Chinese state hackers, the group now called Salt Typhoon, spent as long as two years inside the biggest telecom networks in the United States. At least nine major carriers, AT&T, Verizon, T-Mobile, Lumen, Charter, and others, were breached. The attackers accessed call detail records, who called whom, when, for how long, and from where, for more than a million American subscribers. For a smaller set of high-value targets, including presidential campaign staff, they got actual recorded calls.
Here is the detail that should stop you cold. They got in largely through CALEA, the system the United States government mandates that carriers build into their networks so that law enforcement can execute court-ordered wiretaps. The surveillance backdoor, the one built for the “good guys,” was the door a hostile nation walked through. Investigators described it as the worst telecom hack in the nation’s history, and as of early 2026, some of those systems were reportedly still compromised.
Now connect that to everything we have written about building an anonymous phone. You can source the handset off a shelf so no shipment points at you. You can pay cash so no purchase record ties it to you. You can activate it cleanly so setup does not reattach your name. And then you slide in a SIM, and hand yourself right back to a system that logs you by design and has already been breached at national scale.
The handset can be a ghost. The SIM is a name tag.
What the SIM actually is
A SIM is not a neutral little chip that grants you phone service. It is a persistent identifier that broadcasts who you are to the network, continuously, for as long as the phone is on.
Two numbers do the work. The IMSI, the identity burned into the SIM, and the phone number attached to it. From the moment your SIM registers on the network, the carrier logs which cell towers it connects to, everywhere it goes, all day, every day. That is not a bug or an abuse. It is how cellular works: the network has to know roughly where you are to route a call to you, so the location history is a natural byproduct, recorded and retained. Your carrier holds a map of everywhere your SIM has been. So does anyone who takes that data from them, buys it, subpoenas it, or, as we just learned, hacks it out.
And it does not stop at your carrier. Because the SIM answers any tower that calls to it, it will also answer a fake one. IMSI catchers, the surveillance devices often called Stingrays, impersonate a cell tower to make every phone nearby cough up its IMSI. Your SIM does not know the difference. It broadcasts its identity to whatever is pretending to be the network, which is exactly how those devices identify and track the phones in a given place.
The link that undoes an anonymous handset
Here is the specific mechanism that matters for a private device. The instant your SIM registers inside a phone, the carrier records that this SIM, the one tied to you, is inside this handset, identified by its IMEI. Your identity and that specific piece of hardware are now paired in the carrier’s records.
That pairing is what unmasks careful people. Put your SIM into an “anonymous” phone and it is no longer anonymous; it is the phone that your SIM lives in. Swap that SIM into a second handset and the carrier now links both IMEIs to you through your one IMSI. This is precisely how burner-swapping gets defeated, and it is why we said in an earlier post that a burner is only as clean as the SIM you feed it. The SIM is the thread that ties every device it touches back to a single subscriber, which is to say, back to you.
And the data is not safe where it sits
You might think, fine, the carrier has my location and metadata, but it stays locked up unless a judge signs off. That comfort is gone.
Carriers have been caught and fined for selling their customers’ real-time location data to aggregators, who resold it down a chain that reached bounty hunters. Location and tower records are pulled by law enforcement through geofence and tower-dump requests, sometimes sweeping up everyone who happened to be in an area. And then there is Salt Typhoon, the proof that the entire apparatus can be taken wholesale by a foreign intelligence service, through the lawful-intercept system itself. There is no version of “just trust your carrier with your movements and your contacts” that survives that story. The honest assumption, as one analysis put it bluntly, is that if you use a major carrier, your metadata is compromised.
Registration makes it worse, and eSIM often worst
In most of the world, you cannot even buy a SIM without showing ID; mandatory SIM registration is the norm, and it ties the IMSI to your name at the point of sale. In the parts of the US where you can still buy prepaid with cash, the anonymity is real at purchase but fragile in use, because activation details and usage patterns re-link it fast. Anonymous when you bought it is not the same as anonymous while you use it.
And eSIM, marketed as the modern convenience, is frequently worse for anonymity, not better. An eSIM is provisioned digitally, usually through an app, an account, and a payment method, which is a tidy, identity-linked record of exactly which line you activated on which device. There are a few services trying to offer anonymous eSIMs, but they come with their own trust questions. Digital and convenient generally means logged and linked.
The one option that actually gets you off the leash
So what do you do? There is a spectrum, and it is worth being honest about each rung.
An anonymously purchased physical SIM helps at the point of sale, but the carrier still logs your continuous location, still records your metadata, still pairs the IMSI to the IMEI, and patterns can still re-link it. Necessary, sometimes, but not sufficient.
The option that genuinely removes the leash is the one people forget is available: no SIM at all. A phone with no SIM has no IMSI to broadcast, generates no call detail records, and gives the carrier nothing to log, because it is not on the carrier’s network. You run it WiFi-only, over networks you choose, through an anonymous VPN, and you communicate over serverless, no-identifier messaging rather than phone numbers. You give up the convenience of cellular, always-on mobility and a dialable number. In exchange, you are simply not a subscriber to the surveillance system that Salt Typhoon just ransacked. For a device whose entire purpose is to stay unlinked, that is often the right trade.
This is a first-class way to run one of our phones, not a hack around them. Because our devices are de-Googled and do not force a SIM or an account, a WiFi-only build with an anonymous VPN and serverless messaging is a supported configuration, a phone that never speaks to a carrier at all. And if your situation genuinely requires cellular, we help you get connectivity as anonymously as the reality allows, and, just as importantly, understand exactly what the carrier can still see so you are not fooling yourself.
The honest scope
This is the fourth link in the chain: source it clean, pay for it clean, activate it clean, and then decide, deliberately, how it connects, because the SIM can quietly undo the other three. The device can be built to make going SIM-less or minimizing the carrier’s role easy. The choice of whether to accept the leash is yours, and it should be a choice, not a default you never noticed you were making.
The last link is the subtlest of all, the way your devices give you away by simply being in the same place at the same time. That one gets its own post. If you want a phone that can genuinely operate off the cellular leash, and clear-eyed guidance on the trade-offs of every connectivity option, that is what we do. Email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.