IP Library Granted Patent US 12706950
Granted Patent B2
US 12706950 · App. 18/829,653 · Granted Aug 11, 2026

Sensing a presence of intrustion of digital communications for phishing attempts

Inventor: William Vance Hendley (Lake Wylie, SC)
Assignee: TRUIST BANK
H04L63/1483G06F3/04842H04L51/214
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706950
App. No.
18/829,653
Granted
Aug 11, 2026
Kind
B2
Abstract

A system and method sense a presence of intrusion of digital communications for phishing attempts including: a processor operatively connected to a memory device and a non-transitory storage device, wherein the processor executes computer-readable instructions of a digital communication application; a computer device with a display communicating with the processor to display digital communications addressed to a receiving communication address; and wherein, upon execution of the computer-readable instructions, the computing system performs steps comprising: in response to selection of the digital communication displayed at the computer device via the computer device, displaying either a Check Phishing button or a submenu listing a Check Phishing action at the computer device; and in response to selection of the button or selection of the action via the computer device, the processor executes computer-readable instructions of a check phishing application stored in the storage device to authenticate the from address of the digital communication.

Claims (33)

1 . A computing system for sensing a presence of intrusion of digital communications for phishing attempts, the computing system being included in an enterprise system maintained by an enterprise, the computing system comprising:

a processor, a memory device, and a non-transitory storage device internal to the enterprise system, the processor being operatively connected to the memory device and to the storage device, wherein the processor executes computer-readable instructions of a digital communication application;

a computer device with a display, the computer device communicating with the processor to display digital communications processed by the digital communication application and addressed to a receiving communication address associated with an employee of the enterprise; and

wherein, upon execution of the computer-readable instructions by the processor, the computing system performs steps comprising:

upon receiving a digital communication addressed to the receiving communication address, displaying the digital communication at the computer device;

in response to selection of the digital communication displayed at the computer device via the computer device, displaying either a Check Phishing button or a submenu listing a Check Phishing action at the computer device display;

in response to selection of the button or selection of the action via the computer device, the processor executes computer-readable instructions of a check phishing application stored in the storage device, the check phishing application, without transmitting the digital communication to an external service, performing steps of:

comparing a displayed from address of the digital communication with a plurality of valid communication addresses in a database stored in the storage device and maintained by the enterprise, the valid communication addresses including employee communication addresses, client communication addresses, and vendor communication addresses;

when the from address corresponds to one of the valid communication addresses, displaying a first popup window at the computer device display indicating that the from address is valid; and

when the from address does not correspond to any of the valid communication addresses, displaying a second popup window at the computer device display indicating that the from address is invalid.

2 . The computing system according to claim 1 including removing the digital communication from the display when the from address does not correspond to any of the valid communication addresses.

3 . The computing system according to claim 2 including forwarding the digital communication to a review team communication address.

4 . The computing system according to claim 1 including comparing the from address with a source address included in a header of the digital communication, when the from address corresponds to the source address and the source address corresponds to one of the valid communication addresses in the database, displaying the first popup window at the computer device indicating that the from address is valid, and when the from address does not correspond to the source address and the source address does not correspond to any of the valid communication addresses in the database, displaying the second popup window at the computer device indicating that the from address is invalid.

5 . The computing system according to claim 4 including removing the digital communication from the display when the from address does not correspond to the source address and the source address does not correspond to any of the valid communication addresses.

6 . The computing system according to claim 5 including forwarding the digital communication to a review team communication address.

7 . The computing system according to claim 1 wherein the displaying the submenu listing a Check Phishing action at the computer device includes displaying a menu listing a Report Spam action at the computer device and displaying the submenu in response to a selection of the Report Spam action from the menu.

8 . A method for performing an automated review of digital communications for phishing attempts in a computing system included in an enterprise system maintained an enterprise, the method comprising steps of:

providing a processor operatively connected to a memory device and to a non-transitory storage device in the computing system, wherein the processor executes computer-readable instructions of a digital communication application;

providing a computer device with a display, the computer device communicating with the processor to display digital communications processed by the digital communication application and addressed to a receiving communication address associated with an employee of the enterprise;

storing in the storage device a check phishing application and a plurality of valid communication addresses in a database maintained by the enterprise, the valid communication addresses including employee communication addresses, client communication addresses, and vendor communication addresses; and

wherein, upon execution of the computer-readable instructions, the computing system performs steps comprising:

upon receiving a digital communication addressed to the receiving communication address, displaying the digital communication at the computer device display;

in response to selection of the digital communication displayed at the computer device via the computer device, displaying either a Check Phishing button or a submenu listing a Check Phishing action at the computer device;

in response to selection of the button or selection of the action via the computer device, the processor executes computer-readable instructions of the check phishing application, without transmitting the digital communication to an external service, thereby performing steps of:

comparing a displayed from address of the digital communication with the plurality of valid communication addresses in the database;

when the from address corresponds to one of the valid communication addresses, displaying a first popup window at the computer device display indicating that the from address is valid; and

when the from address does not correspond to any of the valid communication addresses, displaying a second popup window at the computer device display indicating that the from address is invalid.

9 . The method according to claim 8 including removing the digital communication from the display when the from address does not correspond to any of the valid communication addresses.

10 . The method according to claim 9 including forwarding the digital communication to a review team communication address.

11 . The method according to claim 8 including comparing the from address with a source address included in a header of the digital communication, when the from address corresponds to the source address and the source address corresponds to one of the valid communication addresses in the database, displaying the first popup window at the computer device indicating that the from address is valid, and when the from address does not correspond to the source address and the source address does not correspond to any of the valid communication addresses in the database, displaying the second popup window at the computer device indicating that the from address is invalid.

12 . The method according to claim 11 including removing the digital communication from the display when the from address does not correspond to the source address and the source address does not correspond to any of the valid communication addresses.

13 . The method according to claim 12 including forwarding the digital communication to a review team communication address.

14 . The method according to claim 8 wherein the displaying the submenu listing a Check Phishing action at the computer device includes displaying a menu listing a Report Spam action at the computer device and displaying the submenu in response to a selection of the Report Spam action from the menu.