Mind the SIM: Awareness and Mental Models in a South Korean Case Study

要旨

Mobile phone numbers function as single keys to banking, government, and commerce, making the Subscriber Identity Module (SIM) a critical element of security. In April 2025, South Korea’s largest carrier experienced a SIM breach that compromised authentication keys and exposed nearly 27 million subscriber identifiers. We conducted semi-structured interviews with mental-model elicitation (N=33) to examine user awareness, responses, and understanding of SIM-based authentication. Results reveal a pronounced awareness–action gap: participants recognized the breach yet held incomplete mental models, perceived little personal risk, and rarely acted protectively, even when affected. Learned helplessness, reliance on carriers, and the invisibility of SIM shaped these passive responses. Brief educational interventions improved conceptual understanding but seldom produced lasting behavioral change. Our findings demonstrate how technical opacity and psychological factors jointly inhibit protective action and offer design implications for usable security, emphasizing interventions that realign users’ mental models with system risks to foster sustainable practices.

著者
Hyunsoo Lee
KAIST, Daejeon, Korea, Republic of
Seyoung Jin
Sungkyunkwan University, Suwon, Korea, Republic of
Hyoungshick Kim
Sungkyunkwan University, Seoul, Korea, Republic of
Uichin Lee
KAIST, Daejeon, Korea, Republic of

会議: CHI 2026

ACM CHI Conference on Human Factors in Computing Systems

セッション: Human Factors in Privacy, Security, and Trust

P1 - Room 117
7 件の発表
2026-04-14 18:00:00
2026-04-14 19:30:00