Malicious SIM cards can hijack the modems inside EV chargers and industrial gear, researchers find
A team at the University of Birmingham showed that a booby-trapped SIM can run attacker code on the cellular modules baked into cars, routers and chargers.

Key points
- Researchers at the University of Birmingham and security firm Fuzzware tested 26 phones and cellular modules and found most will execute commands sent by a malicious SIM card.
- The flaw lives in the modems built into electric-vehicle chargers, industrial routers and car telematics units, not just handsets.
- The attack abuses the SIM Application Toolkit, a decades-old carrier feature that lets the SIM instruct the device.
- On internet-connected hardware with no screen and no user present, a compromised modem hands over the whole unit.
- Researchers describe it as a supply-chain risk for cellular IoT deployments.
A SIM card is supposed to be passive. You slide it into a phone, it proves your identity to the mobile network, and that's that.
Turns out it can do rather more. And if it's hostile, it can tell the device it sits in to run commands chosen by an attacker.
Researchers at the University of Birmingham, working with security firm Fuzzware, tested 26 phones and cellular modules and found the capability was widespread across hardware already shipping to customers.
What exactly did the researchers find?
A hostile SIM can push commands into the modem, the small radio chip that manages the cellular connection, and get them executed. On a phone that's bad enough. For an industrial device with no screen and no watching user, it's considerably worse.
The mechanism is the SIM Application Toolkit, a set of instructions baked into mobile standards in the 1990s so carriers could push menus and prompts to handsets. That same channel, the researchers showed, can be pushed further than its designers intended.
Why does this matter beyond phones?
Because the same cellular modules sit inside things few people think of as computers. EV chargers in car parks, industrial routers in factories and water plants, telematics units bolted into cars reporting location and diagnostics to manufacturers.
These devices are typically built around an off-the-shelf cellular module from a small number of vendors. If the module can be taken over by the SIM inside it, the whole device can be taken over. This connects to a broader pattern Threat Vectr has tracked in embedded hardware: our 4 August story on TP-Link router flaws showed how a single compromised component can cascade across an entire network.
| Detail | What the research says |
|---|---|
| Devices tested | 26 phones and cellular modules |
| Research team | University of Birmingham and Fuzzware |
| Feature abused | SIM Application Toolkit |
| Devices at risk | EV chargers, industrial routers, car telematics |
How would an attacker actually pull this off?
They'd need to get a malicious SIM into the target device. For a phone in your pocket, that's a real barrier. For a roadside EV charger or a fleet of trucks fitted with telematics boxes at a depot, physical access is a softer problem than it sounds.
The supply chain compounds it. SIMs for industrial devices are often shipped in bulk, provisioned by third parties, installed by contractors. Each handoff is an opportunity to swap in a hostile card.
Who is behind this, and is it being exploited?
This is academic research, not an incident report. No known group is tracked as using the technique in the wild. The work's value is that it confirms the capability exists in shipping hardware, and that the mobile industry's assumption of a trusted SIM breaks down when the SIM is the attacker.
Vendors of cellular modules will likely push firmware updates restricting which SIM Toolkit commands the modem will accept. Operators of large IoT fleets, utilities, car makers and logistics firms should now be asking harder questions about where their SIMs actually originated.
For ordinary phone users, there's nothing to act on today. Don't accept a SIM from a stranger. That was already good advice.



