Skip to main content
LiMP VPN
All news

eSIM Hijacking: Attackers Steal Phone Numbers

eSIM Hijacking: Attackers Steal Phone Numbers

In short: In late July 2026, subscribers of the Russian operator Beeline faced a wave of number-hijacking attempts: attackers pushed users to confirm a login to their personal account, then remotely issued an eSIM and blocked the original SIM card — intercepting the number. Beeline reported thousands of fraudulent requests over several days but called successful cases isolated. The main defence: never confirm a login you did not start, and set a ban on remote SIM re-issuance.

What happened?

In late July 2026 Beeline confirmed what it described as a coordinated attack aimed specifically at remote SIM issuance and replacement. According to the operator, over several days attackers shifted their approach and sent thousands of fraudulent requests for access to subscribers' personal accounts. Beeline said cases where criminals completed the takeover were isolated and that it helped affected customers restore their numbers — but staff at retail offices reported regular complaints over the preceding two weeks. Even the editor-in-chief of a major radio outlet was among those targeted, which underlines the scale.

The mechanics differ from the classic "give me the SMS code" scam, yet the goal is the same — seizing control of your number. We looked at a related pressure tactic in our report on the two-call phone scam that steals SMS codes. This time the trick is subtler: no code is spoken aloud at all.

How does the attack work?

It starts with a login prompt. A user receives a system notification asking them to confirm a sign-in to their operator account. As one victim explained, when you pick "log in from the phone screen," the system does not ask for a password — a single tap on the pop-up is enough. Once the victim confirms, an eSIM is issued and the original physical SIM is blocked, moving the number to the attacker's device.

Security specialist Alexander Baulin noted that if criminals reach the operator's infrastructure they can transfer an eSIM from a user's device to their own, and that such attacks are usually accompanied by a mistake on the user's side — one careless confirmation. That is the whole point: the attackers are not breaking encryption, they are engineering a single tap. It is the same confirmation-fatigue weakness we described in our piece on device-code phishing.

Why is losing your number so dangerous?

A phone number is the master key to your digital life. As tech blogger Ivan Olyansky put it, gaining someone's number means obtaining access to their one-time codes, email, banking and other accounts. The moment an attacker controls your number, they can request password resets, intercept the SMS codes those resets send, and cascade from your SIM into your mail, your messengers and your money. That is why a SIM or eSIM takeover is not a telecom nuisance but a full account-compromise event.

It is worth being honest about one limit: a VPN would not have stopped this specific attack, because the takeover happens at the operator level after a user confirms a login. What a no-logs VPN does protect is a different layer — it encrypts your traffic and hides your real IP on untrusted networks, so the credentials and data that feed such schemes are harder to intercept and your activity is harder to profile. Digital safety works in layers, as we explain on our features page.

How to protect your number right now

Never confirm a login you did not initiate. If a sign-in prompt appears out of nowhere, reject it and contact your operator directly through the official app or hotline — not through any link in the message.

Set a ban on remote SIM re-issuance. Most operators let you forbid remote SIM and eSIM changes so that a replacement can only be made in person with ID. It is the single most effective lock against this class of attack.

Move 2FA off SMS. Use an authenticator app or a hardware key for important accounts, so that losing your number does not automatically hand over your logins.

Reduce your exposure. Use unique passwords with a manager, watch for phishing that references your data, and encrypt your connection on public networks with a no-logs VPN such as LiMP VPN. None of this replaces the SIM-issuance ban, but together these habits shrink the trail attackers use. More privacy basics live on our blog.

Sources

This report is based on coverage by Habr and Kommersant (July 2026).

eSIM Hijacking: Attackers Steal Phone Numbers | LiMP VPN