Your phone number is one of your most sensitive identifiers. Banks, email providers, and social platforms often use it for password resets and alerts. That makes the path into your number—via SIM swap, social engineering, or carrier features—especially valuable to attackers. This guide explains how the SIM Toolkit and related carrier features can expand your attack surface, which ones are high risk, how to disable or harden them on iPhone and Android, and what to monitor going forward.
What Is the SIM Toolkit (SIM Application Toolkit)?
The SIM Toolkit (sometimes called STK or “SIM applications”) is a set of carrier-provided menus and commands stored on your SIM card. These menus can trigger actions like balance checks, subscriptions, data packages, value-added services, and network commands. On some phones you’ll see a dedicated app called “SIM Toolkit,” “SIM Services,” or a carrier-branded icon. On iPhones, the menu (if present) usually appears under Settings > Mobile/Cellular > SIM Applications.
These features rely on special commands (often USSD or proactive SIM actions) that interact directly with your carrier network. While many are harmless, some can enable changes to your line or reveal data that could be abused during account takeover attempts.
Why SIM Toolkit and Carrier Line Features Matter for Account Takeover
Attackers try to intercept your one-time codes and password reset links by taking control of your number. They may:
- Convince carrier support to move your number to a new SIM (SIM swap).
- Use weak line features like unprotected call forwarding or insecure voicemail to catch codes.
- Leverage USSD and SIM menu flows to subscribe or alter services that change how calls or texts route.
If you reduce or lock down these avenues, you make account takeover significantly harder—even if an attacker has some of your personal details.
High-Risk Features to Review and Disable
Not every phone or carrier exposes the same options. Prioritize these areas and ask your carrier for help where needed.
1) Call Forwarding Without Authentication
Call forwarding can silently send your calls to a number an attacker controls. If your carrier or SIM menu lets you toggle forwarding without strong verification, disable it and request a support PIN or account lock for any future changes.
- Disable conditional and unconditional call forwarding (CFU, CFB, CFNRy, CFNRc) unless truly needed.
- Request that your carrier block or password-protect forwarding changes on your line.
2) Weak or Default Voicemail Settings
Voicemail is still abused to capture two-factor codes when services fall back to voice calls. If your voicemail uses a default PIN or allows remote access without a PIN, it’s risky.
- Set a unique voicemail PIN and disable “skip PIN on your device” if supported.
- Turn off remote voicemail access if you don’t need it.
- Disable voicemail entirely if you can operate without it.
3) Unnecessary SIM Toolkit (STK) Apps and Subscriptions
Some SIM apps initiate USSD sessions or subscriptions that can change line behavior or expose info (like balances or data packages) that assist social engineering.
- Open the SIM Toolkit or SIM Applications menu and disable or opt-out of nonessential apps, value-added services, or subscriptions.
- Ask your carrier to remove SIM menu apps you don’t need or to disable STK access on your line if they support it.
4) USSD Codes That Change Line Settings
Carriers support short USSD codes to alter call forwarding, barring, or other settings. If these are easy to trigger, a malicious app with overlay permissions or physical access could attempt changes.
- Do not grant phone or call permissions to apps that don’t need them.
- Avoid installing apps from unknown sources that might auto-dial USSD.
- Request your carrier place a “change lock” or account PIN on forwarding and other line features.
5) eSIM Profile Management Without Extra Locks
eSIM simplifies line activation but can be abused if your main device or accounts are compromised.
- Lock your device with a strong passcode and enable biometric unlock.
- Use a unique carrier account password and a support PIN or passphrase for any SIM or eSIM changes.
- Enable SIM PIN (distinct from device PIN) to prevent unauthorized SIM changes if the device is stolen.
How to Find and Adjust SIM Toolkit Features
Locations vary by phone and carrier. Use these general steps, then confirm with your carrier if you can’t find what you need.
Android
- Find SIM Toolkit: Look for an app called “SIM Toolkit,” “SIM Services,” or your carrier’s app icon in the app drawer. On some devices, it appears only after you insert the SIM.
- Disable apps/subscriptions: Open the menu and opt out of value-added services or disable push messages/alerts from within the SIM app if available.
- Call forwarding: Go to Phone app > Settings > Calling accounts or Supplementary services > Call forwarding. Disable all forwarding types unless required.
- Voicemail PIN: Phone app > Voicemail settings. Set a strong PIN and turn off remote access if offered.
- SIM PIN: Settings > Security > SIM card lock. Enable SIM PIN and store it safely. Avoid simple sequences.
iPhone
- SIM Applications: Settings > Cellular/Mobile Data > SIM Applications. If present, review and opt out of any unnecessary features.
- Call forwarding: Settings > Phone > Call Forwarding. Turn it off unless needed.
- Voicemail security: Set or change your voicemail password (Phone app > Voicemail > Set Up/Change Voicemail Password). Ask your carrier to require the PIN even from your device and to disable default PIN behavior.
- SIM PIN: Settings > Cellular > SIM PIN. Enable and choose a unique code.
Ask Your Carrier for Stronger Line Security
Some protections can only be enabled by your carrier. Contact support using the number on your bill or the official app and ask for:
- A required account passcode/support PIN for any change to your line (SIM swaps, forwarding, port-outs, eSIM activations).
- Port-out and SIM-swap protection flags, if available, requiring in-person verification or additional checks.
- Blocking or password-protecting call forwarding changes, or disabling forwarding entirely if not needed.
- Disabling or removing STK services or specific SIM menu apps you don’t use.
- Requiring a voicemail PIN for all access, including from your device, and disabling default or carrier-bypass settings.
Document what protections were applied and ask for a case or ticket number. Re-check after any plan or device change.
Best Practices to Reduce Phone-Number Takeover Risk
Hardening the SIM Toolkit is one layer. Combine it with these broader steps for better protection.
- Move away from SMS 2FA where possible: Use app-based authenticators or security keys for banking, email, and crypto accounts. SMS can still be a backup but avoid relying on it as the primary factor.
- Separate numbers: Consider using a secondary number for public profiles, signups, or business inquiries. Keep your recovery number private and tied only to critical accounts.
- Secure the carrier account: Use a unique password and turn on two-step verification for your carrier login. Add a support PIN/passphrase for phone-based support.
- Lock your device: Strong passcode, biometric unlock, auto-lock, and Find My/Find My Device enabled.
- Review installed apps: Remove apps you don’t use; restrict phone, SMS, and overlay permissions to essentials only.
- Monitor your line: Unexpected call forwarding toggles, sudden signal loss, or messages about SIM changes are red flags. Contact your carrier immediately if they occur.
What If You Can’t Find SIM Toolkit or Options Are Grayed Out?
Some carriers do not expose a SIM Toolkit or limit what you can change. In that case:
- Confirm with your carrier which SIM/STK features are active on your line.
- Ask them to disable value-added services, block forwarding changes, and enforce a voicemail PIN from the network side.
- Request SIM-swap/port-out locks and note what verification is required to remove them.
If your device is carrier-locked, options may be restricted. Consider contacting your carrier’s fraud or security team for additional safeguards.
How to Use SIM PIN Safely
Enabling a SIM PIN protects your line if your phone is stolen or someone tries to move your SIM into another device. Use it carefully:
- Choose a 6–8 digit code that’s not a birthday or repeating pattern.
- Record the PUK (Personal Unblocking Key) somewhere secure in case you forget the PIN. Your carrier provides it.
- Be aware that too many wrong PIN attempts can lock the SIM; you will need the PUK to unlock.
Detecting and Responding to Suspicious Activity
Time is critical in account takeover incidents. Watch for:
- Sudden loss of cellular service when others still have coverage.
- Unrecognized call forwarding indicators or settings toggled on.
- Carrier messages about SIM changes, eSIM activations, or password resets you didn’t request.
- Logins or password reset emails for major accounts that you did not initiate.
Immediate actions:
- Call your carrier from another phone and report suspected SIM swap or line changes. Ask to freeze the line, remove unauthorized forwarding, and restore your SIM profile.
- Change passwords and revoke active sessions on your email, bank, and critical accounts.
- Switch any SMS-based 2FA to app-based or security keys as soon as you regain access.
Privacy and Identity Monitoring Still Matter
Even with strong SIM and carrier settings, data breaches and social engineering can still target your financial identity. Continuous monitoring helps you catch misuse early. If you want a practical way to watch for suspicious credit or identity activity, consider a privacy-focused credit and identity monitoring service that alerts you to changes and helps you respond quickly. One option is available here: SmartCredit for privacy, credit monitoring, and identity protection.
Quick Checklist: Reduce SIM and Line Attack Surface
- Disable all call forwarding unless absolutely required; ask carrier to block or PIN-protect changes.
- Set a strong voicemail PIN; disable remote access or voicemail entirely if possible.
- Review SIM Toolkit apps; opt out of nonessential services or ask carrier to remove them.
- Enable a SIM PIN and store your PUK securely.
- Lock down your carrier account with a unique password and support PIN.
- Prefer app-based 2FA or security keys over SMS.
- Limit app permissions that can initiate calls or USSD.
- Monitor for odd messages, forwarding toggles, or SIM change alerts.
Common Myths
- “If I enable SIM PIN, I don’t need a device passcode.” You need both; they protect different things.
- “Disabling call forwarding breaks my service.” Normal calling and texting keep working; only forwarding is affected.
- “eSIM is always less secure than a physical SIM.” Security depends on account protections and carrier verification, not just the form factor.
- “SMS 2FA is safe enough for banking.” It’s better than nothing, but app-based or hardware keys are significantly stronger.
Conclusion
Attackers favor the easiest path to your accounts—often your phone number. By disabling risky SIM Toolkit features, locking down call forwarding and voicemail, enabling a SIM PIN, and adding strong carrier-side protections, you remove several takeover paths in one sweep. Pair these changes with stronger authentication on your critical accounts and ongoing identity monitoring so you can detect and respond to trouble quickly. Small adjustments to your SIM and line settings today can prevent major damage tomorrow.
Good to Know
Carriers name and place the SIM Toolkit differently. If you cannot find it on your phone, contact your carrier and ask them to disable specific SIM or line features (like call forwarding or SIM menu apps) on their side.