Your backup doesn't include your phone number
eSIMs are in no iPhone backup — not iCloud, not Finder. Transferring one needs the old device working. So the single case where you most need it back, a lost or stolen phone, is the exact case where nothing has it.
Facts cited
| eSIM in iCloud / Finder backups | not included, cannot be restored | consistent across Apple community and vendor documentation |
|---|---|---|
| Supported route | device-to-device transfer during setup | Apple: transfer your SIM or eSIM before setting up the new device |
| If the old device is gone | carrier must re-issue the profile | new QR code, identity verification |
| Why it's bound to the device | cryptographically bound to the eUICC's EID | GSMA SGP.22 — a profile issued for one EID is rejected by any other eUICC |
| Global life expectancy | 73 years | World Bank, 2023 |
Assumptions low → high
| What we can't measure | low | likely | high |
|---|---|---|---|
| iPhone users on eSIMeSIM-only hardware in some markets makes this rise every year. | 250M | 450M | 700M |
| Share per year who lose the old device before transferringTheft, loss, water, a dead board — any case where Quick Transfer isn't possible. | 1% | 2% | 4% |
| Time to get a number backIdentity verification, a new QR code, sometimes a store visit. Longer when the account's own 2FA goes to the number you've lost. | 1800s | 5400s | 14400s |
Who can fix it
- Owner
- Apple (backup scope & disclosure) · carriers (re-issue speed)
- Channel
- Apple Feedback Assistant · carrier support
You back up your iPhone. Photos, messages, app data, settings, keychain — all of it. Not your eSIM. It is in no backup, on any platform, and cannot be restored from one.
The supported way to move an eSIM is a device-to-device transfer during setup of the new phone. That works beautifully for a planned upgrade, when both handsets are on the desk. It requires the old device.
Which means the one scenario where you’d actually reach for a backup — the phone is gone — is precisely the scenario the mechanism doesn’t cover.
The steelman, and it’s real
There’s a genuine reason, and it isn’t laziness. Under the GSMA’s SGP.22 standard, a profile is cryptographically bound to the EID — the unique identifier of the device’s eUICC chip. A profile issued for one EID is rejected by any other eUICC. That binding is precisely what stops a profile being intercepted or cloned onto another handset.
So a freely backed-up, freely restorable eSIM would be a SIM-swap attack in a file — and SIM-swap is how people lose bank accounts. “Just put it in the backup” isn’t the fix; the thing you’d be backing up is the thing whose non-copyability is protecting you. Even if the bytes were in your backup, the new phone’s eUICC would refuse them.
A distinction that resolves most of the confusion: the profile can never move, but the entitlement — your right to a profile for that number — can. That’s what device-to-device transfer actually does: the old profile is deleted and the carrier issues a fresh one to the new EID. So any system that appears to “back up an eSIM” is necessarily storing the activation reference, not the credential. That’s a real and useful thing to store. It is also not what the backup screen currently implies, in either direction.
But the disclosure failure is entirely real
Granting all of that, two things remain indefensible:
- “Back Up Now” implies completeness. Nothing in the backup flow says “your cellular plans are not included.” A user reasonably reads a backup as “if I lose this device, this is what I get back,” and the omission is invisible until the worst possible moment.
- The instruction arrives too late to act on. Apple’s guidance is transfer your eSIM before setting up the new device — advice that only appears when you already have the new device, and is useless if the old one is at the bottom of a canal.
The principle: if a backup is incomplete, it must say what it omits — at backup time, not at restore time. A gap you learn about while recovering is not a disclosure, it’s a discovery.
Why the harm compounds
Losing a number isn’t losing a number. It’s often losing the second factor for everything else — banking, email, the carrier account itself. There’s a nasty circularity: re-issuing the eSIM may require verification sent to the number you can’t receive.
And the timing is malicious in the theft case: you’re locked out of SMS 2FA at exactly the moment someone else has your device.
The math
450M eSIM users × 2% lose the device × 5,400s = ~20 lifetimes / year
Hours on the phone to a carrier, proving who you are without the thing that proves who you are.
The fix
- Say it in the backup screen. One line listing what a backup doesn’t include. Difficulty: none.
- Prompt for a recovery route while the phone still works — carrier account details captured now, when capturing them is trivial.
- Carriers: make self-service re-issue real, verified by account credentials rather than by an SMS to the number in question.
What to do meanwhile
Because the fix isn’t shipping today: write down, somewhere off the phone, for each eSIM — the carrier, the account number or ID, the phone number, and the carrier’s re-issue procedure. That note is the backup Apple isn’t making. It takes five minutes now and replaces several hours later.
One unresolved conflict. Two eSIM-vendor blogs describe an iCloud “eSIM Backup” toggle and iOS 18 saving eSIM details to Keychain. This could not be confirmed on Apple’s own documentation and is not repeated as fact here.
Note it wouldn’t actually contradict EID binding — such a feature could only be storing the activation reference, letting a new device request a fresh profile automatically, rather than storing the credential itself. That’s coherent and would be genuinely useful. But whether it exists, and whether it ships on or off by default, is unverified. If it exists and defaults to off, this case changes character entirely: from an omission nobody mentions to a safety net built and left switched off — the same failure as case 025. Worth thirty seconds in Settings → Apple ID → iCloud to settle.
Difficulty to fix: easy
The security argument for not backing up an eSIM is sound. The argument for not mentioning it is that nobody wrote the sentence. One line, on the screen that promises to save everything.