All episodes
EP 029The Defenders Log

Decoupling Digital Identity: Beyond Carrier-Level Defense

Mark Kreitzman, GM of Ephani

Decoupling Digital Identity: Beyond Carrier-Level Defense

Why Your Phone Number Is the Ultimate Cyber Target—and How to Secure It

In a recent episode of The Defender’s Log, host David Redekop sat down with Mark Kreitzman, General Manager at Efani and a 25-year cybersecurity veteran, to discuss an overlooked enterprise threat vector: mobile network infrastructure.

The Illusion of Carrier Security

Despite decades of network upgrades, legacy telecom protocols like SS7 remain vulnerable during international roaming or over older 3G networks. However, the most pressing threat to modern phone security isn’t just network protocol exploits—it’s social engineering.

Major carriers rely on automated, low-friction port-out portals that allow fraudsters to swap SIM cards with minimal verification. Attackers leverage AI and automated reconnaissance tools to map stolen credentials from frequent data breaches, targeting standard phone numbers to bypass multi-factor authentication (MFA).

Turning Personal Vulnerability into Protection

After falling victim to a sophisticated SIM swap attack in 2017—despite having strict carrier security protocols on his account—Kreitzman pivoted his focus to mobile security. He joined Efani, a secure mobile service provider designed specifically to eliminate carrier-level social engineering and unauthorized port-outs.

Efani protects high-risk individuals and enterprise executives by decoupling digital identity from standard cellular networks. Key elements of this security posture include:

  • Minimal Data Footprint: Efani avoids collecting personal identifiers like Social Security numbers or birthdates, insulating customer data from carrier breaches.
  • Human-Centric Verification: High-risk account operations require rigorous, multi-layered human verification instead of automated approvals.
  • Financial Assurance: Services include up to $5 million in insurance coverage against SIM swap losses.

Securing the Enterprise Attack Surface

To mitigate mobile vulnerabilities, security leaders should audit executive BYOD policies, enforce strict hardware security keys (such as YubiKeys) for critical accounts, and encourage hygienic email compartmentalization across all corporate and personal platforms.

Full episode of The Defender’s Log here:

https://www.youtube.com/watch?v=GLpU4-J8dIA

TL;DR

  • Guest: Mark Kreitzman (25+ year security veteran, GM at Efani).
  • The Problem: Major carriers accept SIM swap risks to avoid the cost of human-verified port-outs. Attackers use AI and breached data to target phone numbers as MFA bypasses.
  • Legacy Risks: 2G/3G SS7 networks are mostly turned down in the US, but international roaming still poses protocol vulnerabilities.
  • Kreitzman’s Catalyst: He was SIM-swapped in 2017 via a rogue phone store employee, leading him to build Efani.
  • Efani’s Solution: Decouples identity from carriers by withholding SSNs/birthdates, requiring 11-layer human verification for transfers, and offering $5M in SIM swap insurance.
  • Key Advice:
    • Use hardware keys (YubiKeys) instead of SMS for MFA.
    • Keep ultra-private emails exclusively for financial and critical accounts.
    • Don’t abandon old phone numbers; park them or convert them to VoIP lines to prevent hijackers from taking them.

Links

View it on YouTube: https://www.youtube.com/watch?v=GLpU4-J8dIA

Listen to the episode on your favourite podcast platform:

Apple
https://podcasts.apple.com/us/podcast/decoupling-digital-identity-beyond-carrier-level-defense/id1829031081?i=1000786979995

Spotify
https://open.spotify.com/episode/58l2XxgHIw6BjdH7zWB6PI

Amazon Music
https://music.amazon.ca/podcasts/d7aa9a19-d092-42a6-9fe9-9e8d81f68d30/episodes/f40fe0fd-2486-4ea0-b1c9-0a01d34ace93/the-defender%E2%80%99s-log-podcast-decoupling-digital-identity-beyond-carrier-level-defense

ADAMnetworks
https://adamnet.works


The Defender’s Log full transcript - Episode 029

Introduction

Announcer: Deep in the digital shadows, where threats hide behind any random byte, a fearless crew of cybersecurity warriors guards the line between chaos and order. Their epic battles? Rarely spoken of until today. Welcome to The Defender’s Log, where we crack open the secrets of top security chiefs, CISOs, and architects who’ve faced the abyss and won. Here’s your host, David Redekop.

David Redekop: Today on the Defender’s Log, we’re joined by Mark Kreitzman, a veteran cybersecurity entrepreneur with over 20 years of experience building and leading security companies. And Mark’s career spans two decades of defending enterprise environments, including co-founding and scaling companies, whose technology was acquired by giants like Microsoft and Cisco Systems.

And after falling victim to a sophisticated SIM swap attack in 2017, despite having every carrier security protocol in place, Mark turned a personal vulnerability into a professional crusade, and he pivoted entirely to mobile security. So today, he serves as a general manager at Efani. Did I pronounce that right, Mark?

Mark Kreitzman: Efani, yes. You got it. You got it close. Yeah. Efani.

David Redekop: Good. A secure mobile services provider designed specifically to eliminate carrier-level social engineering, unauthorized port outs, and mobile identity theft. I am not a stakeholder in Efani, but I did sign up for the services myself to validate this because as an executive, I am concerned about my threat model. And anyway, Mark, welcome to the Defender’s Log. Good to have you.

Mark Kreitzman: Thanks for having me. I appreciate it.

The Journey into Telecom and Cybersecurity

David Redekop: I’m always interested in the background story of someone who has put this much time and effort into a space and still wakes up, sometimes in the middle of the night, to continue the passionate work. Tell us your background.

Mark Kreitzman: My background, so I was one of those lucky people where I caught the computer bug because my father was a high school teacher, and he bought one of the first Apple computers. And from that point on, when I was super young, I just got hooked on it. And, my college degrees, my undergrad and my master’s, are in technology, MIS, and information systems.

So I landed in the right field, had the right degrees. And, I used to be a hobbyist, and I was a really good programmer, and so that came in handy. But, when I was in my master’s program, AT&T hired me about nine or ten months early, and they waited for me. But they gave me an offer, and we agreed, and they waited for me.

And, I joined AT&T. I was super young. I was probably an average of 20 to 22 years younger than all my peers, and I was lucky enough to start out in, the first organization I started out in AT&T was the SS7 organization, which is an important protocol in the telecom space and mobile.

And again, in my early 20s, I was put in a position where I was helping manage the backbone of what was MCCAW Cellular right before it became AT&T Wireless. And so I was one of the first people, 22, 23 years old, with a mobile phone, like very first couple of months that came out.

But I got to see the inside of some mobile backbones, big customer backbones, and that was really like it wasn’t exactly like where I really wanted to be because it was like a deep operations. But it was a great background for eventually getting into cybersecurity and that’s a whole another story.

What had happened was I had worked for the telcos for about eight or nine years, and I was working in the middle of Silicon Valley, and everybody was just asking me, “Well, how come you’re not jumping to any of these companies that are all these stock options?” We’re going crazy and bartenders were joining companies where they couldn’t even spell the name of the company, and then all of a sudden they’re worth one, two, three million on paper.

But I couldn’t join at the time, it was late ’90s, because they all looked so horrible to me when I would look at them. I couldn’t understand what they were doing. And in the end, it turns out, they’re all selling to each other. But when that whole thing burst, then there was some winners that came out, and that’s where I eventually jumped into the cybersecurity business. I left the security of the telcos to go be the 29th, 30th employee of, and work directly for one of the co-founders of an enterprise email cloud-based security solution.

I think, that was around 2001 when I joined that company. So at this point, I’ve got about 25 years in cybersecurity, and about 12 of those now have been almost pretty much dedicated to mobile out of that. And it’s the one space that nobody can escape, right? Because absolutely everybody in the world in business has a mobile phone. So it’s one of those uniform attack surfaces to a degree.

The Vulnerabilities of SS7 and Mobile Networks

David Redekop: SS7, talk to us about how it is that we simply cannot shake that protocol completely.

Mark Kreitzman: Yeah. Well, we’re getting close to it. So SS7 came out, it was invented in the mid-’70s. And then, it was deployed in the late ’70s, early ’80s, it was the signaling whenever you called an 800 number or when you called somebody, it was basically just the signaling to tell the networks how to connect the path together.

But the problem was is that the protocol grew and it was being used all over the world, but it wasn’t built with security in mind and it wasn’t encrypted. And so you couldn’t just wake up one day and just change it because then all of a sudden the whole world could not communicate with each other. There’d be so many issues, and so it just had to stick around.

Then, when mobile came out, mobile had to use SS7 and of course 2G and 3G were primarily just SS7 signaling on its own. And so originally, the mobile networks were very vulnerable to network-based attacks. But the carriers have made a lot of upgrades, especially in the US over the last 10, 15 years.

So, one, is that all the carriers in the US have now turned down their 2G and 3G networks. And so those were primarily SS7. Those were where it was vulnerable and that things like IMSI catchers and Stingrays could break down the signaling and potentially be able to manipulate or collect that kind of data. But those have been turned down. It doesn’t mean it doesn’t exist.

But, now the SS7 is in the US is primarily carried over what’s called SIGTRAN. It’s basically an IP version. It’s SS7 over IP. But it doesn’t mean that it’s completely secure, it just means that it’s more secure. But it still does exist, and it exists because AT&T, Verizon, T-Mobile, US Cellular, they all have to talk to each other. It’s used a lot for like billing information.

And then there’s carriers around the world from, especially from like the Third World and Second World-type countries where 3G still exists. And, you can’t really do anything about SS7 on that end. It’s mostly gone in the US but on the other end. So, when you’re traveling overseas, you wanna try and stay off 3G. It still does exist. And it’s one of the reasons why Efani provides a, our own global data eSIM for high speed, but we can talk about that one later.

But SS7 is much more secure in the sense that it’s just not used nearly as much as it used to be. LTE and 5G are using Diameter instead of SS7. And then LTE and 5G use masking protocols for like the IMSI number. And LTE provides rotating masking numbers for your IMSI number, and then true 5G, it’s no longer called an IMSI number at that point, it’s just like a customer profile ID, but encrypts that.

And even that type of security is getting much better. And so the network side of things have cleaned up somewhat. Now, there’s still the social engineering, which is a major gap. But it doesn’t mean the carriers are all secure. It’s still heavily monitored and data’s being collected and so we all have to be careful about clicking on the wrong links and opening up the wrong images and so there’s still definitely a lot of vulnerability.

David Redekop: Yeah, for sure. Yeah, at the protocol level, that’s one of the areas of interest that I’ve always had because of the ease of Stingrays being able to capture someone’s communication that’s not on LTE or better. In fact, might be of interest to you, when I signed up for your services, I was actually a passenger while my son was driving in rural Ontario, and as I’m going through the activation process, all I have is 3G.

I’m like, “Oh, darn.” So we are not at a place where the SS7 or the 3G networks are turned down completely yet. We still rely on them a lot. And our workaround, or my workaround is to, basically unless I need cellular to be on airplane mode, and run over my Starlink, that is mobile in the vehicle, because oddly enough you get better security that way and better call quality.

So we have arrived at a weird and wonderful place. If we had projected ourselves to the present 10 years ago, we’d be dumbfounded as to how we’d be operating safely, when we’re out and about.

Mark Kreitzman: Oh, yeah. Even myself, I use Wi-Fi calling whenever there’s Wi-Fi available, just because it just avoids the whole cell tower altogether and just makes it a SIP call of it’s an encrypted. Our cellular service, the voice is VoLTE encrypted. But the SS7 on the SMS over SS7, that’s where it can be vulnerable.

A Personal SIM Swap Nightmare

David Redekop: So I’m really interested in your own experience of your SIM swap attack. Can you tell our audience about how that happened? Because it’s not like you had an insecure posture to begin with. So how did your own victim experience play out?

Mark Kreitzman: Yeah, when I got mobile hacked. I had about 18 years of building cybersecurity companies, and I’m a techie. I wasn’t like this sort of salesy guy with no tech skills. I’m somebody that’s coded in 10 plus different computer languages and I lived cybersecurity inside of networks for big carriers. And so I definitely am, I would put myself in the top 1% of cybersecurity experts, and here I was, I got mobile hacked.

And so when it happened, I couldn’t believe it, for one, but they got me in the desert of Arizona. They got me when I was driving between Tucson and Phoenix, and anyone who’s been in that area, it’s north-south, dead straight. It’s all dirt. There’s no payphones out there. I was by myself, driving to my parents’ house, and at first I’m like, “Please, I hope the cellular networks just don’t have coverage for these couple miles.”

And then as I drove, I’m like, “I hope my credit card on file, maybe I just forgot. Maybe the card expired or something.” And I just ended up just driving to my parents’ house, and, of course my father was happy to see me, but I had just, “Out of the way, I got an emergency.”

Called the carrier. They think I’m the hacker, I’m calling in, I’m like, “Hey, my mobile account hasn’t been working for the last hour.” And then they said, “It took extra verification, because now they think I’m actually the nefarious person.” So I get verified, and it turns out that somebody had ported my number out for 61 minutes and then ported it back.

Now, I didn’t even know they could port it back. I didn’t know that could even be done. And I had my profile set up that to make any change to my mobile carrier whatsoever, my account, I had to be in a physical store with my driver’s license and my passport. Because I knew that these, these things can happen, and so I thought, “Well, that’s gonna cover it.”

And I had to trick another third-party store to find out what actually happened, because the carrier’s going to liability protection mode. They don’t try and protect the nefarious person, but when they go into that mode, they end up protecting them more than they protect you because now they’re trying to protect themselves from a lawsuit.

But I had to trick another third-party phone store when I was visiting up in South Lake Tahoe, and I ended up getting the employee’s ID with the promise I was gonna send him a thank you card because they helped me so much. And, they innocently gave me the employee ID, and it turned out to be somebody out of Memphis, Tennessee.

And I’m a West Coast person. I haven’t been in Tennessee in 12, 13 years. And, so somebody just randomly picked my number and when I confronted the carrier after three months, when I finally figured out who did it and what store, that’s when they told me, “Oh yeah, what happened was that it was their last day at work and they picked three people to SIM swap, and you’re one of those lucky people.”

But for those three months I couldn’t sleep. I would wake up at 3:00 in the morning, 7:00 in the morning, 4:00 in the morning. I’m looking, I wanted to make sure that I had LTE in my phone, so I became very paranoid that somebody would steal my mobile number at 11:00 PM after I’m sleeping, and then port it back at 5:00 AM.

And if they were good, then, they cover it up. They potentially could do that. But, yeah, I didn’t use Wi-Fi for three months. But during that timeframe, I tried to escape actually cybersecurity because I did get a little bored and I just started to get into crypto.

And I started to get into Bitcoin, so that may have made me a target. And so I looked around to see who has anyone claimed that they’ve solved this? And every solution out there was, like, reactive, which is meaningless. If something tells you then you’ve been SIM swapped afterwards, then it’s meaningless.

And so I found one person who claimed that they did. It turned out that they were building one of the biggest Bitcoin ATM networks with a couple of their friends. And this SIM swap solution was a side project for him. He wasn’t taking it serious. He did it for himself because he got SIM swapped multiple times, and then a couple of his friends wanted it.

And then here I came along, and I’m like, “Man, I have never been this angry in my life.” I am literally every day, I can’t sleep. I started getting bags under my eyes and it started making me sick of having to worry about this. Yet, I relied on it, because I relied on my mobile phone for everything, all day long into the evening.

I was trying to do my own startup and I said, “This is what I do.” We hit it off after three or four or five calls, and he’s like, “Okay, let’s do it.” The first thing we did was change the name from Don’t Port to the name of Efani. That was a test name for about 30 days, and after 30 days, we just got used to it, and it was like, “Yeah, we can’t switch.”

The last thing I checked when we were trying to decide, I looked up Efani in slang words and it had words associated like enlightenment, things like that, and then we couldn’t give that up at that point. It sounded too perfect. And our seven-year anniversary will be within the next, I think, four or five months.

And so it’s been a long road. I definitely would have never woken up and thought like, “Hey, I think I’m gonna start a secure mobile carrier,” if I didn’t get mobile hacked. And if I didn’t have the background I had at the time, I would have never done it. I would’ve just been an angry person and just moved on.

but it just so happened to be very lucky that I got mobile hacked with all the years in telecom and all the dedicated years to mobile security. Because pri- right prior to that, the last startup I was at was a startup that provides the security behind T-Mobile’s solution for consumers, like the VPN and the smart VPN that they offer.

And now Efani resells AT&T and Verizon, so in one sense, I’ve got all three carriers covered with my contribution to cybersecurity in the telco space.

How the Mobile Industry Got Here

David Redekop: Well, it’s amazing that a very negative experience that we encounter very often ends up being the, what’s the word? The catalyst to actually move us towards changing it for everybody, right? It’s how a lot of movements have started, is because somebody was impacted so deeply to the tune of not being able to sleep for three months.

But let’s take a step back for then for a moment, because attackers basically treat phone numbers as the ultimate authentication bypass. And maybe you can just recap how is it that our industry got to that state to begin with?

Mark Kreitzman: Yeah. So the mobile industry in particular invests everything up front. So their investment is on the marketing, getting you to buy their mobile service, buy their phone, finance their phones. But on the back end, when you wanna leave them, there’s no humans involved in that.

And so the reason that this, the industry is vulnerable is because, like, Efani has portals where we can move customers from any carrier over to Efani. And so do all the other MVNOs and resellers and independent phone stores, and of course the carriers and their stores and their customer support has access to these portals.

And maybe you didn’t think about this when you moved over to Efani, but we didn’t have to call your carrier and say, “Hey, do you approve this?” And you probably didn’t call your carrier. At least you don’t have to. You don’t have to call your carrier and say, “Hey, I’m gonna cancel this service.”

You provide a couple pieces of information over, we enter that into a portal, and it just magically ports over. And so the way that the industry is built is they’ve done the math to say that we’re going to allow a percentage of fraud to happen, and then we’ll deal with that because we’re gonna save so much money by not having humans involved when somebody leaves us.

So they’re perfectly happy to have customer support, when they’re trying to sell you a kind of new feature or add global roaming and the day pass for $10 a day. But when it comes to leaving them, then there’s really no humans involved. And it’s one of the reasons what Efani has done is we flip the model, like our sales resources are super tiny.

The Growing Threat of AI and Data Breaches

Mark Kreitzman: And we’re lucky in the sense that every time there’s a data breach the SIM swaps start up, the attacks start coming, the spam of emails and SMS start to come in. Like there was just, in the last five days, there’s been two crypto wallets that have had data breaches.

Trezor itself didn’t get hacked, but their third-party shipping company was breached like around 12,000 of their customer records. And then SafePal’s another one where they got hacked in, they had a breach of almost 40,000 customer records back in April, but they just announced it yesterday, and that’s typical for a lot of the companies.

They get breached, but then they wait a couple months to deal with their attorneys and how they’re gonna cover this and then publish it. But it’s not just crypto companies. It’s AT&T, T-Mobile, Verizon have all had their massive data breaches over the last six or seven years.

They’ve paid massive penalties for it. And we’re talking tens of millions of customer records. And, at this point, there’s a data breach somewhere in the US pretty much every day. Like there’s websites that are built just to track all the data breaches that are happening, and it’s like 18 months ago, the company that does all the background checks on all the US citizens.

If you’ve ever had a background check on yourself, your father probably did, your family members probably did. So like generations of people’s data got breached when that company lost over a billion records. So it was a couple generations of background check information. So it’s unfortunately as a US citizen, we don’t really have data privacy anymore.

David Redekop: Oh my goodness. This is not a comfortable conversation to have because as much as I am still in the day-to-day operationally, in day-to-day in cybersecurity, to hear that this problem is still growing day by day, it reminds me of how much of a pattern we have in other industries too, right?

Like for example, the banking system, especially in Canada, they clearly have done the bean-counter math to say that we’re not gonna offer proper 2FA until enough breaches happen that make the equation so that the support cost around implementing proper 2FA is less than the breaches that we’re gonna get for not doing MFA properly, right?

And, that seems to be still a way off. Kudos to you because one of the first things that gave me confidence is that the only way I could properly, not the only way, but the preferred way I could properly MFA, my Efani account was with a YubiKey. And, we are all about sovereign pass keys whenever possible, especially for something that can become the initial point of attack, is those things like your password manager, your mobile account authorizing any transfers out.

And by the way, I transferred or I’m in the process of transferring from T-Mobile to you, so clearly T-Mobile’s security has also been strengthened because something to do with my account would not allow me to get the transfer out pin. And so at the moment I need to physically visit a T-Mobile store in order to authorize that transfer out.

So they must have experienced enough problems to say, “We better put some kind of hurdle in place before it can be transferred out.” So,it gives me a little bit extra confidence.

Mark Kreitzman: Yeah. Yeah. Every couple years they are continuing to add layers. But the problem is there’s insiders, there’s bribery, there’s like impersonations that are just done so well. So somebody could impersonate you in a store, for example, to do this. And then hopefully the store catches them, but a lot of people don’t really realize that the most of the phone stores are actually independently owned. And so you’re relying on their ability to hire the right person and manage and monitor and it’s nearly impossible to do that.

But yeah, the carriers, and you may have added like an extra, you may have added that extra feature, which is good to have. If T-Mobile offers that, then anybody listening to that’s on T-Mobile should probably go into their account and check that box.

David Redekop: I did some time ago, checked every box, like what you had done proactively, make sure that this number is it’s not my day-to-day phone. It’s a different phone, so that I don’t mix my regular daily use with really important SMS-based MFA, where that’s the only way it can be done. And I don’t advertise it. I don’t have it on any business cards, and the phone never gets answered. So it’s not like I had a bad security posture to begin with.

But allowing this to happen, especially hearing your story now that you were just randomly chosen, that’s scary. I’m often thinking about I will be targeted, so therefore I need to really have a strong posture. But to be randomly chosen, that’s in a way even more scary. Because if someone does a random choice, it probably means they’ve got a pretty decent mechanism of compromise.

And especially nowadays with AI aggregation, we’re now reading about how attackers are now leveraging AI more effectively than defenders. And so when you have the combination of data breaches and AI aggregation, how are attackers now leveraging that?

Mark Kreitzman: Yeah. Well, to give you an example, would be like there’s now innocent AI tools that are like just simple like lead gen sales tools, where you can actually point this at somebody or a group of 100 people, 1,000 people, and it’ll go out and gather all the information about what are all the numbers, the profiled to this person.

What are all the mobile numbers, landlines, emails? And it can find emails that you might have forgotten you even had 10 years ago. But it can find emails where you think you’ve done a good job hiding it, but it somehow gets profiled to you. And so if somebody can learn what emails you’re using, they can go to the top 10 banks in Canada or US, top 10 cryptocurrency exchanges, online wallets, down the line, and then take all those email IDs and just use the forgot password and see what kind of response they get.

And so a lot of pre-work can be done with AI and then just simple manual efforts. But AI, of course, AI could even automate that further, where if it knew seven or eight of my email addresses, AI could probably go out to like the top 10 of pretty much every service provider that potentially somebody like me could use, and then just go and check and just say forgot password and record all those kind of responses.

Does it ask for a SMS code? Does it ask for an authenticator app? And then have the pre-work done on somebody and so people have to a couple things people can do for free without, you know, even having to get Efani and VPN, things like that, is just be aware of like the email IDs you’re using.

Because one of the patterns is somebody will use an email ID that they sign up for their bank or they sign up for Coinbase and they use that for their cable company, and then they also use that to email family, friends, or sign up for like website to get free access to free tools and things like that, not really thinking about the fact that is their login on a lot of applications.

And so that’s one piece. And these the hackers that are using the forgot password, they don’t care if you’re using a nine-digit simple password or whether it’s 18 characters long and the most complex because they’re just using this, the forgot password. And so a lot of this is really hacking the human.

I think a lot of people, they don’t really follow like the sort of the hacking space. They, I think, get the idea that it’s more about them hacking into like your Android operating system or hacking into like the carrier itself and trying to collect information about you from the carrier.

But, we have so much information like on the applications we use and so much information we volunteer up on our phone, our contact list and just on the phone could make you vulnerable and we’re just volunteering our information all over the place. And so you wanna have a set of data, like email IDs that you use when you’re just doing freebie stuff and when you’re just emailing family, friends, and doing anything public, and then have this very, very private set of emails, where you don’t even ever link it.

You don’t send one email from one email over to one of your more public emails. Just make them very private and you’ll keep them private for at least longer than otherwise. And it should help.

Underestimating the Attack Surface

David Redekop: Yeah. There’s, unfortunately, nobody can get away with not having some level of education, right? And, the amount of cybersecurity education on your own attack surface needs to be aligned with what you stand, what you risk losing. And I would argue, I have a sister that works in healthcare, and her Microsoft email was compromised, and it wrecked her in so many ways that we never foresaw would ever happen.

And this was just a personal email that was tied to everything, right? To PayPal, to banking, but also personal, to your point, that should be separate. So, I know SIM swapping gets all the headlines, and you’ve touched on a couple of other threats. What other vulnerabilities should we be concerned about that, especially as enterprise security teams that may be underestimating the attack surface?

Mark Kreitzman: Yeah. When it comes to enterprise, I think I’m starting to see a trend of more companies, at least in the executive ranks, sort of the C-suite, where they’re going back to company-provided devices and mobile service. Because most of them have had a BYOD-type strategy, so they’re paying for their own phone, they’re paying for their own mobile service, and maybe they get subsidized by the company and paid for it on the side.

But these can be like Trojan devices, where they go into work whether they’re at the office or at home, they’re authenticating in. And then that device, whatever’s on that device, if it’s infected, it could potentially be causing damage and collecting data in- inside of the network.

Yeah. And so I would think that for companies, I’m seeing this trend of going back towards providing the devices and the mobile service and making them only work-related, especially in the financial space. And I think that every company has to worry about phishing attacks.

And, this would be your simple email or your simple SMS or somebody sends one of your key personnel or an executive an image and it’s got a hidden pixel in there and it’s a tracking pixel. Or it grabs information, a couple bits of information off the phone that allows them to potentially come back and SIM swap them or use that in an nefarious way later on.

And there are examples of corporations having some very big damage done. Like,Marks & Spencer is a great one, I’d like to point out, and this was just last year. A middle manager, somebody that happened to have something to do with Marks & Spencer’s IT division, got his mobile account stolen away, and then the hacker or hackers then used that to impersonate him inside of Marks & Spencer.

They got an IT password reset, and that allowed them access to submit ransomware, and they took over the point-of-sale devices for Marks & Spencer. And it cost Marks & Spencer around €350 million. And you can Google that and I’m sure I’m close to it. It’s somewhere around €350 million. And that was a simple SIM swap, and that’s not the only example of that.

What gets the headlines is that Marks & Spencer lost €350 million on a hack, and then when you read through the article, you find out that it actually started from a mobile SIM swap. And there’s a digital asset exchange out of Manhattan that about three years ago, same thing happened.

The right guy got SIM swapped, and they got into the backend systems of their platform. They deleted all the customer, their customers’ historical transactions, stole all their customers’ personal information. They didn’t steal any money, but the loss of confidence. They tried to recover.

They put a bunch of money into security, and they hired a new CISO. I actually got to do two video calls with their new CISO, a high-level guy, big name, and they’re trying to save themselves, but they couldn’t. And, within two years, they just did not get over the loss of confidence that people had. People moved their value out of there, and then they just never moved it back.

Decoupling Digital Identity: The Efani Architecture

David Redekop: There are certain mistakes that only need to be made once that cause a massive amount of destruction. And avoiding that SIM swapping scenario is really the focus of this episode. And, I think one of the areas of value that our listeners will receive is if you could talk a little to the architectural, the layers of changes that were required for Efani to go through in order for that protection to actually work.

Mark Kreitzman: Yeah. Great question. So a lot of people will think, or they say to me, for example, “You have this great technology,” and they picture that we’ve got these racks of servers, like around the US or around the country, and we’re almost the opposite. We’ve actually stripped everything out.

There’s no free Hulu, there’s no free Netflix, no free Disney Plus. I don’t even know if that exists anymore. But that’s data profiling. They can profile you. They’re gathering your personal information, your personal habits, and of course, people from those organizations or somebody rogue can then sell that data and use it against you.

So we’ve cleaned that out. So there’s no freebies on the side with us. One of the things that’s different about Efani versus the carriers is a lot of people don’t realize when they purchase from the carriers that it’s basically a credit account. So they got your birthday, they have your Social Security, your payment information, your personal information, address, and all of that.

And that’s one of the reasons why you’re vulnerable is because people can impersonate you by phone off your account, leave the store, call the support from a phone that’s on your account, like the device IP will match to what’s on your account. And they can move one of the mobile numbers over.

So we’re not selling phones, we’re not financing phones, and in fact, when you sign up with us, the underlying carrier is not giving your personal information. So we don’t even collect your birthday or Social Security. So the only thing we collect is payment info and verification info, but we’re not collecting your birthday, Social Security.

And then the information we’re giving to the carriers, you’re gonna look like you’re an anonymous executive, that you’re part of this team, and that the information like the address and things is like our address. And so you’re looking like anonymous executive of using like one of our addresses, and so that adds a little privacy from prying eyes at the carriers.

But in terms of the security we’re providing is we’re doing it all, it’s all human-based. And so we have 11 layers of protection for the risky transactions, and so some of those are very obvious. That would be like what email do you use on file? What payment method do you use? It will send you a text to make sure you still control the number.

If it’s one of the risky transactions that requires all the layers, then we’ll do things like, “We just sent you a credit to your payment method.” Not telling you exactly what it is, just saying, to make sure you have control of your payment methods and you have access to that.

“We just sent you an email. Can you please read that? Or when you get to it, respond to it?” One of the differences between Efani and another carrier or your traditional carriers is they wanna verify you right on the spot. And so if you don’t know your PIN number, they’ll just say “Oh, okay, Mark.

We’ll verify you another way.“ And with Efani, if we tell somebody like, “Hey, we just texted you and sent you an email,” if they have to leave the phone and call us back. So we’re the opposite of the carriers. They put no investment of humans on the back end. But with Efani, we have very few sales, barely anything.

But when somebody wants to do a risky transaction, that’s where the team is. Or if somebody wants to port out, that’s where we’re like zeroed in on that. That’s mainly where our human efforts are going inside of Efani. And so our model depends on providing good service. So you’re gonna end up with a concentration of executives that really care.

David Redekop: So you almost become an even more hyper-valuable target yourselves because of the customers that you have, right? You have to absolutely do that. But I just had a light bulb moment that this literally is what you’re doing is literally decoupling your digital identity from the vulnerability of a cellular network.

That decoupling is, in effect, from what I understand now, the single biggest value that you provide, because that decoupling is what makes any potential attack against my AT&T eSIM card or Efani SIM card, or eSIM card completely. It adds a whole new layer of difficulty for an attacker to ever compromise.

Mark Kreitzman: Yeah, and then you add in the motivation that we have. So we offer all of our customers a line of insurance that covers up to $5 million in losses due to a SIM swap. And so we’re not just promising, we’re not just saying like, “Hey, we’re gonna guarantee this.” When somebody wants to port out or they wanna move their phone, that insurance policy is like, that’s what we’re defending.

And because we’re gonna defend that insurance policy from ever being utilized, then you’re secured because of that. And that’s our motivation. Our motivation is that’s our reputation. We wanna make sure that’s never been utilized. And so you’re right. It is the decoupling of that direct relationship and the stores and potentially resellers having access to your information.

But that motivation is a big part of what we’re doing and why we do it and why we work so hard to keep people secure. I don’t wanna say lucky in one sense, that myself and the CEO, we were both mobile hack victims. And that adds a lot to it as well. Like this is not a business where you wake up and go, “You know what?

I think it’d be a great idea to go create a secure mobile service.“ Without having the experience that we had, it is literally one born out of being, so angry and not being able to sleep, and then that’s what is a big driver for the both of us, and then that carries on down towards our team as well.

Best Practices for Phone Numbers and Security

David Redekop: Yeah, this is actually a wonderful complement to our approach to a program that we call The Quiet Walker, which is all about reducing the digital breadcrumbs left online via your connectivity by introducing a strict egress control on device with an always-on VPN tunnel that exits some other place.

And there are risk profiles that really beg for that kind of protection, because if the Marks & Spencer storyline is something that is part of your exercise of walking through, what would our environment look like if we got attacked and you go through that tabletop exercise, really every organization should be able to identify the weak links that are in the enterprise.

And I would suspect that a good chunk of that would be concentrated in the area of that mobile device. And, our baseline as well is that it needs to be a corporately managed device. Apple Business Manager is a base starting point for iPhones because unless you have the ability to use mobile device management, the end user can easily be tricked and socially engineered into doing whatever.

What I love is being able to tell our sons, “When you get a text message with a link, go ahead and click on it.” I’m curious what they’re trying to do because we’re confident enough in that egress control not allowing them to go somewhere where they shouldn’t be going to begin with.

And, what’s amazing to me is how often they actually receive messages that are relevant to an area of their interest, right? It could be a shipping notification when they are actually expecting an Amazon package, right? It could be around tax time, of course. It could be around they’re all paying their income tax and expecting the refund to happen during the middle of the calendar year and so forth.

I know those campaigns are broad brush because of seasonalities of them, but the amount of times that it is very specific to their area of interest, but it boggles my mind because they keep a very small OSINT footprint. So there clearly is a massive amount of data, where I’m leading with this, that is not publicly known that has been breached, but is being closely held by these attackers that are obviously making use of this combination of data breaches and AI aggregation in order to deliver highly targeted phishing, smishing, vishing attempts that we just absolutely have to stay incredibly vigilant on every and every respect.

Mark Kreitzman: Yeah. Speaking of like high-value target, just to give you an idea of the lengths that people will go to, there’s a big name investor, his name’s Michael Terpin, and about six years ago, seven years ago, he got mobile SIM swapped, and some 15-year-old kid stole $24.5 million from him. And then that same 15-year-old kid got this other guy named Rob Ross for like 1.8 million. And he happened to be working with a couple other older guys that ended up talking too much and they all ended up getting in trouble.

But Michael Turpin, after all these years, he took those numbers and he held them, he parked them. And it’s been seven years later, and then there’s like a personal detail about this, but those numbers ended up getting released back into the wild just literally a couple months ago.

And somebody from that hacking team that got him before had waited the entire time and then grabbed his numbers, and then recently an article came out that was blackmailing them. So there’s certain things that were still attached to those numbers with like his business side of things after all these years.

So if you’re like a big target, we always get asked, “Should I give up my number and get a new one?” And we always tell them that, “Hey, this is like the risk. Your number could go into the wild.” It goes into this sort of escrow period, and then somebody could, if the wrong person grabs it, then you gotta make sure like everything’s detached from it, the internet the banks don’t know you from this number anymore.

Just because you gave up that number and you switched out your account, like online, the data brokers and everything still may associate that number with you, and it’s easier to impersonate somebody. And so for the big targets like that, these guys are like even waiting seven, eight years to grab numbers that, you know, from that long ago.

David Redekop: That seems kinda crazy.

Mark Kreitzman: Yeah.

David Redekop: Attackers like repeat customers too, right? We see this constantly over and over again. So my second last question was for you to articulate the importance of people not dropping their numbers completely, or if they do, to be 100% certain that it’s been decoupled from everything.

Think about how many people’s individual address book you are in, that may never get changed. So it’s one of those things if you accumulated a phone number, you probably should not get rid of it. Hang on to it. So I have a specific plan that I’m not gonna disclose on a podcast here today on what I wanna do with my numbers, in the approach of starting fresh in order to have a far superior strategy.

But, I’ll run that by you offline later and make sure that it lines up with the wisest approach.

Mark Kreitzman: Yeah. I can tell you with one of my old numbers, I turned it into a VoIP number.

David Redekop: Okay. There you go.

Mark Kreitzman: And then I ended up because I’m a crazy sort of person. I code on the side, I ended up creating this nice little sort of VoIP solution for myself, and so I could actually take that number and I put it in my LinkedIn profile.

And so that way I still own it, I’m still protecting it,and somebody can message me, text me there, leave me a voicemail there. But I would say that if you wanna give up a number, I would park it or turn it into a VoIP line.

Final Wisdom for Defenders

David Redekop: Yeah. Makes sense. Love it. Mark, I usually have a very final question around wisdom that you would like to impart upon others that maybe wasn’t captured in any question yet today. What is one piece of wisdom you’d like to leave with, other current and future defenders?

Mark Kreitzman: Okay. Does it have to be related to cybersecurity?

David Redekop: I’m assuming it does not have to be related to cybersecurity at all, just wisdom in general for the defender space.

Mark Kreitzman: Okay. Well, because I’m in cybersecurity and that’s my life, it’s a lifestyle, it’s not really a job, I’ll keep it to that.

But I would say that just a reminder to everybody, whether you’re an executive, whether you’re just a mom at home, that be very careful with the information you share, information you volunteer. Things like you take a picture of you and your daughter at a park, or you go visit a lake or something and you post that, send it to some friends, there’s metadata that gets carried with that, so like the location, the time, the date.

So if any of you are listening to that or some people think, “Well, I got hacked.” Well, it’s because they most likely just got ahold of one of your recent pictures and looked at the metadata. But just be very careful about what you’re sharing these days, because there’s gonna be no guardrails in some cases, and it’s just gonna be AI coming after all of us, and that’s a scary thought.

But, the more information that you volunteer out there, the more difficult it is to find yourself. And if you’ve got something to lose, you know, money, reputation, get blackmailed, your social media account, your hosting account for your own business, payroll, things like that.

I’ve talked to so many victims, where all that’s been destroyed by just a simple SIM swap. So be wary of people that are close to you, people that work for you, work with you. Sometimes they, insiders, can be doing this as well, disgruntled employees. And you say something online that’s not politically correct, and it may get somebody to target you just from that, and that’s just the world that we live in these days.

David Redekop: Keeping a very low profile just reduces your attack surface, right? That makes sense to me.

Mark Kreitzman: Yeah, I wish I could, but, I’m one of the most high-profile, not in the sense of being this big financial target, butI’m all over the internet.

David Redekop: Yeah. Well, you and I have chosen to be public about podcasting on purpose because it’s good business to be able to be discoverable for a third party to assess your authenticity. At the end of the day, character shines through in a podcast, in an interview.

But yes, the downside of that is that your voice or my voice could very easily be cloned in about five seconds, and it’s very difficult for someone to discern from that, especially as AI only keeps on accelerating its quality and capabilities more each time.

Not just audio, but video as well. The amount of video that we’re seeing now on personalities that have published enough high-quality content that can then easily be faked is quite remarkable. But then the next generation is very good at detecting that. So,there are still elements of it’s too smooth, too perfect with the way all this goes, so.

Mark Kreitzman: Yeah, but, you’re right. People buy from people, and that’s one of the reasons why I like to build awareness for people, because when you connect that person, they’re not just going to some website and thinking like, “Well, are they gonna be out of China? Are they gonna be out of Belarus?” Or some nefarious person somewhere in the world, or maybe even in the US. But, definitely people still buy from people, so that’s a good thing.

Outro

David Redekop: Mark, thanks to you and Efani. This has been a real enlightening experience for me to go through the process of protecting one of my really important phone numbers, and I appreciate that. I look forward to a long and safe journey with you, and I will connect with you again in the future.

Mark Kreitzman: All right. Thanks for having me. Appreciate it. Take care. Bye-bye.

Narrator: The Defender’s Log requires more than a conversation. It takes action, research, and collective wisdom. If today’s episode resonated with you, we’d love to hear your insights. Join the conversation and help us shape the future together. We’ll be back with more stories, strategies, and real-world solutions that are making a difference for everyone.

In the meantime, be sure to subscribe, rate, write a review, and share it with someone you think would benefit from it, too. Thanks for listening, and we’ll see you on the next episode.