Mind the SIM: Awareness and Mental Models in a South Korean Case Study

Privacy by Design & User ControlPrivacy Perception & Decision-MakingExplainable AI (XAI)Mobile Payment UsersPrivacy Policy Makers

Paper Title

Mind the SIM: Awareness and Mental Models in a South Korean Case Study

Publication Info

  • Topic area: User awareness and mental models in SIM-based authentication security.
  • Keywords: SIM security, mental models, user awareness, authentication, mobile security, South Korea, data breach, trust, usable security, behavioral response.

Background and Problem

  • Problem / challenge: Despite the critical role of SIM cards in mobile authentication, users often lack understanding of their operation and associated risks. This knowledge gap exacerbates vulnerabilities, as seen in the 2025 SKT SIM authentication key breach in South Korea.
  • Significance: SIM-based authentication underpins essential services like banking, government access, and e-commerce. A breach in this infrastructure threatens financial security, identity protection, and public trust in digital systems.
  • Motivation and related work: Prior studies have focused on technical vulnerabilities and statistical breach analyses but have largely overlooked user perceptions, mental models, and behavioral responses to SIM-related security incidents. This study addresses these gaps by exploring user awareness and responses to the SKT breach.

Solution

  • Proposed approach: A qualitative case study using semi-structured interviews and mental model elicitation to investigate user awareness, responses, and understanding of SIM-based authentication in the context of the SKT breach.
  • Novelty:
    1. Real-world case study of a nationwide SIM authentication key breach.
    2. Identification of an awareness–action gap, where users recognized the breach but rarely undertook protective measures.
    3. Insights into user mental models of SIM functionality and their implications for usable security design.
  • Procedure and key techniques:
    • Conducted interviews with 33 South Korean participants (SKT and non-SKT users, aged 20s–60s).
    • Explored awareness, emotional and behavioral responses, and mental models of SIM operations.
    • Used a drawing task to assess participants’ conceptual understanding of SIM functions.
    • Provided a brief educational video on SIM functionality and collected post-session reflections.

Results

  • Concrete findings:
    • Limited awareness of the breach: Most participants described it as “being hacked” without understanding the exposed data or its implications.
    • Dominant concerns included financial loss (25 participants) and identity theft (20 participants).
    • Mental models varied widely, with only a few participants demonstrating accurate or detailed understanding of SIM operations.
  • Advantage over baselines:
    • Highlighted the disconnect between technical mechanisms and user perceptions, which prior technical studies did not address.
    • Identified specific psychological and cultural factors (e.g., learned helplessness, reliance on carriers) that inhibit protective actions.
  • Experiments / evaluation:
    • Participants included 17 SKT users and 16 non-SKT users, balanced across age groups and technical backgrounds.
    • Behavioral responses: 9 SKT users replaced their SIM cards, 2 enrolled in protection services, and 5 took no action.
    • Mental model analysis: Participants were categorized into low, mid, and high levels of understanding based on their drawings and explanations.
  • Limitations and future work:
    • Limited cross-cultural generalizability due to the focus on South Korea.
    • Retrospective self-reports may be subject to recall bias.
    • Future research could use longitudinal or experimental methods to track mental model evolution and evaluate interventions.

Summary

This study investigated user awareness, mental models, and behavioral responses to the 2025 SKT SIM authentication key breach in South Korea. Findings revealed an awareness–action gap, where users recognized the breach but rarely took protective measures due to limited understanding, reliance on carriers, and perceived low personal risk. Mental models of SIM functionality varied widely, with most participants holding incomplete or incorrect conceptions. Brief educational interventions improved understanding but did not consistently lead to behavioral change. The study highlights the need for security designs that make SIM processes more visible, provide contextual explanations, and reduce barriers to protective actions.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/222476/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3791714
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making, Explainable AI (XAI)
work
Professions
Mobile Payment Users, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
8 related papers