IP Library Granted Patent US 11,552,991
Granted Patent B2
US 11,552,991 · App. 17/004,855 · Granted Jan 10, 2023

Systems and methods for performing a simulated phishing attack

Inventors: Alin Irimie (Palm Harbor, FL); Stu Sjouwerman (Bellair, FL); Brian Jack (Clearwater, FL)
Assignee: KnowBe4, Inc.
H04L63/1483H04L51/18H04L51/23H04L51/42H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,552,991
App. No.
17/004,855
Granted
Jan 10, 2023
Kind
B2
Abstract

Systems and methods for performing a simulated phishing attack are provided. A simulated attack server can send a simulated attack email including a unique identifier to a target. The simulated attack server can receive a reply email including the unique identifier from the target. The simulated attack server can extract the unique identifier from the reply email. The simulated attack server can determine a match between the unique identifier and an identity of the target. The simulated attack server can record a target failure, responsive to determining the match between the unique identifier and the identity of the target.

Claims (31)

1. A method comprising:

including, by one or more processors, an identifier of a user within a simulated phishing communication, the identifier uniquely identifying the user separate from any identifier of an email account of the user;

communicating, by the one or more processors, the simulated phishing communication to a first account of the user, the simulated phishing communication communicated to one or more second accounts different from the first account; and

determining, by the one or more processors using the identifier of the user in a reply to the simulated phishing communication, that the reply was received responsive to the simulated phishing communication being communicated to the first account of the user.

2. The method of claim 1 , further comprising assigning, by the one or more processors, a different identifier to each user of a plurality of users that identifies each user separately from any email account of the user.

3. The method of claim 1 , further comprising embedding, by the one or more processors, the identifier of the user in the simulated phishing communication.

4. The method of claim 1 , wherein the simulated phishing communication comprises an email.

5. The method of claim 1 , further comprising including the identifier in one of a body, a subject line, a field or an attachment of the simulated phishing communication.

6. The method of claim 1 , wherein the one or more second accounts are different accounts of the user.

7. The method of claim 1 , wherein the one or more second accounts are one or more email accounts of another user.

8. The method of claim 1 , further comprising identifying, by the one or more processors, the identifier in a location of the reply in which the identifier was included in the simulated phishing communication.

9. The method of claim 1 , further comprising determining, by the one or more processors based at least on the identifier and a source of the reply, that the simulated phishing communication was interacted with via the one or more second accounts.

10. A system comprising:

one or more processors coupled to memory, and configured to:

include an identifier of a user within a simulated phishing communication, the identifier uniquely identifying the user separate from any identifier of an email account of the user;

communicate the simulated phishing communication to a first account of the user, the simulated phishing communication communicated to one or more second accounts different from the first account; and

determine, using the identifier of the user in a reply to the simulated phishing communication, that the reply was received responsive to the simulated phishing communication being communicated to the first account of the user.

11. The system of claim 10 , wherein the one or more processors are further configured to assign a different identifier to each user of a plurality of users that identifies each user separately from any email account of the user.

12. The system of claim 10 , wherein the one or more processors are further configured to embed the identifier of the user in the simulated phishing communication.

13. The system of claim 10 , wherein the simulated phishing communication comprises an email.

14. The system of claim 10 , wherein the one or more processors are further configured to include the identifier in one of a body, a subject line, a field or an attachment of the simulated phishing communication.

15. The system of claim 10 , wherein the one or more second accounts are different accounts of the user.

16. The system of claim 10 , wherein the one or more second accounts are one or more email accounts of another user.

17. The system of claim 10 , wherein the one or more processors are further configured to identify the identifier in a location of the reply in which the identifier was included in the simulated phishing communication.

18. The system of claim 10 , wherein the one or more processors are further configured to determine based at least on the identifier and a source of the reply that the simulated phishing communication was interacted with via the one or more second accounts.

19. A system comprising:

one or more processors coupled to memory, and configured to:

generate a simulated phishing communication comprising an identifier unique to a user and separate from any identifier of an email account of the user;

communicate the simulated phishing communication to a first account of the user, the simulated phishing communication communicated to one or more second accounts different from the first account; and

determine, using the identifier of the user in a reply to the simulated phishing communication, that the reply was received responsive to the simulated phishing communication being communicated to the first account of the user.

20. The system of claim 1 , wherein the one or more processors are further configured to embed the identifier of the user to be invisible in a body of the simulated phishing communication.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2020
From: IRIMIE, ALIN; SJOUWERMAN, STU; JACK, BRIAN
To: KNOWBE4, INC.
Reel/Frame 053619/0439 →