Fast Facts
Researchers proved that malicious SIM card attacks can execute attacker code inside the cellular modems running EV chargers, industrial routers, and telematics units. Six of eight tested industrial modules accepted the command. No mandatory patch exists yet, only a scattered, vendor-by-vendor response.
Malicious SIM card attacks just moved from theory to demonstrated fact for industrial hardware. Cellular IoT connections are on pace to reach 5.4 billion worldwide in 2026, according to IoT Analytics, and the module makers behind a large share of that growth just received a public lesson in a 40-year-old blind spot.
A Feature, Not a Bug
The vulnerability traces back to Proactive SIM, a legitimate cellular specification that lets a SIM card send commands directly to a device’s modem instead of only answering its requests. One of those commands, RUN AT, tells the modem to execute an AT command, the same control language used to operate modems since the 1980s, according to researchers from the University of Birmingham and security firm Fuzzware who presented the findings at the 2026 USENIX WOOT Conference in Baltimore. Using a custom toolkit called CATana, the team tested 26 devices: 18 smartphones and 8 cellular IoT modules used in EV chargers, industrial equipment, and connected cars.
The proactive capabilities of a SIM and the resulting attack surface is explicitly defined in the technical specifications for cellular communication, resulting in specification-compliant attacks.— Dr. Marius Muench, University of Birmingham
9 of 26 devices tested executed attacker-issued commands from the SIM, confirming that malicious SIM card attacks work against real, commercially available hardware, including a working code-execution demonstration on a commercial EV charger.
Why Industrial Modules Failed Where Phones Didn’t
Only 3 of 18 phones accepted the command, the OPPO Find X5, the OPPO Reno 14F 5G, and the ASUS Zenfone 9, while 6 of 8 industrial and IoT modules did. No iPhone or Pixel was affected. That gap explains why malicious SIM card attacks land harder on industrial hardware than on consumer phones. Phones get frequent, forced OS updates; a cellular module soldered into a factory router or a charging station can run untouched for a decade.
Five of the six vulnerable modules were Quectel parts, and Quectel holds close to a third of the global cellular IoT module market, per Berg Insight’s 2025 vendor data. That concentration means malicious SIM card attacks against a single module family can reach a fleet-wide exposure in one move. See our analysis where we explain why device lifecycle management is IIoT’s coming bill.
⚠ Fiction — illustrative scenario: A logistics yard runs forty industrial routers on the module family flagged in the Birmingham research. Devices report normally, dashboards stay green, and nobody schedules a firmware review because nothing looks broken. This is exactly the kind of setup where malicious SIM card attacks go unnoticed: a manipulated SIM inserted during routine maintenance runs commands the operator never authorized, and the modem reports nothing unusual, because nothing outside the network noticed.
Who Pays to Fix Deployed Hardware
The researchers disclosed their findings to Google, Oppo, Quectel, Semtech, and Qualcomm in March 2026, then to the GSMA in May, per The Hacker News. Qualcomm has since shipped a hardened configuration that disables the SIM AT interface by default. Quectel says the flaw was already fixed in newer firmware but hasn’t published affected or fixed version numbers. As of mid-August, no vendor has issued a public advisory, and none of the affected companies have committed to retrofitting hardware already installed in the field.
That silence is the real commercial exposure behind malicious SIM card attacks: a fix that only applies to new shipments does nothing for the millions of modules already bolted into chargers, routers, and telematics units. See our related coverage on why industrial cyberattacks are targeting factory floors directly and how to protect industrial IoT fleets from botnet-style attacks.
Global Implications
There is no confirmed in-the-wild exploitation as of August 2026, according to Rescana’s CVE analysis, but malicious SIM card attacks only require physical or supply-chain access to a SIM, a realistic bar anywhere field technicians handle routine SIM swaps without strict chain-of-custody controls. That includes many industrial deployments across Africa and Southeast Asia, where cellular IoT growth is fastest and procurement cycles rarely include a hardware-level security audit. See our analysis of Nigeria’s 2026 satellite and IoT licensing shift and our broader look at industrial IoT ROI heading into 2026.
💡 CreedTec Analyst’s Note — Daniel Ikechukwu
Strategic Impact: Malicious SIM card attacks expose a hardware trust problem, not a software patch problem. Buyers who assume “patched” means “fixed everywhere” are miscounting their exposure.
- Stop: Treating SIM cards as a trusted, passive component in industrial procurement checklists.
- Start: Asking module vendors directly whether the SIM AT interface is disabled by default on your specific hardware revision.
- Watch: Whether the GSMA’s CVD-2026-0122 tracking produces an industry-wide retrofit standard, or stays vendor-by-vendor.
ROI Outlook: Auditing SIM provisioning across an existing fleet costs far less than recovering from one of the malicious SIM card attacks this research demonstrated on a live EV charger. This is a low-cost fix window that will not stay open indefinitely.
Cellular IoT is scaling past five billion connections before most industrial buyers even know their module vendor’s name. Malicious SIM card attacks prove the next line item on an OT security audit shouldn’t be the network. It should be the SIM.
Get CreedTec’s next industrial IoT security briefing before your next fleet procurement cycle.
Subscribe free
Sources
- University of Birmingham, USENIX WOOT Conference 2026 research findings
- The Hacker News, “A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices,” August 2026
- Help Net Security, “Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G,” August 2026
- Rescana, Critical CVE Analysis, August 2026
- IoT Analytics, Cellular IoT Market Update, Spring 2026
- Berg Insight / HTNXT, Global IoT Module Market Report 2026
- The Register, “Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G,” August 2026


