IP Library Granted Patent US 11,108,821
Granted Patent B2
US 11,108,821 · App. 16/860,689 · Granted Aug 31, 2021

Systems and methods for use of address fields in a simulated phishing attack

Inventors: Jasmine Rodriguez (Clearwater, FL); Daniel Cormier (Clearwater, FL)
Assignee: KnowBe4, Inc.
H04L63/1483G09B19/0053H04L51/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,821
App. No.
16/860,689
Granted
Aug 31, 2021
Kind
B2
Abstract

Systems and methods are disclosed for creating simulated phishing attack messages that have characteristics which make them appear genuine, while also having characteristics that a user should recognize as being false. Simulated phishing emails may appear to be more realistic to a recipient user if the user observes that the email has also been sent to an individual known to the recipient within the same company. However, it may not be desirable to send the simulated phishing email to such additional recipients. The systems and methods include communicating a simulated phishing email from a server of a simulated phishing attack system to a recipient user of an entity. The simulated phishing email appears to the recipient user as though it is also addressed to one or more non-recipient users of the entity, even though the email is not sent to the non-recipient users.

Claims (23)

1. A method comprising:

(a) generating, by a server for a recipient user of an entity to be targeted with a simulated phishing email, one or more email addresses of one or more non-recipient users to be displayed as recipients of the simulated phishing email when received by the recipient user;

(b) generating, by the server, the simulated phishing email addressed via one or more address fields to the recipient user and the one or more non-recipient users;

(c) initiating, by the server, transmission of the simulated phishing email to a mail server of the entity;

(d) communicating, by the server, a RCPT TO command of a simple mail transfer protocol (SMTP) to the mail server to include the recipient user as the recipient of the simulated phishing email and to exclude the one or more non-recipient users as recipients of the simulated phishing email; and

(e) communicating, by the server, via a DATA command of the SMTP with the mail server, the one or more email addresses of the one or more non-recipient users with content of the simulated phishing email to the recipient user to cause the simulated phishing email to be displayed to the recipient user with the one or more email addresses of the one or more non-recipient users as recipients of the simulated phishing email in order to give appearance to the recipient user that the simulated phishing email was communicated to the one or more non-recipient users that were excluded from the RCPT TO command.

2. The method of claim 1 , wherein (a) further comprises generating, by the server, the one or more email addresses as real email addresses of the one or more non-recipient users of the entity.

3. The method of claim 1 , wherein (a) further comprises generating, by the server the one or more email addresses as fake email addresses with a display name of the one or more non-recipient users.

4. The method of claim 1 , wherein (b) further comprises including, by the server, the one or more email addresses in one or more address fields of a header of the simulated phishing email.

5. The method of claim 1 , wherein (c) further comprises establishing, by the server, a SMTP session with the mail server.

6. The method of claim 1 , further comprising identifying, by the server, whether the recipient user interacted with the simulated phishing email and responsive to the identifying that the recipient user interacted with the simulated phishing email, determine a training module for the recipient user.

7. A system comprising:

a server comprising one or more processors, coupled to memory and configured to:

generate, for a recipient user of an entity to be targeted with a simulated phishing email, one or more email addresses of one or more non-recipient users to be displayed as recipients with the simulated phishing email to be received by the recipient user;

generate the simulated phishing email addressed to the recipient user and the one or more non-recipient users;

initiate transmission of the simulated phishing email to a mail server of the entity;

communicate a RCPT TO command of a simple mail transfer protocol (SMTP) to the mail server to include the recipient user as the recipient of the simulated phishing email and to exclude the one or more non-recipient users as recipients of the simulated phishing email; and

communicate via a DATA command of the SMTP with the mail server, the one or more email addresses of the one or more non-recipient users with content of the simulated phishing email to the recipient user to cause the simulated phishing email to be displayed to the user with the one or more email addresses of the one or more non-recipient users as recipients of the simulated phishing email in order to give appearance to the recipient user that the simulated phishing email was communicated to the one or more non-recipient users that were excluded from the RCPT TO command.

8. The system of claim 7 , wherein the server is further configured to generate the one or more email addresses as real email addresses of the one or more other non-recipient users.

9. The system of claim 7 , wherein the server is further configured to generate the one or more email addresses with a display name of the one or more non-recipient users with fake email addresses.

10. The system of claim 7 , wherein the server is further configured to include the one or more email addresses in one or more address fields of a header of the simulated phishing email.

11. The system of claim 7 , wherein the server is further configured to establish a SMTP session with the mail server.

12. The system of claim 7 , wherein the server is further configured to identify whether the recipient user interacted with the simulated phishing email and responsive to the identifying that the recipient user interacted with the simulated phishing email, determine a training module for the recipient user.

Assignments (7)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: CORMIER, DANIEL
To: KNOWBE4, INC.
Reel/Frame 052563/0087 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: RODRIGUEZ, JASMINE
To: KNOWBE4, INC.
Reel/Frame 052563/0043 →
Continuity (2)
Provisional Application 62841532 · May 1, 2019
Related Publication 20200366713A1 · Nov 19, 2020