Swarmshop
| Primary URL | Location | Industry | Undetermined |
Country
—
|
Commercial
|
|---|
Profile
Swarmshop operates as an underground carding marketplace that facilitates the trade of stolen payment card data, online banking credentials, and personal identification information such as Social Security and Social Insurance Numbers. The platform provides a venue where administrators, sellers, and buyers can exchange illicit financial and personal data. Its core service is the distribution of freshly harvested credit and debit card details to cybercriminals seeking to monetize the information. By focusing on card‑related commodities, Swarmshop serves a global clientele of fraudsters and identity thieves.
In March 2021, a cyberattack on Swarmshop resulted in the public release of a database containing over 600,000 stolen payment cards, associated online banking credentials, and nearly 70,000 Social Security or Social Insurance Numbers. The breach also exposed administrative, seller, and buyer records, including nicknames, hashed passwords, contact details, and transaction histories, affecting more than 12,000 individual users. Researchers verified that the leaked data consisted of fresh information rather than recycled material from an earlier incident. The scale of the disclosure underscores the volume of illicit data that Swarmshop was handling at the time of the attack.
The incident highlighted Swarmshop’s specialization in current, non‑recycled carding data, distinguishing it from markets that rely on older dumps. It occurred amid a broader wave of attacks targeting similar underground platforms, with observers noting speculation about possible retaliatory motives behind the intrusion. The attackers released the database without providing any explanation or demand, simply making the information publicly available. No public details about Swarmshop’s ownership, parent company, or subsidiary structure have been disclosed in the available sources.
