Malicious SIM Cards Can Hijack IoT Devices Like EV Chargers and Industrial Routers
Security researchers from the University of Birmingham and Fuzzware have discovered that a malicious SIM card can be used to send attacker-controlled commands to the cellular modems found in many connected devices. On critical hardware such as electric-vehicle chargers, industrial routers, and car telematics units, this capability could allow an attacker to fully take over the device.
The research tested 26 phones and cellular modules and found that many were vulnerable to this type of attack. Because cellular modems often have deep access to a device's core functions, a compromised SIM could give attackers a way in that bypasses traditional network security measures like firewalls, since the connection happens over the mobile network rather than the internet.
For small businesses that rely on connected equipment—whether that's a fleet tracking system, a smart charging station, or IoT sensors using cellular connectivity—this research is a reminder that the risk isn't only in software and Wi-Fi networks. Hardware components like SIM cards and modems can also be an entry point for attackers, particularly as more business equipment becomes cellular-enabled.