My wife and I have been customers of Freedom Mobile since the end of the year. And I have to admit that one thing that does give me cause to pause is the Freedom My Account Web Portal located at https://login.freedommobile.ca. I say that because in the age of SIM swap attacks, I question if this web portal can adequately defend against a threat actor who wanted to do either or both.
First let me explain what a SIM swap attack is. This is where a threat actor takes over the SIM card on your cell phone by porting the number from the SIM card in your phone to a SIM card inside a phone that they have control over. Why would they want to do that? Well, if you have text message based two factor authentication set up, those authentication messages will now come to the threat actor’s SIM card instead of yours. Which means that if they already have your user name to a given online account that relies on two factor authentication, you’re pwned because they can reset the password to said account to get in, assuming that they don’t already have the password. If you want an example of how bad a SIM swap attack could be, take a look at this article written by Brian Krebs on a very large scale SIM swap attack that affected 130 organizations.
Here’s a couple of examples of why SIM swap attacks are dangerous. Late last year I wrote about telephone scams from threat actors pretending to be Rogers, TELUS, or Bell, offering great deals and a new phone to the unsuspecting. But in reality, what the threat actors were doing was that they were trying to get victims to hand over the two factor authentication codes that victims got via email or text message so that they can get into the victim’s account and order a new phone for shipment overseas. Now imagine if they could just focus in on the text message group by doing a SIM swap so they don’t even need to call you to do that. Or how about this? A threat actor does a SIM swap attack and is able to get the two factor authentication codes for your bank account. Then they proceed to drain your bank account dry. Clearly these are non trivial results of a SIM swap attack, which is why the security that telcos provide to stop these attacks need to be top shelf.
Now here’s why I question if Freedom Mobile is doing enough on this front. When you go to https://login.freedommobile.ca, you see this:

Here you will be asked to enter your Freedom Mobile phone number and a four digit PIN number that you chose when you set yourself up to access this web portal. Realistically, Freedom Mobile needs to have proper accounts with proper passwords. And have a password complexity requirement. For example, all passwords need to be a minimum of eight characters with one capital letter, a number, and a special character ($%#& for example). I say that because I can see a scenario where a threat actor who tries a credential stuffing attack by trying various combinations of the PIN number to see if they can get into the account. To be fair, I have not tested this which means that I have no idea if Freedom Mobile can defend against this attack. But seeing that only four digits are in play here, if I were a threat actor, that’s what I would try first as I have “only” 9999 possibilities to work with. Which from a security perspective is pretty weak.
The other thing that Freedom Mobile should do is move away from delivering the two factor authentication via text message. I say that because of this:

Once you enter your Freedom Mobile number and enter the PIN you get to choose the phone number that you want a text message with a two factor authentication code delivered to, and confirm that phone number.

Here’s where you get to enter the security code that you get via text message.
Now I will admit that there’s a lot of hoops that a threat actor would have to hop through to pull an attack on Freedom Mobile off. But as evidenced by the Brian Krebs story, threat actors if they are motivated enough and believe that there’s value in doing so will find a way to pull this sort of attack off.
But let me hand some free advice to Freedom Mobile to help them to kill off this potential attack vector. My current bank of choice is CIBC. Their mobile app has an option to receive verification codes via push notification rather than text. So if you try to log into the CIBC website, you’ll get a push notification on your phone as long as the CIBC app is installed on your phone. That does two things. First a SIM swap attack won’t work because it’s not tied to your phone number. Second, if your phone gets stolen you can kill push notification access to that phone. Now for Freedom Mobile to do something like this, it would require them to do a real phone app rather than the one that they presently have which only replicates the exact functionality of https://login.freedommobile.ca in a mobile friendly way. But that would be something that would be a worthy endeavour in my opinion.
Now I will put it out there that I could be completely off base here and Freedom Mobile may have security measures “behind the curtain” so to speak that addresses my concerns. If they do and they are willing to go on the record about how they protect customers from this sort of attack, I’d love to hear from Freedom Mobile about this and publish a story with their response. To be clear, I don’t expect them to tell the world exactly what they are doing. But Freedom Mobile addressing these concerns would be a smart move on their part because I am sure that their customers would love to hear how they are being protected from SIM swap attacks among other threats that exist in the world in 2024.












I Questioned Freedom Mobile’s Security When It Comes To Preventing A SIM Swap #Scam… Now There’s A Case Of SIM Swapping That Cost A Couple $140K
Posted in Commentary with tags Freedom Mobile, Scam on March 22, 2024 by itnerdWhen my wife and I switched to Freedom Mobile, I’ve wondered about the security to stop things like SIM swap scams. I say that because the way that Freedom Mobile has set up their “My Freedom” customer portal doesn’t seem all that secure to me. Which is why a story from Global News caught my attention as it details the story of a couple who are Freedom Mobile customers that lost $140K in a SIM swap scam:
Wayne Stork and his wife Diana had not heard of the SIM swap scam until they became victims.
The GTA couple did nothing wrong but they lost about $140,000 anyway.
“It’s a nightmare,” Wayne told Global News in a television interview, his wife Diana at his side.
“We’re doing this, in part, to get the word out,” Diana said.
The Storks are longtime customers of Freedom Mobile. Last September, when the couple were at home, Wayne’s phone suddenly stopped working.
“My phone went into SOS mode, it was deactivated,” he said.
From that point, Wayne had no use of the phone, but someone else had access to the personal information attached to it.
“He (Wayne) was watching his accounts drain of money, that’s when the panic set in,” Diana said.
Over the next 24 hours, scammers had gained access to Wayne’s stock trading account and other accounts, including a cryptocurrency one that contained the proceeds from an inheritance.
“The Bitcoin was worth $140,000, and we lost that,” Diana said.
When the couple called Freedom Mobile’s customer service line, they say a representative said records showed someone had obtained a new SIM card in a retail location in Toronto, apparently claiming to be Stork.
Stork says the phone representative asked “weren’t you in the store yesterday to get a new SIM card?” to which Stork said no, it wasn’t him.
So you’re likely wondering how a SIM swap scam ends up in someone losing a lot of cash. Well, people often use their cell phones, specifically text messaging, to receive multi factor authentication codes for the financial institutions or online services that they use. So if a threat actor can get their hands on your cell phone number and some other information like passwords and the like, they can drain you of all your cash.
Now while this incident didn’t involve the “My Freedom” customer portal, it does suggest that Freedom Mobile does have weaknesses in terms of preventing this sort of scam from happening. After all, it should not be possible, or at least very difficult to walk into a retail location and execute this scam in 2024. In fact, I pinged my “off the record” contacts at Rogers, TELUS, and Bell. While they don’t rule out the possibility of this happening with them, and they don’t know the specifics of how this incident was executed, all of them say that this would be far more difficult to execute with them because of the security measures that they have in place. Or put another way, they’re throwing shade on whatever security measures that Freedom Mobile does or more importantly doesn’t have because they assume that they can do better. I’m not sure that I would make that assumption. But that’s just me. And what makes this worse is that now that this story is out there, other threat actors will specifically target Freedom Mobile because the perception will be that they are an easier target in terms of executing this scam. That’s bad for Freedom Mobile, and its customers.
Now if you’re worried about being a victim of a SIM swapping, the Global News article as well as the link to what a SIM swap is has some actionable information. But the one thing that you could really do to protect yourself is use app based multi factor authentication rather than text message based multi factor authentication wherever possible. Because the second that you do that, the safer you become as that’s not tied to the SIM card in your phone. That does require financial institutions and online services to move in that direction. So you may be stuck with text message based multi factor for a while. Which means it’s up to carriers like Freedom Mobile to up their game to protect their customers. Let’s see if Freedom Mobile does that now that this incident is out in the public domain.
Leave a comment »