An eSIM cannot be physically removed from a stolen phone: the chip is soldered to the board, so the oldest trick in phone theft, ejecting the SIM in the first minute to kill tracking and hijack the number, simply does not work. That single hardware fact is the foundation of the security case for travelling on eSIM.

Security rarely makes the sales pitch for travel connectivity; price and convenience do. But travellers operate in exactly the conditions where phone security fails: unfamiliar networks, crowded transit, airport Wi-Fi, and a device that has temporarily become wallet, map, boarding pass and bank branch at once. The connectivity choice you make before the trip quietly shapes how exposed all of that is.

This guide lays out the full picture: what the non-removable SIM actually protects against, where eSIM helps with SIM swap fraud and where it honestly does not, why keeping your home number alive abroad strengthens your two factor authentication, the real risk gap between public Wi-Fi and cellular data, and a checklist to set it all up before departure.

In this guide:

Why a SIM you cannot remove matters

Watch what happens to a stolen phone in the first five minutes. A practised thief powers it down or pulls the SIM immediately, for two reasons: a phone without its SIM stops appearing on the network, which frustrates tracking, and the SIM itself is an asset. Slotted into another handset, a plastic SIM can receive your calls and, critically, your SMS verification codes; combined with details skimmed from notifications or documents, that is the raw material of account takeover.

An eSIM removes both moves. There is no card to eject, so the profile stays locked inside a device that is itself locked; and because the phone keeps its identity, Find My on iPhone and Find Hub on Android keep reporting location for longer, improving the odds of recovery and giving you time to erase the device remotely. The thief holds hardware, not your identity.

The traveller’s edge case

This protection matters most precisely when travelling, because street theft concentrates on tourists: crowded metros, café tables, beach bags. A tourist’s phone is also unusually valuable per gram, holding boarding passes, hotel bookings, payment cards and translation, which makes it both more targeted and more damaging to lose. Solo travellers feel this hardest, and our solo travel safety guide covers the wider playbook; the eSIM’s contribution is that losing the phone no longer means losing control of your number.

SIM swap fraud and where eSIM helps

SIM swap fraud is an attack on your carrier, not your card: the fraudster convinces a carrier, through social engineering or a bribed insider, to move your number onto a SIM they control. From that moment your SMS verification codes flow to the attacker, and accounts protected only by SMS two factor authentication start falling. It is one of the more damaging consumer frauds of the past decade, and no SIM format fully prevents it, because the weakness is a human process.

Honest accounting, then. What eSIM does not do: stop a determined attacker from social engineering your home carrier. What it does do: remove the physical branch of the attack entirely (no card to steal, clone or intercept in the post), and add friction, since eSIM provisioning at reputable carriers typically routes through stronger in-app or identity verified flows than a counter clerk handing over a blank SIM.

Travel adds one more advantage. A prepaid travel eSIM is a data plan detached from your identity’s phone number; it carries no number anyone is trying to steal. Your sensitive number, the one your bank knows, stays on your home SIM, used less and exposed less while abroad. Separating the number that matters from the data you burn through daily is a quiet but real reduction in attack surface.

Keep your home number alive for 2FA abroad

The worst security decision travellers used to make was ejecting their home SIM at the airport and replacing it with a local card. From that moment, every bank confirmation, card fraud alert and login code went to a number sitting in a drawer or, worse, in a hotel bin. Locked out of your own bank from a beach in another hemisphere is a genuinely hard problem to fix remotely.

Dual SIM ends that trade-off. Your home SIM stays in the phone with its number reachable for calls and SMS; the travel eSIM handles all data at local prepaid rates. Bank codes arrive, family can ring the number they know, and WhatsApp keeps your identity untouched, as our guide to keeping your WhatsApp number abroad explains in detail. Keep data roaming off on the home line and it costs nothing to simply exist in the phone; receiving SMS is typically free even while roaming.

Two upgrades while you are at it. First, wherever a service offers app based codes or passkeys, switch away from SMS verification; authenticator apps work without any signal and are immune to number based attacks. Second, add a PIN to your physical home SIM in your phone’s settings, so that even if the plastic card were stolen from your phone, it would demand the PIN in any other device before working.

Public networks vs cellular data: the real risk gap

Free Wi-Fi is the default traveller instinct and the single riskiest connectivity habit. The core problem is trust: your phone has no reliable way to confirm that Hotel_Guest_WiFi is operated by the hotel. Anyone with a pocket sized device can broadcast a convincing network name in an airport or café and sit between you and the internet, harvesting whatever the connection leaks and serving fake login pages to catch credentials. HTTPS closes much of the classic snooping gap, but it does not stop rogue portals, malicious redirects or the profiling of everything your device announces.

Cellular data has a structurally different trust model: traffic is encrypted between your phone and the tower, networks authenticate through the SIM itself, and intercepting it requires operating licensed radio infrastructure rather than a laptop in a departure lounge. No consumer technology is perfectly secure, but the bar for attacking a cellular session is orders of magnitude higher than for spoofing a café hotspot.

Public Wi-FiCellular data via eSIM
Who can operate itAnyone, including attackersLicensed network operators
Network impersonationTrivial (evil twin hotspots)Requires specialised hardware and legal risk
Encryption to the networkOften none or shared-passwordStandard between phone and tower
Captive portals and fake loginsCommon attack vectorNot applicable
Sensible useCasual browsing, downloadsBanking, email, payments, anything signed in

The practical rule costs nothing once a travel eSIM is installed: let cellular carry everything sensitive, and treat public Wi-Fi as a bulk pipe for downloads and streaming only. Airports are where the temptation peaks and the risk concentrates; our airport layover connectivity guide covers how to stay connected through transit without touching untrusted networks at all. With a prepaid plan installed there is simply no cost pressure pushing you onto free Wi-Fi for the tasks that matter.

The traveller security checklist

Run this list the week before departure; none of it takes more than a few minutes.

  1. Install your travel eSIM at home over trusted Wi-Fi, not from an airport hotspot after landing.
  2. Confirm dual SIM is set correctly: home SIM on for calls and SMS with data roaming off, travel eSIM carrying data.
  3. Set a SIM PIN on your physical home SIM.
  4. Enable Find My (iPhone) or Find Hub (Android) and verify you can see the device from another logged in browser.
  5. Switch your critical accounts (email first, then banking) from SMS codes to authenticator apps or passkeys where offered.
  6. Set a strong alphanumeric phone passcode and reduce lock screen notification previews, so codes and messages are not readable from a stolen, locked phone.
  7. Save your bank’s fraud line and your provider’s support contact somewhere outside the phone, on paper or in a companion’s device.
  8. Turn off auto join for open Wi-Fi networks in your phone’s Wi-Fi settings.
  9. Back up the phone before departure, so remote erase is a decision you can take without hesitation.

If any step exposes a gap, fixing it at home beats improvising abroad; a locked or incompatible handset, for instance, shows up in two minutes on a device compatibility checker rather than at the worst possible moment.

Travel safer with one change

Most of the list above is generic good hygiene, but the connectivity choice underneath it is the multiplier: a prepaid travel eSIM gives you a SIM that cannot be stolen out of the device, a data line detached from your sensitive number, a home number that keeps receiving verification codes, and a reason never to trust a free hotspot with anything that matters.

Setting it up takes minutes: pick your destination from the worldwide plans at Viasimo, and the prepaid plan arrives instantly by email with QR installation in minutes, no subscription attached and support around the clock if anything looks off. One small change before the flight, and the most common ways travellers get burned digitally stop applying to you.