Travellers from the US and Canada face a growing risk of SIM card identity theft abroad, as criminals exploit mandatory prepaid SIM registration laws to harvest passport data from unsuspecting tourists, according to new research from travel eSIM provider Saily.
The research identifies a legal requirement operating across more than 160 countries and territories: before a prepaid SIM card can be activated, the purchaser must present a passport or government-issued identification. That obligation, originally designed to curb anonymous misuse of mobile networks, has created an opening for fraudsters who pose as legitimate sellers, collect travellers’ document details and then use or sell that data for criminal purposes.
How the SIM Registration Loophole Fuels Fraud
The scale of the regulatory environment is considerable. The GSMA, which represents over 1,000 mobile operators worldwide, has documented that SIM registration mandates now apply in more than 160 destinations globally. Several of the countries on that list rank among the most visited by North American travellers, including Thailand, France, Spain, Italy, Mexico and Australia. Travellers arriving in those markets and purchasing a physical SIM card should expect to hand over identification as a matter of course.
The problem is not the registration requirement itself, but where and to whom travellers surrender their documents. Vykintas Maknickas, chief executive of Saily, warned that street sellers and unofficial resellers outside airports and train stations present a particular risk. ‘Registering a SIM card serves a good cause. It helps combat criminal activity and prevent the misuse of mobile communications for illegal purposes. Nevertheless, criminals use this obligation to collect information from travellers’ passports and to make a profit at their expense. So, never blindly trust the first SIM card seller you see outside an airport or train station,’ Maknickas said.
Passport data exposed in a typical SIM purchase includes a traveller’s full name, date of birth, nationality and passport number. Saily notes that unauthorised sellers may photograph or scan those documents, then use the data to commit identity theft, open financial accounts or apply for credit in the victim’s name, or sell the images on the dark web. ‘A big risk is that travellers have no control over how their documents are scanned or how that data is stored afterward,’ Maknickas added. Pre-registered SIM cards, sometimes marketed as convenient or anonymous, carry a related hazard: Saily warns they may already be linked to another person’s identity, creating potential legal complications for the buyer.
Saily’s research, which focused on Canadian travel behaviour, found that 34% of Canadians still purchase local SIM cards while travelling abroad in order to reduce mobile data costs. The warning applies equally to American travellers, who frequently make the same trade-off.
SIM Card Identity Theft Abroad: Why eSIMs Are Being Recommended
Maknickas argues that the most reliable way to avoid SIM card identity theft abroad is to arrange connectivity before departure. ‘Many US and Canadian travellers assume a local SIM card is the cheapest and simplest way to get connected abroad. In many destinations, however, buying one also means sharing sensitive details, such as passport information, with a seller they do not know,’ he said. Installing an eSIM from a reputable provider ahead of travel removes the need to hand documents to an unfamiliar third party at all.
Saily, which is owned by Nord Security, offers data plans across more than 150 countries. According to a review published by NordLayer, the provider’s European plan covers 36 countries, giving frequent travellers to that region a single pre-arranged option rather than multiple in-destination purchases. That kind of pre-trip setup aligns with the core advice emerging from Saily’s research: reduce the number of touchpoints at which sensitive identity documents change hands.
For travellers who choose to buy a physical SIM card on arrival regardless, Saily recommends purchasing only from official mobile carrier stores, licensed airport kiosks or authorised retailers, confirming the SIM is registered in their own name, and monitoring bank accounts and mobile statements after returning home for any irregular activity.
Travellers who have purchased a SIM card from an unauthorised vendor in a country with mandatory registration requirements should consider placing a fraud alert on their credit file on returning home, given that Saily’s research documents cases where registration data has been abused to steal personal information.
