IP Library Granted Patent US 8,615,807
Granted Patent B1
US 8,615,807 · App. 13/785,127 · Granted Dec 24, 2013

Simulated phishing attack with sequential messages

Inventors: Aaron Higbee (Leesburg, VA); Rohyt Belani (New York, NY); Scott Greaux (Glenmont, NY)
Assignee: PhishMe, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,615,807
App. No.
13/785,127
Granted
Dec 24, 2013
Kind
B1
Abstract

Described herein are methods, network devices and machine-readable storage media for conducting simulated phishing attacks on an individual so as to educate the individual about the various ways in which phishing attacks may be disguised. Specifically described is a simulated phishing attack involving a sequence of messages. At least one of the messages has an associated target action that would ordinary, if the attack were an actual phishing attack, result in the individual's personal information and/or computing device becoming compromised. In the simulated phishing attack, no malicious action is actually performed. At least one of the other messages is designed to draw attention to the message with the target action.

Claims (29)

1. A method, comprising:

conducting a simulated phishing attack, the simulated attack comprising:

transmitting a first message to at least one of one or more computing devices of an individual, the first message being disguised as originating from at least one of one or more trustworthy contacts of the individual and notifying the individual that the individual should expect to receive a second message; and

after transmitting the first message, transmitting the second message to at least one of the one or more computing devices of the individual, the second message also being disguised as originating from at least one of the one or more trustworthy contacts of the individual and attempting to lure the individual into performing, on at least one of the one or more computing devices, a target action associated with the second message,

wherein if the individual performs the target action, the simulated phishing attack does not actually compromise any personal information or any one of the one or more computing devices of the individual; and

monitoring whether the individual performs the target action on at least one of the one or more computing devices.

2. The method of claim 1 , wherein the first and second messages are e-mails.

3. The method of claim 1 , wherein the first message is a Short Message Service (SMS) message and the second message is an e-mail.

4. The method of claim 1 , wherein the first and second messages are Short Message Service (SMS) messages.

5. The method of claim 1 , wherein the first and second messages are transmitted using a common electronic communication protocol.

6. The method of claim 1 , wherein the first message is transmitted using a first electronic communication protocol and the second message is transmitted using a second electronic communication protocol, the first protocol being different than the second protocol.

7. The method of claim 1 , wherein the target action comprises one or more of opening an attachment, following an embedded link, replying to the second message, reporting the second message, and providing personal information.

8. The method of claim 1 , wherein the second message is transmitted in response to an action performed in association with the first message.

9. The method of claim 8 , wherein the action performed in association with the first message is one or more of replying to the first message, opening the first message, opening an attachment to the first message, and following an embedded link within the first message.

10. A method, comprising:

conducting a simulated phishing attack, the simulated attack comprising:

transmitting a first message to at least one of one or more computing devices of an individual, the first message being disguised as originating from at least one of one or more trustworthy contacts of the individual and attempting to lure the individual into performing, on at least one of the one or more computing devices, a target action associated with the first message; and

after transmitting the first message, transmitting a second message to at least one of the one or more computing devices of the individual, the second message also being disguised as originating from at least one of the one or more trustworthy contacts of the individual and encouraging the individual to perform the target action on at least one of the one or more computing devices,

wherein if the individual performs the target action, the simulated phishing attack does not actually compromise any personal information or any one of the one or more computing devices of the individual; and

monitoring whether the individual performs the target action on at least one of the one or more computing devices.

11. The method of claim 10 , wherein the second message encourages the individual to perform the target action by reminding the individual that an action from the individual is requested in association with the earlier transmitted first message.

12. The method of claim 10 , wherein the first message is transmitted using a first electronic communication protocol and the second message is transmitted using a second electronic communication protocol, the first protocol being different than the second protocol.

13. The method of claim 10 , wherein the target action comprises one or more of opening an attachment, following an embedded link, replying to the first message, reporting the first message, and providing personal information.

14. A method, comprising:

conducting a simulated phishing attack, the simulated attack comprising:

transmitting a first message to at least one of one or more computing devices of an individual, the first message (i) referencing a second message that the individual should expect to receive after the first message, (ii) being disguised as originating from at least one of one or more trustworthy contacts of the individual, and (iii) attempting to lure the individual into performing, on at least one of the one or more computing devices, a first target action that is associated with the first message; and

after transmitting the first message, transmitting the second message to at least one of the one or more computing devices of the individual, the second message also being disguised as originating from at least one of the one or more trustworthy contacts of the individual and attempting to lure the individual into performing, on at least one of the one or more computing devices, a second target action that is associated with the second message,

wherein if the individual performs one or more of the first target action and the second target action, the simulated phishing attack does not actually compromise any personal information or any one of the one or more computing devices of the individual; and

monitoring whether the individual performs at least one of the first and second target actions on at least one of the one or more computing devices.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded May 6, 2022
From: ORIX GROWTH CAPITAL, LLC
To: COFENSE INC.; COFENSE BIDCO CORPORATION
Reel/Frame 059864/0955 →
SECURITY INTEREST Recorded Oct 4, 2021
From: COFENSE BIDCO CORPORATION; COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 057692/0722 →
RELEASE OF SECURITY INTEREST Recorded Oct 3, 2019
From: SILICON VALLEY BANK
To: COFENSE, INC.
Reel/Frame 050616/0262 →
SECURITY INTEREST Recorded Sep 24, 2019
From: COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 050478/0889 →
MERGER AND CHANGE OF NAME Recorded Jan 15, 2019
From: PHISHME INC; POSEIDON MERGER SUB 2 INC; COFENSE INC
To: COFENSE INC
Reel/Frame 048016/0424 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: PHISHME INC.
To: SILICON VALLEY BANK
Reel/Frame 031597/0315 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2013
From: HIGBEE, AARON; BELANI, ROHYT; GREAUX, SCOTT
To: PHISHME, INC.
Reel/Frame 029922/0630 →
Continuity (1)
Continuation 13763486 · Feb 8, 2013