According to an analysis by NordStellar, SIM-swapping services are available on the dark web for as little as $300 USD, often bundled with stolen identity data.
Cybersecurity experts from travel eSIM app Saily, together with NordLayer Intelligence by NordStellar, a dark web monitoring service, analyzed discussions about SIM swapping across underground forums. The social engineering attack involves transferring a victim’s phone number to a SIM card controlled by the attacker, allowing criminals to intercept SMS-based authentication codes and reset passwords.
According to the data collected, a single SIM swap is offered on the dark web for as little as around $300 USD. Average prices range from $1,000 to $1,300 USD. At $2 to $20 USD, the SIM card itself is one of the least expensive components of such an attack.
The analysis is based on dark web data collected from criminal forums and Telegram channels between August 2025 and August 2026. Only prices that included a currency alongside a numerical figure were considered. The median was used to calculate the average in order to avoid giving excessive weight to outliers. The prices cited were provided by the vendors themselves and were not independently verified.
Increasingly Sold as Complete Takeover Packages
Rather than selling individual SIM swaps, vendors are increasingly offering complete packages that also include stolen identity data, known as “Fullz,” a forged ID with a selfie, and stolen online banking credentials. These full account takeover packages are offered for up to around $2,000 USD.
Matas Cenys, Head of Product at Saily, describes the development as follows:
“In the past, a compromised SIM card was the entire attack, but today it is just one part of it. Criminals sell everything needed to assume a user’s identity. Once the number is swapped, the user’s identity and banking access are very likely to end up in the hands of the same buyer.”
Matas Cenys, Head of Product at Saily
Underground Forum Activity Is Increasing
Over the past year, researchers counted more than 1,150 mentions of SIM cards and more than 400 mentions of SIM swaps across relevant forums. The number of SIM-swap mentions increased roughly fourfold during the period. The offers are not limited to a specific country or mobile carrier. Forum vendors advertise their ability to take over SIM cards regardless of the carrier or country, including by exploiting weak identity verification procedures.
Criminals often call the mobile carrier directly and request that someone else’s phone number be transferred to a SIM card they control. Success largely depends on how much information the attackers have gathered about the victim beforehand.
In addition to exploiting corrupt employees, attackers are increasingly using AI-powered tools to extract publicly available information and quickly build up a victim’s digital footprint. When victims post updates in real time, the timestamps can be matched against records held by mobile carriers, making it easier for attackers to impersonate the victim.

How to Protect Against SIM Swapping
Cenys recommends several measures to protect against SIM-swapping attacks:
- Use multi-factor authentication and avoid SMS-based authentication. Authentication apps and hardware security keys provide stronger protection than SMS-based methods. Mobile carriers can also enable port-out locks and enforce stricter identity verification when transferring phone numbers.
- Visit a mobile carrier store in person if you suspect an attack. This allows you to verify your identity and stop the attack.
- Be cautious about sharing travel information on social media. Attackers can use such information to convince mobile carriers that a personal visit to a store is not possible.
- Follow basic cybersecurity practices. Do not click suspicious links, be skeptical of urgent requests, and avoid reusing passwords.
(Editorial Team/Saily)