IP Library Granted Patent US 10,237,302
Granted Patent B1
US 10,237,302 · App. 15/926,470 · Granted Mar 19, 2019

System and methods for reverse vishing and point of failure remedial training

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,237,302
App. No.
15/926,470
Granted
Mar 19, 2019
Kind
B1
Abstract

Embodiments of the disclosure describe a simulated phishing campaign manager that communicates a simulated phishing communication that includes at least the telephone number and reference identifier, to a device of a user. The content of the simulated phishing communication may prompt the user to call the telephone number identified in the simulated phishing communication. The security awareness system may select a telephone number and a reference identifier to use for the simulated phishing communication, the combination of which may be later used to identify a specific user if they respond to the message. Each of a plurality of users may have a unique combination of telephone number and reference identifier. The telephone number may be selected based on the geographic location of the user, or the telephone number may be selected to correspond to content in a simulated phishing communication.

Claims (30)

1. A method for identifying users who fail a simulated phishing attack associated with telephone numbers, the method comprising:

(a) selecting, by a simulated phishing campaign manager, a telephone number and a reference identifier to be identified in a simulated phishing communication to be communicated to a user of a plurality of users;

(b) communicating, by the simulated phishing campaign manager to a device of the user, the simulated phishing communication comprising the telephone number and the reference identifier selected for the user;

(c) receiving, by the simulated phishing campaign manager, information indicating that the user called the telephone number and provided the reference identifier corresponding to the user; and

(d) identifying, by the simulated phishing campaign manager responsive to the information, the user as failing the simulated phishing attack.

2. The method of claim 1 , wherein (a) further comprises selecting the telephone number for the user based at least on a geographic location of the user.

3. The method of claim 1 , wherein (a) further comprises selecting a combination of the telephone number and reference identifier to be unique amongst the plurality of users.

4. The method of claim 1 , wherein (b) further comprises one of generating or modifying content of the simulated phishing communication to the user to identify the telephone number and reference identifier selected for the user.

5. The method of claim 1 , wherein (b) further comprises generating the simulated phishing communication to comprise content to prompt the user to call the telephone number identified in the simulated phishing communication.

6. The method of claim 1 , wherein (c) further comprises receiving, by a server, a telephone call from the user to the telephone number selected for the user, the server playing a predetermined message instructing the user to enter the reference identifier.

7. The method of claim 1 , wherein (c) further comprises receiving information comprising identification of the user and location from which the user called the telephone number.

8. The method of claim 1 , wherein (c) further comprises receiving information comprising identification of how long the user was on the phone.

9. The method of claim 1 , wherein (c) further comprises receiving information identifying whether the user completed remedial training provided via the telephone number the user called.

10. The method of claim 1 , wherein (d) further comprises communicating a message to a device of the user that the user has failed the simulated phishing attack and locking one or more functions on the device until remedial training for the one or more users has been completed.

11. A system for identifying users who fail a simulated phishing attack associated with telephone numbers, the system comprising:

one or more processors, coupled to memory;

a simulated phishing campaign manager executable on the one or more processors and configured to:

select a telephone number and a reference identifier to be identified in a simulated phishing communication to be communicated to user of a plurality of users;

communicate to a device of the user the simulated phishing communication comprising the telephone number and the reference identifier selected for the user;

receive information indicating that the user called the telephone number and provided the reference identifier corresponding to the user; and

identify, responsive to the information, the user as failing the simulated phishing attack.

12. The system of claim 11 , wherein simulated phishing campaign manager is further configured to select the telephone number for the user based at least on a geographic location of the user.

13. The system of claim 11 , wherein simulated phishing campaign manager is further configured to select a combination of the telephone number and reference number to be unique among the plurality of users.

14. The system of claim 11 , wherein simulated phishing campaign manager is further configured to one of generate or modify content of the simulated phishing communication to the user to identify the telephone number and reference number selected for the user.

15. The system of claim 11 , wherein simulated phishing campaign manager is further configured to generate the simulated phishing communication to comprise content to prompt the user to call the telephone number identified in the simulated phishing communication.

16. The system of claim 11 , further comprising a server configured to receive a telephone call from the user to the telephone number selected for the user, the server playing a predetermined message instructing the user to enter the reference identifier.

17. The system of claim 11 , wherein the information comprises identification of the user and location from which the user called the telephone number.

18. The system of claim 11 , wherein the information comprises identification of how long the user was on the phone.

19. The system of claim 11 , wherein the information identifies whether the user completed remedial training provided via the telephone number the user called.

20. The system of claim 11 , further comprising communicating a message to a device of the user that the user has failed the simulated phishing attack and locking one or more functions on the device until remedial training for the one or more users has been completed.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2018
From: KRAS, GREG; IRIMIE, ALIN
To: KNOWBE4, INC.
Reel/Frame 045987/0224 →