Mind the SIM: Awareness and Mental Models in a South Korean Case Study
Hyunsoo Lee, Seyoung Jin, Hyoungshick Kim, Uichin Lee
Abstract
Mobile phone numbers function as single keys to banking, government, and commerce, making the Subscriber Identity Module (SIM) a critical element of security. In April 2025, South Korea's largest carrier experienced a SIM breach that compromised authentication keys and exposed nearly 27 million subscriber identifiers. We conducted semi-structured interviews with mental-model elicitation (𝑁 = 33) to examine user awareness, responses, and understanding of SIM-based authentication. Results reveal a pronounced awareness-action gap: participants recognized the breach yet held incomplete mental models, perceived little personal risk, and rarely acted protectively, even when affected. Learned helplessness, reliance on carriers, and the invisibility of SIM shaped these passive responses. Brief educational interventions improved conceptual understanding but seldom produced lasting behavioral change. Our findings demonstrate how technical opacity and psychological factors jointly inhibit protective action and offer design implications for usable security, emphasizing interventions that realign users' mental models with system risks to foster sustainable practices.
• Security and privacy → Social aspects of security and privacy; Usability in security and privacy; Human and societal aspects of security and privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5f64b8e4-9b01-4e3d-afd2-e16039fd1749Builds on4
- Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection PracticesYixin Zou, Kevin A. Roundy, Acar Tamersoy, Saurabh Shintre et al.CHI 2020 · 73 citations
- "Now I'm a bit angry: " Individuals' Awareness, Perception, and Responses to Data Breaches that Affected ThemPeter Mayer, Yixin Zou, Florian Schaub, Adam J. AvivUSENIX Security 2021 · 65 citations
- Users' Expectations About and Use of Smartphone Privacy and Security SettingsAlisa Frik, Juliann Kim, Joshua Rafael Sanchez, Joanne MaCHI 2022 · 54 citations
- Understanding Privacy Risks and Perceived Benefits in Open Dataset Collection for Mobile Affective ComputingHyunsoo Lee, Soowon Kang, Uichin LeeUbiComp 2022 · 24 citations
Related papers
- Understanding How Users Prepare for and React to Smartphone TheftDivyanshu Bhardwaj, Sumair Ijaz Hashmi, Katharina Krombholz, Maximilian GollaUSENIX Security 2025
- SecureSIM: rethinking authentication and access control for SIM/eSIMJinghao Zhao, Boyan Ding, Yunqi Guo, Zhaowei Tan et al.MobiCom 2021 · 18 citations
- Evaluating In-Workflow Messages for Improving Mental Models of End-to-End EncryptionOmer Akgul, Wei Bai, Shruti Das, Michelle L. MazurekUSENIX Security 2021 · 21 citations
- "Should I Worry?" A Cross-Cultural Examination of Account Security Incident ResponseElissa M. RedmilesS&P 2019 · 53 citations
- Security and Privacy Advice for UPI Users in IndiaDeepthi Mungara, Harshini Sri Ramulu, Yasemin AcarUSENIX Security 2025
