Taiwan warns travelers to check where eSIM traffic exits

August 11, 2026. Taiwan's National Institute of Cyber Security has told travelers to look beyond the brand name on a travel eSIM and check the company and network that actually carry its traffic. Its July 9 advisory says a phone can connect to a tower in the country being visited while the public internet connection exits somewhere else.
That distinction can affect account logins, banking checks, streaming, search results and connection delay. It does not mean every foreign route is unsafe. It also does not prove that an eSIM provider can read the contents of an encrypted message. The practical problem is that many travelers do not know the route before they depend on it.
The traveler decision: ordinary maps and messaging may work normally on a foreign internet exit. Before opening work systems, making a sensitive payment or relying on a location-restricted service, check the connection's public IP country and network. Follow an employer's approved connection policy when work data is involved.
What Taiwan NICS is asking travelers to check
The Taiwan NICS advisory focuses on two details that are often hidden behind a simple country plan:
- Who is behind the service? The brand selling the plan may use another company for the eSIM profile, mobile core or international data connection.
- Where does traffic reach the public internet? The internet gateway may be in a different country from the traveler and the local radio network.
For government and business trips, NICS advises against using a travel eSIM with an unknown provider or route for work email, internal systems, cloud storage or video meetings. It recommends using an organization-approved VPN and following the employer's reporting process.
For personal travel, the agency recommends watching for an unexpected login country, unusual account alerts and services that stop working because the connection appears to come from another region. It also calls for multi-factor authentication and prompt account checks after an unfamiliar alert.
This is narrower and more useful than saying travel eSIMs are either safe or unsafe. The right connection depends on what the traveler plans to do and how much the provider reveals.
What the USENIX travel eSIM study actually measured
NICS based its warning on the Northeastern University paper "eSIMplicity or eSIMplification?", presented at USENIX Security 2025.
The researchers bought profiles from 25 providers. They tested from one location in the United States over four months, recording public IP addresses, IP geolocation, the network attached to those addresses and repeated traceroute patterns. Most observed public IP locations did not match the phone's physical location. The paper's table includes exits associated with networks in the United States, Europe and Asia.
One widely reported example involved a Holafly profile whose observed address belonged to China Mobile International. The full research paper also records many profiles with public addresses in Texas, New York, Virginia, Poland, Denmark, Norway, Singapore and the Isle of Man. The finding is broader than one provider or one country: roaming traffic often returns to a gateway chosen by the underlying connectivity arrangement.
The paper separately studied reseller access, profile behavior and deletion failures. Those are important security questions, but they should not be collapsed into a claim that every foreign gateway caused a breach.
The limits matter
The measurements are a 2025 snapshot, not a live map of every package in 2026. They were run from one country, and IP ownership and routing can change. A provider may also use different suppliers for different destinations or even different plans on the same destination page.
Roaming eSIM was not listed among the 25 providers in the paper's table. This article therefore makes no claim about Roaming eSIM's public internet exit. The research supports a better question to ask; it does not supply a current answer for a plan it did not test.
A local carrier and a local internet exit are different facts
A travel eSIM connection has several layers. Mixing them up is the reason a phone can show strong local signal while websites see another country.
| Connection layer | What it tells the traveler | What it does not prove |
|---|---|---|
| Local radio carrier | Which mobile network the phone uses for signal | Where public internet traffic exits |
| eSIM profile or issuer | Which subscription identity is installed | That the seller owns the local network |
| Mobile core and roaming partner | Who authenticates and carries the data session | That every plan from the brand uses the same path |
| Public internet gateway | Which country and network websites may see | The phone's GPS position or full route history |
| VPN exit, when used | Which VPN address services see | That the cellular provider has no connection metadata |
The local carrier still matters. It helps with coverage-map checks and manual network selection. It is simply a different field from the gateway country.
Our Travel eSIM Network Disclosure Index measures the first layer. It deliberately does not infer routing, latency or privacy from a carrier name.
How an unexpected eSIM IP country can affect a trip
Most travelers notice routing through an inconvenience before they notice it as a security question.
Account and payment checks
A bank, email provider or work portal may compare the public IP country with the account's normal pattern. A sudden login from another jurisdiction can trigger an extra challenge, temporary block or security alert. The NICS guidance tells travelers to inspect these alerts instead of dismissing them as a harmless side effect of roaming.
Do not keep retrying a sensitive login after the service warns about an unfamiliar location. Confirm that the alert belongs to your own session, review recent account activity and use the institution's official support route if access remains blocked.
Streaming, search and local services
Streaming rights, shopping catalogues, search language and some local websites are selected by IP region. A traveler in Italy may receive a German or Dutch catalogue if the public connection exits there. A local ticket or government service may reject an address that appears to be outside the country.
This behavior is not proof that the phone's GPS is wrong. Apps can use GPS while websites use the public IP, so the two location signals may disagree.
Latency and live calls
Data that travels to a distant gateway and back can add delay. Messaging may feel normal while a video call, cloud desktop, game or hotspot-connected laptop feels less responsive. Congestion, radio signal and the destination server also affect performance, so the gateway is one possible cause rather than a complete diagnosis.
Ookla's newer Q2 2026 travel eSIM performance study now owns the detailed performance question. It covers the same-network 54 ms versus 543 ms example, loaded latency, speed caps and a post-arrival diagnosis without expanding this security advisory into a second speed guide.
Restricted services in mainland China
Foreign routing can be useful in mainland China because a roaming connection may reach the public internet outside the mainland. That is why some international services can work on a travel eSIM when they do not work on a local connection.
The useful outcome does not remove the transparency question. A traveler still needs to know which country and company handle the exit, whether work policy permits that route and whether a particular app treats the exit country as supported.
How to check an eSIM route after arrival
A public IP check is a practical observation, not a full security audit. Use it before sensitive work rather than treating the first successful web page as enough.
- Turn off Wi-Fi so the phone is definitely using the travel eSIM.
- Confirm that the travel eSIM is selected for mobile data and the home line is not carrying the session.
- Open a reputable public IP checker and record the country, network or ISP name and address shown.
- Compare that result with the country being visited and any route disclosure supplied by the eSIM provider.
- Open the service that matters and watch for a location warning, new verification step or region error.
- If the route is unexplained, ask support to identify the underlying provider and public internet exit for the exact package.
An IP country can be wrong because geolocation databases are imperfect. A single address also does not reveal every private hop. If the result matters for business security, the organization's network team should make the decision instead of relying on a consumer IP-check page.
Keep screenshots of the plan fields and the observed result. They give support a specific problem to investigate: plan, destination, date, local carrier, public IP network and affected service.
HTTPS, MFA and VPNs solve different problems
Modern websites and messaging apps normally encrypt content in transit. That helps protect the contents of a session, but the network still needs enough connection information to move traffic. The NICS advisory notes that connection time, location and the services contacted can remain relevant even when content is encrypted.
Multi-factor authentication protects the account if a password is exposed or a login looks unusual. Prefer an authenticator or passkey where the service supports it, and keep recovery codes available offline. MFA does not change the eSIM's route.
A VPN creates another encrypted tunnel and gives websites the VPN's public exit address. It can help when an employer requires an approved gateway or when a traveler needs a predictable region. It does not prove that the eSIM profile, supplier or reseller is trustworthy, and it does not erase all connection metadata from the mobile network.
For a work trip, use only the VPN and device configuration approved by the organization. For personal banking, follow the bank's travel and account-security guidance. Do not install an unknown VPN merely because the eSIM's IP country looks unfamiliar.
Roaming eSIM's verified transparency advantage

Roaming eSIM cannot claim a routing result that has not been tested. It can give travelers better information at an earlier layer of the decision.
The August 6 network-disclosure audit found that Roaming eSIM, Ubigi and MobiMatter tied a named local carrier to the exact offer in the checked United States purchase path. Five other sampled providers named carriers only at destination level, and two did not identify a US partner in the checked path.
The separate Roaming eSIM catalog census covered 2,842 destination-package observations. Every observation named at least one operator and included a network-speed field. Data, validity and top-up eligibility were also available at package level where supplied.
π Roaming eSIM wins the measured package-disclosure comparison: the traveler can inspect the local operator attached to the selected package instead of assuming every offer on a country page uses the same network. That is a real purchase advantage. It is not evidence of a local internet exit, low latency or a particular routing jurisdiction.
Roaming eSIM also publishes a public support hub, WhatsApp route and 24/7 support claim. Ask the route question before buying when it is essential: Which company operates this package's mobile core, and in which country does its public internet traffic normally exit for my destination?
The Travel eSIM App Privacy Index gives Roaming eSIM the strongest result in its separate ten-app Apple-label sample. That label concerns declared app data practices. It does not replace a network measurement.
Which Roaming eSIM plan fits the route?
The four cards below cover Asia, Europe, North America and a broader global itinerary. They are shown because the transparency check applies across routes, not because a regional plan guarantees a regional internet exit.
- Asia 20 Areas Roaming eSIM
- Europe Roaming eSIM
- North America Roaming eSIM
- Global 120 Areas Roaming eSIM
Open the selected card and check its current operators, speed, data allowance, validity, start rule, hotspot terms and reloadability. A country plan may be simpler for one destination. A regional plan can be more convenient across borders, but the broader label does not answer the gateway question.
The travel eSIM versus international roaming guide compares those connection methods. The eSIM settings guide covers the dual-line controls that prevent the home SIM from taking over mobile data.
Ten questions travelers ask about eSIM routing
- Why does my travel eSIM show an IP in another country? Roaming data may return through the profile provider's or supplier's gateway before reaching the public internet. The local tower and public exit are different layers.
- Does a foreign IP mean the eSIM is unsafe? Not by itself. It can be normal roaming architecture. The concern is whether the route is disclosed, suitable for the intended use and permitted by any work policy.
- Can the wrong IP country block streaming or local sites? Yes. Services can use IP geolocation for rights, language, fraud and access decisions.
- Can it trigger a bank or work login check? Yes. An unexpected region may cause another verification step or alert. Review the notice and use the provider's official recovery route.
- Is it safe to use banking over a travel eSIM? No connection type gives a universal guarantee. Use the official app or HTTPS site, strong account authentication and the bank's travel guidance. Avoid a sensitive transaction when the route or alert is unexplained.
- Will a VPN fix an unexpected eSIM country? A VPN can give services the VPN exit country and add an encrypted tunnel. It does not verify the eSIM provider or remove every network-level record.
- How do I check the route? Disable Wi-Fi, confirm the data line, check the public IP country and network, then compare the result with the provider's disclosure. Ask support about the exact package when the result matters.
- Does a named local carrier prove local routing? No. It identifies the radio partner, not the mobile core or public internet gateway.
- Can routing make a video call slower? A distant gateway can add latency, but signal, congestion, device performance and the call service also matter.
- Should a business traveler use a separate connection? Follow the organization's policy. NICS recommends avoiding an undisclosed travel eSIM route for work systems and using the approved VPN and reporting process.
Sources and updates
The July 9 NICS advisory supplied the news event and traveler controls. The USENIX landing page and full paper supplied the experimental scope, provider table, public IP observations, routing method and limits. The story does not use later summaries to widen the paper's claims.
Roaming eSIM's local-carrier result comes from the separate reproducible August 6 catalog and provider audit. This article did not test packet routes or public exits for Roaming eSIM.
Update policy: We will update this report if Taiwan NICS changes its guidance, the researchers publish a new measurement set, a named provider supplies a material correction, Roaming eSIM publishes verified internet-exit data or current account-security guidance changes.



