GO UP
esim background
Telia mobile certificate security

Telia Tightens Mobile Certificate Security for eSIMs

Telia Finland is adding another layer of identity verification to Mobile Certificate activation from the beginning of September 2026, with the first changes focused specifically on customers using eSIM subscriptions.

The move is relatively narrow, but the reason behind it is bigger. Telia says the misuse it has seen around Mobile Certificates has consistently been connected to eSIM subscription activation and compromised identification. The problem is not that eSIM itself is insecure. It is that remote provisioning makes the identity-checking step more important: if a fraudster can convincingly impersonate the customer, a digital SIM can be activated without the physical handover that once formed part of the process.

Mobile Certificate is a significant part of Finland’s digital identity infrastructure. It is offered by Telia, Elisa and DNA, works across more than 20,000 services and is used for millions of identifications each month.

Telia adds a second check

Until now, a customer could activate a Mobile Certificate using online banking credentials. Telia is now introducing additional verification when the customer has an eSIM subscription and the first identification is completed using bank credentials.

“We have observed that criminals are interested in mobile certificates, and the observed misuse of mobile certificates is invariably related to the introduction of eSIM subscriptions and identification. The new phase in identification effectively prevents these risks,”

says Antti Turunen, Head of Fraud Prevention at Telia.

Related Insight:
How Does an eSIM Work? What Really Happens Inside Your Phone

 

According to Telia, the fraud pattern typically begins earlier. Criminals either steal online banking credentials or persuade victims to approve transactions or identification requests using their own credentials. Once that first layer is compromised, the attacker may attempt to activate a Mobile Certificate in the victim’s name.

“For now, additional verification is implemented when the customer has an eSIM subscription and the first identification is done with online banking credentials. In this case, the user is asked for a second confirmation with separate biometric identification in the online service,”

Turunen says.

How activation now works

The rollout on telia.fi follows a two-step process:

  1. First identification: with online banking credentials.
  2. Second identification: using either:
    • a passport or identity card; or
    • Hightrust.id.

When a passport or identity card is used, Telia also checks the customer’s facial image during verification.

The extra step adds some friction, but only where Telia believes the risk is highest. Traditional physical SIM customers are not currently included, nor are activation paths outside the specified eSIM-plus-bank-credentials scenario.

The real issue is identity, not eSIM

That distinction matters. The GSMA describes eSIM as offering security equivalent to the removable SIM and has said that the consumer remote SIM provisioning protocol is adequately secured against network attackers when the participating entities are legitimate. The fraud problem sits elsewhere: account takeover, social engineering and weak customer authentication around legitimate SIM or eSIM changes.

ENISA has warned about this for years. In its work on SIM-swapping fraud, the EU cybersecurity agency identified weak customer authentication as one condition that can enable an attacker to take control of a subscriber’s number. It recommends stronger detection and blocking mechanisms by mobile operators.

Related Insight:
SIM Swap Fraud in the eSIM Era Explained

 

Finland already treats both operator-issued Mobile Certificates and online banking codes as strong electronic identification methods under the national trust framework supervised by Traficom. Telia’s change effectively acknowledges that one strong credential may still be insufficient when that credential itself has been stolen or socially engineered.

The obvious next question is whether risk-based second verification should remain limited to eSIM activation. Telia says Mobile Certificate misuse has historically been very rare and that the service has been in use for more than 15 years. For now, it is targeting the path where it has seen abuse rather than adding friction to every customer journey.

“Telia is constantly monitoring identification events, and we are actively working to prevent fraud and abuse. If necessary, we have the option to extend the feature to traditional SIM cards as well,”

Turunen says.

More on Alertify
Follow the latest eSIM security news
eSIM swapping threats, authentication protocols, Remote SIM Provisioning vulnerabilities, profile management standards, and identity protection in digital telecom.

Explore news

Identity is becoming part of eSIM security

Telia’s change is a reminder that the next phase of eSIM security will not be won only inside the eSIM specification. Provisioning technology can be robust while the customer identity process around it remains exploitable.

That is why the wider telecom industry is moving toward layered fraud controls, from biometric identity proofing to SIM-swap and device-swap signals exposed through operator APIs. Digital SIMs make mobile service faster and easier to provision, but they also force operators to become better at proving who is actually requesting that convenience. GSMA Open Gateway, for example, already includes SIM Swap and Device Swap APIs designed to give digital services additional fraud signals.

Related Insight:
Guuk Secures SIM-to-eSIM Transfers With KYC

 

Telia’s approach is sensible because it applies the extra check selectively. What could make it stronger is greater transparency over the risk rules behind that decision and whether similar protections will eventually apply to physical SIM changes. For Finnish users who prefer another route, bank credentials and the Citizen Certificate remain established strong-identification alternatives.

The important shift is not “eSIM needs more security.” It is that identity verification is becoming part of the mobile connectivity stack itself. Telia is treating it that way.

Driven by wanderlust and a passion for tech, Sandra is the creative force behind Alertify. Love for exploration and discovery is what sparked the idea for Alertify, a product that likely combines Sandra’s technological expertise with the desire to simplify or enhance travel experiences in some way.