IP Library Granted Patent US 11,070,587
Granted Patent B2
US 11,070,587 · App. 16/750,640 · Granted Jul 20, 2021

Systems and methods for performing simulated phishing attacks using social engineering indicators

Inventors: Alin Irimie (Clearwater, FL); Greg Kras (Dunedin, FL); David Austin (Dunedin, FL); Benjamin Dalton (St. Petersburg, FL)
Assignee: KnowBe4, Inc.
H04L63/1483G06F40/186H04L51/18H04L51/32H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,070,587
App. No.
16/750,640
Granted
Jul 20, 2021
Kind
B2
Abstract

Systems and methods are provided for performing simulated phishing attacks using social engineering indicators. One or more failure indicators can be configured in a phishing email template, and each failure indicator can be assigned a description about that failure indicator through use of a markup tag. The phishing email template containing the markup tags corresponding to the failure indicators can be stored and can be used to generate a simulated phishing email in which the one or more markup tags are removed.

Claims (36)

1. A method comprising:

communicating, by a server, a simulated phishing email to one or more email accounts, the simulated phishing email comprising a link to a page embedding a copy of the simulated phishing email using a phishing email template, the phishing email template comprising one or more failure indicators, each of the one or more failure indicators assigned a flag and a description on identifying that type of failure indicator;

causing to display the page embedding the copy of the simulated phishing email responsive to an interaction with the link by a user of an email account of the one or more email accounts receiving the simulated phishing email;

causing to display with the copy of the simulated phishing email one or more flags from the phishing email template corresponding to the one or more failure indicators; and

causing to display a flag of the one or more flags in the copy of the simulated phishing email, the copy of the simulated phishing emails configured to provide the description on how to identify that type of failure indicator corresponding to the flag.

2. The method of claim 1 , further comprising causing the description to display in one of an overlay or popup box responsive to an interaction with the flag.

3. The method of claim 2 , wherein the interaction comprises a pointer hovering over the flag.

4. The method of claim 1 , wherein the flag comprises an icon.

5. The method of claim 1 , wherein the user interaction with the link comprises a selection of the link to traverse to the display of the copy of the simulated phishing email.

6. The method of claim 1 , further comprising tracking, by the server, the one or more failure indicators associated with the interaction with the simulated phishing email by the user.

7. The method of claim 1 , further comprising tracking, by the server, which user interacted with the simulated phishing email.

8. A system comprising:

a non-transitory memory;

one or more processors, coupled to the non-transitory memory and configured to:

communicate a simulated phishing email to one or more email accounts, the simulated phishing email comprising a link to a page embedding a copy of the simulated phishing email using a phishing email template, the phishing email template comprising one or more failure indicators, each of the one or more failure indicators assigned a flag and a description on identifying that type of failure indicator;

wherein the one or more processors:

cause to display the page embedding the copy of the simulated phishing email responsive to an interaction with the link by a user of an email account of the one or more email accounts receiving the simulated phishing email;

cause to display with the copy of the simulated phishing email one or more flags from the phishing email template corresponding to the one or more failure indicators; and

cause to display a flag of the one or more flags in the copy of the simulated phishing email, the copy of the simulated phishing emails configured to provide the description on how to how to identify that type of failure indicator corresponding to the flag.

9. The system of claim 8 , wherein the one or more processors are further configured to cause the description to display in one of an overlay or popup box responsive to an interaction with the flag.

10. The system of claim 8 , wherein the interaction comprises a pointer hovering over the flag.

11. The system of claim 8 , wherein the flag comprises an icon.

12. The system of claim 8 , wherein the user interaction with the link comprises a selection of the link to traverse to the display of the copy of the simulated phishing email.

13. The system of claim 8 , wherein the one or more processors are further configured to track the one or more failure indicators associated with the interaction with the simulated phishing email by the user.

14. The system of claim 8 , wherein the one or more processors are further configured to track which user interacted with the simulated phishing email.

15. A non-transitory computer readable medium storing program instructions for causing one or more processors to:

communicate a simulated phishing email to one or more email accounts, the simulated phishing email comprising a link to a page embedding a copy of the simulated phishing email using a phishing email template, the phishing email template comprising one or more failure indicators, each of the one or more failure indicators assigned a flag and a description on identifying that type of failure indicator;

wherein the program instructions cause the one or more processors to:

cause to display the page embedding the copy of the simulated phishing email responsive to an interaction with the link by a user of an email account of the one or more email accounts receiving the simulated phishing email;

cause to display with the copy of the simulated phishing email one or more flags from the phishing email template corresponding to the one or more failure indicators; and

cause to display a flag of the one or more flags in the copy of the simulated phishing email, the copy of the simulated phishing emails configured to provide the description on how to identify that type of failure indicator corresponding to the flag.

16. The non-transitory computer readable medium of claim 15 , wherein the one or more processors are further configured to cause the description to display in one of an overlay or popup box responsive to an interaction with the flag.

17. The non-transitory computer readable medium of claim 16 , wherein the interaction comprises a pointer hovering over the flag.

18. The non-transitory computer readable medium of claim 15 , wherein the flag comprises an icon.

19. The non-transitory computer readable medium of claim 15 , wherein the user interaction with the link comprises a selection of the link to traverse to the display of the copy of the simulated phishing email.

20. The non-transitory computer readable medium of claim 15 , wherein the program instructions further cause the one or more processors to track which user interacted with the simulated phishing email and the one or more failure indicators associated with the user.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2020
From: IRIMIE, ALIN; KRAS, GREG; AUSTIN, DAVID; DALTON, BENJAMIN
To: KNOWBE4, INC.
Reel/Frame 051600/0852 →