The short version
eSIM has stopped being a feature and become the default. Comparison site WhistleOut listed 23 of the 28 Australian providers in its database as offering eSIM plans as of 21 July 2026 — all three networks, and most of the resellers riding on them. Samsung’s Australian compatibility list runs from the Galaxy S26 series back to the S20, plus foldables, mid-range A-series and 5G tablets.
What has not happened here is the removal of the SIM tray. Apple sells eSIM-only iPhone 17, 17 Pro and 17 Pro Max models in twelve markets — and Australia is not one of them. The only eSIM-only iPhone you can buy in Australia is the iPhone Air, which ships without a tray everywhere in the world.
So the interesting story in 2026 is not the hardware. It is what happens when the credential that controls your phone number stops being a physical object you can hold and becomes a profile that can be issued, remotely, in seconds, to whoever passes a telco’s identity check. That is a security question, and Australia has an unusually well-documented answer to it — because the ACMA has been fining telcos over it for four years.
What an eSIM actually is
An eSIM is not a smaller SIM card. It is a permanently soldered secure chip in the phone that can hold several carrier profiles, downloaded over the air from the carrier’s provisioning server. The industry term is remote SIM provisioning. Practically, three things follow from that design:
- There is nothing to post. A new service can be live in minutes rather than days, which is the entire appeal for travel plans and for replacing a lost phone.
- One phone, several numbers. Modern handsets store multiple profiles and run more than one at a time — a work number and a personal number, or a local plan and a travel plan, without a dual-tray phone.
- Moving is a process, not a swap. You cannot pop it out and push it into a spare handset. WhistleOut’s guide puts it plainly: it is not arduous, but it takes a bit of time to work through the steps. Newer phones can transfer a profile device-to-device during setup where the carrier supports it; otherwise it means a QR code or a call.
That third point is the one people discover at the worst possible moment. A physical SIM survives a dead phone — you move it to an old handset in a drawer and you have a working number. An eSIM does not, unless the carrier lets you re-issue the profile, and re-issuing requires proving who you are. Which brings us to the actual subject.
The number is the credential now
Your mobile number is the recovery path for your email, your bank and most of your logins. Whoever controls it can usually collect the one-time codes that guard everything else. That was true in the plastic-SIM era too — the scam was called SIM swap and it worked by talking a telco into issuing a replacement card — but the physical step imposed friction and delay.
Remote provisioning removes the delay. That is not a flaw in the eSIM standard, which uses encrypted channels and a certification regime for the parties involved; it is a consequence of speed. The weakest link was never the cryptography. It was the identity check at the counter, or the web form, or the call centre — and that is precisely where every Australian enforcement action has landed.
The rules that protect you, and who has broken them
Two instruments do most of the work.
The Telecommunications (Mobile Number Pre-Porting Additional Identity Verification) Industry Standard 2020 requires any telco taking a number across from another provider to run at least one additional identity check confirming the person requesting the port actually holds the rights of use. It targets the port-out attack: your number leaves for a carrier you have never heard of.
The Telecommunications Service Provider (Customer Identity Authentication) Determination 2022, in force from 30 June 2022, covers what happens inside your own account. It requires multi-factor identity checks before high-risk transactions — SIM swap requests, password resets, account changes and disclosure of personal information — along with systems to identify customers at risk and public guidance on the telco’s website. When the ACMA made the rules it put the average loss to a victim of mobile fraud at around $28,000. Its 2022 announcement cited 510 reported frauds targeting customer authorisation processes between January and September 2021, of which 163 resulted in loss, totalling $4.68 million, with a single largest loss of $463,782.
The enforcement record since is where the theory meets the counter:
| Telstra — July 2024 | Penalised $1,551,000 for failing to run customer identity authentication on high-risk interactions between August 2022 and April 2023 — about 168,000 interactions, more than 7,000 of them involving vulnerable customers. Breach of the Customer Identity Authentication Determination 2022. |
|---|---|
| Exetel — August 2025 | Penalised $694,860 after a deficiency in its mobile transfer portal let 73 porting requests through without the required verification between 5 June and 3 July 2024. Reported losses exceeded $412,000. Breach of the pre-porting standard. |
| SpinTel — May 2026 | Penalised $59,400 after scammers exploited a vulnerability to obtain one-time codes used in its multi-factor checks, transferring 10 customers’ numbers without authorisation between February and March 2025 for reported losses over $45,000. Also gave an 18-month court-enforceable undertaking to have its security independently reviewed. |
| Yomojo — May 2026 | Formal warning for failing to publish the required advice telling customers to report mobile number porting fraud to law enforcement. No fine. |
| The running total | Nearly $5 million in penalties from telcos in the 18 months to May 2026, across what the ACMA described as its sixth enforcement announcement in a year under this program. |
Read that list the way a buyer should. The failures are not exotic. A portal that skipped a step. A code-delivery path that could be intercepted. A missing page on a website. None of it required the attacker to defeat the eSIM chip; it required them to defeat a business process. ACMA authority member Samantha Yorke framed the stakes bluntly in the May 2026 release: “Once a scammer gets access to your mobile phone service, you’re in danger.”
What changes next
The Scams Prevention Framework, legislated in February 2025, moves scam prevention from telco-specific rules into a cross-sector regime with an ombudsman attached. The Competition and Consumer (Scams Prevention Framework—Regulated Sectors) Designation 2026 was made on 28 May 2026 and designates three regulated sectors: banking, telecommunications and digital platforms. Each sector gets its own code, on the reasoning that each has vulnerabilities scammers exploit differently; Treasury’s consultation pointed to framework regulations from mid-2026, with the sector codes consulted on across the year.
For a phone customer the practical significance is the direction of travel rather than any single clause: obligations to prevent, detect, disrupt and report scams, backed by a single external complaints body. It is worth knowing that the regime exists, and worth checking what your provider has published about it — the Yomojo warning above was, after all, for not publishing something.
Should you switch to eSIM?
For most people, yes, and the reasons are mundane rather than dramatic. Activation is same-day. A travel profile can be bought and installed before you fly and sit alongside your normal number. There is no tray to lose, no adapter, no paperclip. WhistleOut notes eSIM plans do not cost more than physical-SIM plans, so the switch is free at the plan level.
Three caveats are real. First, the spare-handset problem above: if your phone dies, an eSIM cannot simply be moved, so know your carrier’s re-issue process before you need it. Second, wearables are a separate question — a smartwatch on its own number needs a provider that specifically supports wearable plans, and WhistleOut puts number-sharing at typically $5 or $10 a month on top of your bill. Third, if you buy phones overseas, check the market: an eSIM-only handset from the United States or Japan is fine on Australian networks that support eSIM, but leaves you no fallback if you later travel somewhere that hands you a plastic card.
What to actually do about it
| Stop using SMS for your important accounts | This is the single highest-value change and it costs nothing. Move your bank, primary email and password manager to an authenticator app or a passkey. A stolen number is only catastrophic because SMS codes are still accepted; take that away and a number theft becomes an inconvenience rather than a bank drain. |
|---|---|
| Lock the telco account, not just the phone | Every enforcement action above turned on account-level identity checks. Set a strong, unique password and a distinct account PIN with your provider, and use an email address for the account that is itself protected by something better than SMS. Compromised email is a common route in. |
| Treat sudden loss of service as an emergency | If your phone drops to “no service” without explanation and stays there, assume port-out until proven otherwise. Contact your telco from another phone and your bank straight after — the window between the transfer and the theft is measured in minutes. |
| Know the eSIM re-issue path in advance | Find out now how your provider re-issues a profile to a replacement handset, what identification it requires, and whether it can be done without a working phone. A physical SIM fails gracefully into a spare handset; an eSIM fails into a support queue. |
| Check what your provider publishes | Telcos are required to publish customer-facing guidance on mobile number fraud, including where to report it. A provider that has not bothered is telling you something about the rest of its processes. |
| Buying an eSIM-only phone? Check the market it came from | Australian iPhone 17 models keep the nano-SIM tray; only the iPhone Air is eSIM-only here. Grey-import and overseas-purchased eSIM-only handsets work on Australian eSIM-capable plans, but you lose the physical fallback permanently. |
| If you are hit | The ACMA directs consumers to contact their telco and financial institution immediately, report to Scamwatch, and contact IDCARE on 1800 595 160 if identity details are compromised. It also points to Lifeline (13 11 14) and Beyond Blue (1300 22 4636) for support. |
The bottom line
eSIM is the better technology and Australia has adopted it thoroughly and quietly. Nobody needs talking into it. But the convenience that makes it good — a number that can be issued anywhere, instantly, with no physical step — is the same property that makes the identity check at the telco the only thing standing between a scammer and your bank. Four years of ACMA penalties say that check is not reliably good, and the failures were process failures, not technology failures.
The useful conclusion is not “avoid eSIM”. It is that your phone number should stop being a security control. Take SMS out of the loop on the accounts that matter, harden the telco account itself, and the question of whether your SIM is plastic or a profile becomes what it should always have been: a matter of convenience.
Sources
Facts, figures and dates above are drawn from these primary and reputable sources, captured 7 August 2026:
- ACMA — Compliance net tightens on mobile number fraud (7 May 2026): the SpinTel $59,400 penalty and 18-month court-enforceable undertaking, the Yomojo formal warning, the “almost $5 million in the last 18 months” figure, the sixth-enforcement-in-a-year framing, Samantha Yorke’s quote, and the consumer advice naming Scamwatch, IDCARE, Lifeline and Beyond Blue.
- Cyber Daily — ACMA takes action against SpinTel and Yomojo (7 May 2026): the 10 unauthorised transfers between February and March 2025, the $45,000-plus in reported losses, and the detail of each breach.
- ARN — Telstra penalised $1.5m for ID authentication failures (17 July 2024): the $1,551,000 penalty, 168,000 high-risk interactions between August 2022 and April 2023, more than 7,000 involving vulnerable customers, and Samantha Yorke on the $28,000 average loss.
- Information Age (ACS) — Exetel fined $695k for enabling SIM-swapping fraud (28 August 2025): the $694,860 penalty, 73 unverified porting requests between 5 June and 3 July 2024, more than $412,000 stolen, and the rights-of-use-holder wording of the pre-porting standard.
- iTnews — ACMA clamps down on SIM-swap frauds (8 April 2022): the Customer Identity Authentication Determination 2022 commencing 30 June 2022, the high-risk transaction categories, and the 2021 figures of 510 reported frauds, 163 with loss, $4.68 million total and $463,782 largest single loss.
- ACMA — Customer identity authentication rules: the standing obligations on telcos, including multi-factor authentication, at-risk customer systems and published customer awareness information.
- Federal Register of Legislation — Competition and Consumer (Scams Prevention Framework—Regulated Sectors) Designation 2026 (made 28 May 2026): designation of banking, telecommunications and digital platforms as regulated sectors.
- Treasury Ministers — Consulting on industry codes and rules to protect consumers from scams (29 November 2025): the three initial sectors, one code per sector, the AFCA authorisation, and framework regulations expected mid-2026.
- WhistleOut — What is an eSIM? (updated 21 July 2026): 23 of 28 listed Australian providers offering eSIM plans, eSIM plans costing no more than physical-SIM plans, the transfer-between-handsets caveat, and wearable number-sharing at typically $5 or $10 a month.
- MacRumors — iPhone 17 models are eSIM-only in these countries (9 September 2025): the twelve eSIM-only markets, Australia’s absence from that list, and the iPhone Air being eSIM-only worldwide.
- Samsung Australia — Which Galaxy phones support an eSIM?: the Australian compatibility list spanning the Galaxy S26 series back to S20, foldables, selected A-series and 5G tablets.