there's nothing to look up, track or SIM-swap.
- A private IP address, so websites can't trace your connection back to where you really are.
That's how our privacy eSIMs work, for the UK, Europe, Australia, the UAE (Dubai) and worldwide.
Building a private setup
A private eSIM is one layer. Together with an Encrypted Phone running GrapheneOS, an end-to-end encrypted messenger and a no-account VPN like Mullvad, you get a setup where the connection, the device and the conversation are all protected, and none of them lead back to your name.