Security Confidential S19 E10 Mark Kreitzman

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Mark Kreitzman. Mark is a cybersecurity leader with more than two decades of experience building security companies and protecting organizations from emerging threats. Mark is currently the Chief Cyber Evangelist at Efani, where he’s focused on securing one of the most overlooked attack surfaces we all carry every day: our mobile phones. After becoming the victim of a SIM swap attack, Mark turned that experience into a mission to educate others about mobile identity theft, privacy, and why your phone may be your biggest cybersecurity risk. 

00:00 Intro

05:20 Mark’s Journey into Cybersecurity and Mobile Tech

10:45 The Dot Com Bubble and Mobile Industry Evolution

13:37 Legal Challenges and Industry Liability in SIM Swapping

18:32 Why Industry Costs Make Security Expensive

12:15 The Role of Social Engineering and Insider Threats

25:47 Impact of Mobile Hacks on Major Institutions

29:54 Global Mobile Coverage and Wi-Fi Calling Features

33:11 Cost Comparison: Efani vs Major Carriers

40:00 Special Offer for Listeners and Future Topics

Transcript

Manoj Tandon: Hello everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential. We have another great guest today. I have to remind you, please hit the like and subscribe button. It helps us out quite a bit, and it allows us to keep bringing this great content to you. Today, we are fortunate to have Mark Kreitzman join us. Mark has more than two decades of experience in the field. Currently, he is the Chief Cyber Evangelist at Efani, and he is on a mission to educate others about mobile identity theft, privacy, and why your mobile phone may be your biggest cybersecurity risk. As you have heard on this show before, it probably is one of your biggest cybersecurity risks, if not the biggest. Without further delay, Mark, thank you for joining us. It is an honor to have you here.

Mark Kreitzman: I love that introduction. I am very happy to be here, and I am looking forward to this.

Manoj Tandon: We love learning a little about our guests’ origin stories. Tell us how you got into not only cybersecurity, but this entire space in general, and how you became an entrepreneur. We would like to get a little background.

Mark Kreitzman: I would have to go back a very long way. I was one of those lucky people whose next-door neighbor, my best friend’s father, bought the first Apple computer that came out. I was a little kid typing on it and entering BASIC code from an insert in one of the computer magazines to create a game. That is how I first got into it. My mind just works very well with computers. I have never really taken computer classes, but I can program. I put myself through college by programming and writing in about four different languages as a consultant while I was going to school. I paid my way through both my bachelor’s and master’s degrees by programming, even though I did not end up with a computer science degree. The way I fell into the industry was that only a couple of months into getting my master’s, AT&T came in and hired me. They actually had to wait almost a year for me to finish. It was because of my technical skills. I did not want a career in computer programming, but they hired me for those skills. I got into telecommunications very young. I finished my master’s at an early age and came into AT&T at a time when they were laying people off. That was a whole different experience—being in my early twenties while people around me were simultaneously being laid off and making comments about whether I was going to attend the Christmas party. It was a very unique time, but I stuck through it and got to see the inside of AT&T. I was part of its SS7 organization in my early twenties.

Manoj Tandon: Signaling System 7.

Mark Kreitzman: Exactly. A lot of people do not even know what SS7 is, but it is Signaling System 7. Here I was in my early twenties, and my peers were probably 50 or 52 years old. I was this young guy coming in. A couple of years later, I was in a group that helped manage the backbone of the air-to-ground stations. If you remember the airplanes where they used to have a phone you could pull out with the stretch cord, I worked with that infrastructure. I got to see the inner workings of mobile before AT&T Mobile even existed. I was troubleshooting issues in the backbone of McCaw Cellular before it became AT&T Wireless. Through that process, I ended up moving to Northern California. AT&T gave me the full relocation package and everything. I watched the dot-com bubble blow up around me, and I could not understand the business model of most of those companies. That ended up being lucky because I watched it all implode. That was when I decided to jump in. Once it completely imploded, I started seeing that some companies were going to emerge from it.

Manoj Tandon: Wow.

Mark Kreitzman: I worked for Microsoft for 365 days and five minutes before putting in my two weeks’ notice because I wanted to go back and do the same sort of thing. I joined an enterprise web security company very early, and then Cisco Systems bought it. It became the primary web security solution Cisco offered to businesses. I went off and did another one, and then, in the middle of everything, I was mobile-hacked in 2018. I was trying to build my own startup. I was attempting to enter the cryptocurrency and mobile app spaces because I was very familiar with mobile by that point. I had been in mobile security for about seven years, but I wanted to do something on my own. Then I got mobile-hacked, and it brought all those memories back. I was hacked while I was in the middle of the Arizona desert, where there were no phones around. For the entire drive between Tucson and Phoenix, if you have ever been in that area, it is basically one highway going north and south.

Manoj Tandon: I have driven that road many times.

Mark Kreitzman: There are no payphones out there. Your options are to eventually find a Costco or something and beg someone to use their phone, or drive all the way to your parents’ house. I drove to my parents’ house, and when the Wi-Fi connected, six password-reset notifications appeared on my phone. It turned out that a third-party phone store employee in Memphis, Tennessee, was involved. It took me about 90 days to determine what had happened. I had to trick the carrier and another third-party phone store into giving me information. It turned out that they had ported my number out, reset passwords for 61 minutes, and then ported it back to try to hide what they had done. I did not sleep properly for a couple of months, until Efani was started and I got onto our own service. The company was not created because I thought, “I really want to start a mobile operator.” It was created because I was angry. I had never been that angry. At the time, I was just starting to get into Bitcoin, and I had 2.2 Bitcoin stolen. They also got into the hosting account for the startup I was building. It was embarrassing because I had 18 or 19 years of cybersecurity experience. I had configured my carrier profile so that no changes could be made unless I physically brought my driver’s license and passport into a store. All it took was a third-party phone store employee, three or four thousand miles away, lying to a computer. That person had no relationship with me. They probably saw me in a YouTube video or on a website and thought I would be a target.

Manoj Tandon: Do you think that third-party employee might have just been a mule? They may have been used by somebody else and paid a couple hundred dollars.

Mark Kreitzman: That is normally how it works. They have a friend who works at a phone store, or they pay that employee $300 or $3,000. There are SIM-swap forums where people can target individuals. An employee with access to a target’s account might say, “Send me this amount of Bitcoin, and I will do it.” The reason I know it was a third-party employee is because of how I tricked the store. I went to a third-party store while I was in South Lake Tahoe and told them, “This employee really helped me. I thought I had lost my phone, and they switched my SIM card. I promised I would send them a gift card, but I never did. Could you tell me which store it was? I travel a lot.” They instantly looked it up on the computer and gave me the employee ID of the person who did it. The ID contained enough of the employee’s name that I could match it through a Google search and find their social media accounts. I called the carrier and said, “You have been lying to me this entire time. I know which store it was, and I know who did it.” That was when they told me it had been the employee’s last day and that the employee had SIM-swapped three people. I was one of the unlucky ones. Until then, they had been in liability-protection mode and refused to give me any information. I filed a police report, and the police called the carrier’s law-enforcement hotline. The carrier still refused to give them any information and said they needed a subpoena. I would have had to hire an attorney and obtain a subpoena simply to find out what had happened to me. That is the nature of how these carriers work. When your mobile account is stolen, they go into liability-protection mode. Through that process, they often protect the hacker more than their own customer because they do not want to be sued or provide information that would enable you to sue them.

Manoj Tandon: Exactly. A couple of years ago, there was a case in New York involving a private individual who had approximately $16 million in Bitcoin stolen. That is the number I remember, although I may be wrong. A group of teenagers committed the theft after convincing a telecom employee to move the victim’s mobile number to their phone. They compromised the multifactor authentication, reset passwords, gained control of the victim’s Bitcoin account, and moved the money into their own accounts.

Mark Kreitzman: The attacker was a 15-year-old kid working with another adult who was around 23 or 24. The victim was Michael Terpin, and he had approximately $24.5 million in Bitcoin stolen. There was also a man named Rob Ross, who was unrelated and did not know Terpin. The same 15-year-old SIM-swapped him and stole about $1.8 million in cryptocurrency, mostly Bitcoin. That represented a substantial amount of his life savings. I have met both of them. Rob Ross actually consulted for us for a while, and I met Michael Terpin in person at the Bitcoin conference in Miami Beach. Listening to Rob Ross talk about having to sit down with his daughter and tell her that her college education was gone was difficult. He is a very smart guy and had a great career, so he was eventually able to recover. Both victims sued the carrier.

Manoj Tandon: That is the case I was talking about, and the outcome was disturbing. I just looked it up. It was Terpin versus AT&T Mobility. In that case, the court essentially said AT&T’s liability was limited to damages connected to the value of its contract, such as the fees paid for mobile service. The breach-of-contract damages were limited, and the fraud and punitive damage claims were thrown out. Here was a person who lost millions of dollars, while the company that enabled it incurred only hundreds of dollars in liability.

Mark Kreitzman: I have been asked to serve as an expert witness multiple times. Attorneys call Efani, get connected to me, and say, “I have eight victims. I would love to have you as an expert witness for all of them.” One attorney told me that the carriers’ defense was essentially that SIM swapping had become normalized across the industry. Their argument was, “This happens across all carriers, so there is not much that can be done about it. Also, you are only paying $60 or $80 per month, so that should be the limit of our liability.” When you become a victim, you also discover that all the carriers have inserted arbitration clauses into their contracts. You end up in arbitration rather than a traditional court. Some people have been winning, but they may recover only 20, 30, or 35 cents on the dollar, and then they have to pay an attorney out of that. The carriers are trying to improve security, but they are also trying to eliminate their liability because they have calculated that fully securing and tightening everything would be too expensive. There are simply too many holes.

Manoj Tandon: Why is it so expensive to tighten things up? Why can you not force a situation where a third party cannot swap the SIM? If someone wants to make that change, why can the carrier not require them to verify their identification in person, go into a store with real ID, and prove who they are? Why can it be done over the phone? I am curious, Mark. What is the carrier’s reason? What is so expensive about it?

Mark Kreitzman: The way the industry is built is that all carriers provide portal access. There is a dashboard that authorized people can log into to make account changes. What many people do not realize is that most phone stores are independently owned. Someone might own only your local store, while another person might own 300 stores across Arizona or 800 stores across the United States. Those independently owned stores have portal access. The customer-support representatives you call through the 800 number have portal access. Resellers like Efani have portal access. If you give us just a couple pieces of information about your account, we can enter that portal and move your phone number to Efani without us having to talk to your carrier and without you having to speak directly to the carrier. You do not verbally approve it. You simply provide a couple pieces of information, and the change can be made. Carriers have invested heavily in their networks and their sales operations. They want to sell devices, lease agreements, and the newest and most expensive mobile-service packages. That is where the investment goes. When you want to leave, their attitude is, “You are leaving. We do not want to spend money on that. We do not even want to talk to you.” The portal access given to so many people makes it extremely difficult to enforce tighter processes. It is similar to why many banks and financial institutions in the United States still use SMS verification. People wonder why banks do not require YubiKeys or authenticator apps. Imagine the customer-support problems they would face when customers lost phones containing their authenticator apps. All of those expenses and burdens would fall on the bank. Instead, they decide to tolerate a certain amount of fraud and continue using an insecure verification method. Telecom companies have done the same calculation. It is cheaper for them to tolerate fraud in exchange for gaining more customers and revenue.

Manoj Tandon: The problem is that this is no longer just an inconvenience. It has real-life consequences, so those basic agreements should be nullified. It reminds me of a car company years ago. I cannot remember which company it was, but its vehicles were flipping over, and the company knew the design was defective. It still decided it was cheaper to pay the insurance claims than to fix the design flaw.

Mark Kreitzman: I remember 60 Minutes doing an episode on that. I do not remember the specific car either.

Manoj Tandon: Eventually, the company had a major problem and it cost them a fortune. At some point, a smart attorney is going to come along and successfully hold these carriers accountable. Mobile service used to be a luxury or an optional product. Now it is ubiquitous, and you cannot complete many transactions without a mobile device.

Mark Kreitzman: In many SIM-swap attacks, the objective is not necessarily money. It can be harassment, blackmail, or revenge. We have customers who were SIM-swapped before coming to Efani and moved their mobile service to us afterward. I get to hear all those stories. One customer and her boyfriend built an IT services company in Phoenix that sold equipment. They broke up, and the boyfriend SIM-swapped her because he had been paying for the mobile account. He used that access to destroy her entire business and push her into bankruptcy. I hear stories about people getting divorced and using SIM swaps against each other. People may think of me like a bartender because I have also been a victim, so they tell me more about their lives than you might expect. It is not just about money. Attackers can target your business. One of the major stories of 2025 involved Marks & Spencer. A middle manager in the IT division was SIM-swapped. The attackers used that SIM swap to impersonate him inside Marks & Spencer and obtain a password reset. They reset a password somewhere in the company’s IT environment, used it to load ransomware into the payment system, and took down the company’s point-of-sale terminals. It cost the organization approximately $350 million. An incident like that makes me wonder whether there was an insider involved. The attackers may have known that this employee had a certain level of access. It could even be someone sitting next to you who wants revenge. One SIM swap cost Marks & Spencer more than $350 million. There were also insurance companies in the United States in 2024 and 2025 where SIM swaps involving executives led to breaches of approximately 68,000 customer records. Attackers are no longer focused only on targeting individuals like you or me. They are increasingly targeting corporations, executives, middle managers, and key personnel. Once they take over those accounts, they can do enormous damage to someone’s life or an entire company. With bring-your-own-device strategies, many companies allow employees to pay for their own mobile service, purchase their own phones, and use them however they want. Those phones become Trojan horses if an attacker steals the employee’s mobile account or compromises the device and gains access to company applications. Mobile phones and mobile devices are becoming more important every day.

Manoj Tandon: They certainly are. I am surprised—although perhaps I should not be—that Congress has not stepped in more aggressively on this issue. I am sure the telecom lobby is very powerful.

Mark Kreitzman: The FCC has tried. It has told carriers to implement additional restrictions, but the problem is that you have insiders, bribery, impersonation, and people who are exceptionally skilled at social engineering. Those things are very difficult to prevent. There is a great video involving a woman who is a social-engineering expert at DEF CON in Las Vegas. She was paired with a reporter, and they sat at a table with a camera recording them. The reporter asked, “What are you going to do?” She said, “I am going to call your mobile operator.” He replied, “They have my back.” While they were filming, she played a YouTube video of a baby crying in the background. She called his carrier and said, “We got married a couple months ago, and my husband has been bothering me about getting my name added to the account.” In about 90 seconds, she added her name to his account and changed the account PIN. He had his hands over his face because he could not believe she had done it so quickly. She added a name and email address and changed the PIN. Then she thanked the representative and hung up. She could have waited two hours, called back, and no longer needed to trick anyone. She could simply call the 800 number and say, “This is Amber. Here is the PIN, and here is the email address.” It would no longer appear suspicious. These are the techniques attackers learn. Someone can go into a store and impersonate me. Suppose I use T-Mobile. They can enter one store, fail because the employee asks for a Social Security number, leave, drive three miles to another T-Mobile store, obtain whatever additional information they need, and try again. There was a news story four or five months ago, I believe in Texas, involving a woman who wanted revenge against another woman. By the time she was caught, she had visited approximately 122 stores trying to perform a SIM swap. People will go into stores and pretend to be you. They may exploit a salesperson’s incentive to sell a phone. Suppose I walk into a store and successfully impersonate you. I purchase a phone and add a line to your account. You may not notice until your next billing cycle. I leave the store and call the carrier’s 800 number from a phone and line that are now associated with your account. The representative sees that the phone and line are on the account, so I am already two or three steps into the verification process. I then say, “I want to switch the old number to the new phone.” Attackers use multiple stages of social engineering to catch people off guard. It is extremely difficult to stop when companies are selling and financing phones. Family plans are often the weakest link. Attackers do not necessarily have to impersonate you. If your daughter or spouse is on your family plan, they can impersonate that person instead. We have heard many stories like this. One of our customers was the co-founder of a cryptocurrency company. Before moving his service to us, he was on his father’s family plan. Someone impersonated his father and used that access to move the son’s mobile number onto a new phone purchased through the father’s account. The attackers then used the number to take over the company’s X account. It was a business account for their cryptocurrency startup. The attackers posted that the company was selling a new token and then sold fraudulent tokens to followers. In a case like that, whom do you sue? Is it the carrier, the attackers, or X? Anyone involved with Bitcoin may also remember what happened when the SEC announced the approval of the first Bitcoin exchange-traded fund. The announcement appeared early, but it was actually caused by a SIM swap. Someone at the SEC who managed the organization’s X account had their mobile account stolen. The attackers took over the SEC’s X account and announced that the Bitcoin ETF had been approved. They may have loaded up on hundreds of millions of dollars in Bitcoin, announced the approval early, watched Bitcoin rise by $3,000 or $4,000, and then sold it. A couple of hours later, the SEC discovered that the announcement was unauthorized. The entire event happened because someone stole the mobile account belonging to the person who managed the SEC’s X account.

Manoj Tandon: Wow. Does what you are describing also apply to the world of SS7? I am sure many people do not know about it, but could someone obtain access to an SS7 dashboard and, instead of swapping the SIM, tap the phone?

Mark Kreitzman: There are different things attackers can do. Efani stopped offering 2G and 3G in 2021 and moved to LTE and 5G only. SS7 is a protocol developed around 1978 or 1979 and implemented in the early 1980s. The problem is that it became a global protocol, so you could not change it without ripping apart the infrastructure that made everything work—landlines, 800-number routing, and other network functions. LTE and 5G use Diameter protocols, which removes approximately 99.9% of the need for SS7 in normal usage. That is one of the reasons we stopped supporting older technologies and moved exclusively to LTE and 5G around the end of 2021. The other carriers shut down their 2G and 3G networks between approximately 2022 and 2024, which significantly reduced SS7 exposure. There are still IMSI catchers, which can be homemade devices that intercept communications between a phone and cellular towers. Again, those primarily affect 3G and older technologies. When you use Efani, we operate as a reseller of AT&T and Verizon. We provide LTE and 5G service in the United States, Canada, and Mexico. We also provide optional high-speed data at no additional cost in more than 200 countries. We want all our customers to remain on LTE and 5G globally. If you are taking a vacation to Bali, visiting an island in Thailand, traveling to Australia, or going anywhere else for business or leisure, you want to stay on LTE and 5G because those are encrypted protocols using Diameter. It does not mean they are 100% perfect, but they are approximately 100 times better than old 3G networks using SS7.

Manoj Tandon: Tell us a little about Efani. Are you a telecommunications provider? Are you a registered phone company? What exactly is Efani?

Mark Kreitzman: We are what is known as an MVNO, or mobile virtual network operator. We resell AT&T and Verizon service, but we are a full MVNO in the sense that we own the accounts. Nobody at AT&T, Verizon, or anywhere else can directly modify our customers’ accounts. You can always go to AT&T directly, or you can receive AT&T service through Efani. The first thing we do when you port your number to Efani is unplug it from those third-party portals. Nobody on the planet can simply port your number away from Efani. You could give someone your passcode, address, and all your account information, and they still could not port your number out. Our verification is human-based. You have to go through our verification process. We have very few salespeople, but we have a team focused on risky account changes. When someone requests a risky change, we put a spotlight on it and conduct a verification process to make sure we are doing the right thing. Another difference is that we are prepaid, which means we are not required to perform traditional KYC. When you go to most carriers, you are essentially opening a credit account, and that is one reason your identity information is exposed. You have credit accounts with companies like Mint Mobile, T-Mobile, AT&T, and Verizon. Because we are prepaid, we operate under a different set of KYC laws. Technically, someone could use a gift card or anonymous payment card and purchase Efani service without providing their real name, although there are disadvantages to doing that.

Manoj Tandon: For our audience, explain KYC quickly. It means “know your customer.”

Mark Kreitzman: Correct. Traditional carriers have to know virtually everything about you. They have your payment information, Social Security number, birth date, and other personal information because you have a credit account with them. With us, you could technically use an anonymous payment card and sign up under a fictional name, but there are disadvantages. Some companies promote complete anonymity, but people should understand that if they use their mobile number for banking and switch it to an entirely anonymous identity—perhaps Batman or Batgirl—financial institutions may reject transactions. Banks such as Chase or Goldman Sachs pay third parties to assess the reputation connected to mobile numbers. If someone attempts a $50,000 withdrawal and the number is registered to “Batman,” the transaction may be rejected. We do have customers who use superhero names, but those individuals generally do not use SMS verification for financial institutions anyway. We tell most people that we will provide the carrier with only a limited version of their name so those reputation queries still work, but the carrier will not have all their personal information. We want to retain as little information as possible. We do not collect detailed call records or SMS records. We have a no-log policy. We may see that you made a certain number of calls or used a certain amount of data during a billing cycle, but we do not retain the detailed records. Our philosophy is that the less information we hold, the less information can ever be disclosed. Everything is encrypted, and we do the best we possibly can.

Manoj Tandon: Could someone bypass you? If you are reselling AT&T, could they go directly to AT&T and say, “This is an Efani customer. Give me the information associated with this number”?

Mark Kreitzman: People have tried. We have several customers who are professional penetration testers, and they conduct penetration tests against their own accounts. We do not recommend doing that because the carriers do not want to encourage people to try to deceive their systems, but attackers cannot bypass us by convincing someone at AT&T or Verizon to change one of our accounts. We have full ownership of those accounts. We also guarantee protection against mobile SIM swaps through an insurance policy that covers up to $5 million. We are motivated to protect you. You could simplify our business by saying that we provide global mobile service with a boutique, white-glove experience, and we want to make sure our insurance policy is never used. That policy stays behind us as a guarantee, and our objective is to ensure it is never needed. It is not simply because we love you as a customer—although we do value our customers. Our business and reputation depend on preventing that insurance policy from ever being triggered. Other carriers are motivated primarily to avoid complaints and apologies. If you are SIM-swapped, they may enter liability-protection mode. At Efani, our goal is to make sure the insurance policy is never used. We provide more than SIM-swap protection. There is also a privacy advantage because carrier stores, resellers, and other parties cannot access your personal information or modify your account. We do not sell phones, which closes one of the main gaps carriers have. We control customer support and monitor everything. Multiple employees must approve a highly risky transaction. Our business is built around keeping people safe. We also focus on keeping customers connected at high speeds globally and providing an excellent mobile-service experience.

Manoj Tandon: Are you targeting the average consumer or corporations? Who is Efani’s intended audience?

Mark Kreitzman: We are targeting people who have money to lose, reputations to protect, a risk of blackmail, or businesses that could be severely damaged. We have many executives spread throughout Fortune 1000 companies. Many of them work in bring-your-own-device environments. We have a lot of CEOs, including CEOs of cybersecurity companies, because if the CEO of a cybersecurity company gets SIM-swapped, it can make the company look foolish. They want to protect against that. We are also beginning to serve family offices and small and medium-sized businesses. We are a strong option for anyone who travels frequently. Even if you are a retired consumer who travels to Europe or Asia a couple times per year, our global travel service is valuable even without considering the security protections and insurance. One feature we provide is a dual-eSIM configuration. Your primary SIM might use AT&T, while your secondary SIM is our global data eSIM. If you have an iPhone 13 or newer—or technically an iPhone 12 SE, third generation, or newer—we enable Wi-Fi calling globally. If you land in Tokyo, you can receive calls to your Efani number through the data eSIM. To you, it feels like a normal phone call, but the phone is using the second data eSIM as the Wi-Fi connection. An iPhone 13 or newer essentially becomes a global roaming device. You can make unlimited calls back to the United States over that connection without traditional Wi-Fi. You could be in the countryside of Thailand, and your phone would still ring. You do not have to pay $10 or $12 per day or $100 per month for traditional roaming. With Efani, if you have a compatible iPhone and travel a couple of times per year, the service can be an obvious choice even before you factor in the security and insurance. There are only about 15 countries where this Wi-Fi calling feature does not work. They include places such as Iraq, Pakistan, and Dubai, which blocks Wi-Fi calling for some reason. In approximately 185 or 186 countries, we turn compatible phones into global roaming devices that are both secure and insured.

Manoj Tandon: From a cost perspective, how do you compare with AT&T or Verizon?

Mark Kreitzman: For individual customers, we have only one plan. Everything I have discussed so far is included in that plan. I have not mentioned any add-ons. It costs $99 per month, including taxes and fees. That includes the insurance policy, our security commitment and guarantee, mobile service, and global data coverage. Compared with AT&T, the people who sign up with us are not necessarily concerned about paying an extra $15 or $20 per month. They have something to lose, and they do not want to lose it. As a victim, I still experience something similar to post-traumatic stress from what happened. You do not want to become a victim. Many of our customers know someone who was victimized and understand the pain it causes. Whether the price makes sense depends on what you could lose and whether protecting it is worth the cost. Some customers tell us that they were already paying Verizon $115 per month. That may be uncommon, but there are people paying $150 or $180 because of roaming, international calling, and other fees. With our plan, you can add unlimited international calling for $15 per month, or pay nothing extra if you expect to remain within the included 500 minutes.

Manoj Tandon: Got it. That is fantastic. We are already at the end of our time. Is there anything you would like to promote or make sure our audience knows about?

Mark Kreitzman: We could probably talk for three hours about everything we do, including AI threats, mobile security, and cybersecurity in general. One thing I do want to mention is that we like working with people who educate others about cybersecurity, and we want to give something back to the community. You can receive a $99 discount on Efani by going to Efani.com/promo. If you go directly to Efani.com, you receive no discount, but if you go to Efani.com/promo, you receive $99 off. We also offer a 60-day money-back guarantee. If you reach the 59th or 60th day and feel that we have not met your expectations or the service does not work for you, you can request a refund. We are trying to make the process very easy. Beyond that, there is so much more we could discuss. I would love to come back, and we would not even have to talk about Efani.

Manoj Tandon: Mark, you are going to have to come back. We did not even scratch the surface. Thank you so much. I really appreciate you taking time out of your busy schedule to join us today.

Mark Kreitzman: Thank you as well.

Manoj Tandon: Take care.

Read more about Mark on his LinkedIn.

Visit Efani.com/Promo for $99 off the Efani SAFE Plan

Check out the vCISO bot we created

Check out the other episodes in Season 19:

Ep. 0 Diyar Saadi – How Hackers Exploit Hidden Vulnerabilities

Ep. 1 Krisztian Kiraly – Who Really Controls Your Algorithm Data?

Ep. 2 Jason Roos – What the U.S.–Saudi Relationship Means for Cybersecurity

Ep. 3 Jasson Casey – Identity Attacks Are the #1 Threat

Ep. 4 Andy Smith – What Good Is Cybersecurity Tech… If It Still Fails?

Ep. 5 Murphy John – The Future of Decentralized Data

Ep. 6 David Linthicum – Artificial Intelligence Mistakes Every Company is Making Right Now

Ep. 7 Bronwen Aker – Treat Artificial Intelligence like a Drunk Intern

Ep. 8 Yagub Rahimov – You Can Get Hacked With Emojis

Ep. 9 David B. Cross – The Future of Cyber Threats

Ep. 10 Mark Kreitzman – The Hidden Cost of Mobile Identity Theft

Mark Kreitzmans' profile picture for Dark Rhiino Security's Security Confidential podcast

Mark Kreitzman is a cybersecurity executive with more than 20 years of experience helping build innovative security companies, several of which were later acquired by Microsoft and Cisco.

Throughout his career, he has held leadership roles at OpenDNS, Mobolize, and Lattice Security, focusing on protecting organizations from emerging cyber threats.

Today, Mark serves as Chief Cyber Evangelist at Efani, a secure mobile service dedicated to preventing SIM swap attacks, mobile identity theft, and other phone-based threats.

After becoming the victim of a SIM swap attack himself, Mark made it his mission to educate individuals and businesses on why mobile security has become one of the most overlooked risks in cybersecurity.

He also hosts the Efani Features Podcast, where he speaks with security experts about today’s evolving digital threats.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host Manoj Tandon talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, YouTube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top