IP Library Granted Patent US 11,418,541
Granted Patent B2
US 11,418,541 · App. 17/399,739 · Granted Aug 16, 2022

Systems and methods for simulated phishing attacks involving message threads

Inventor: Greg Kras (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1483H04L51/08H04L51/212H04L51/216H04L51/42H04L63/1416H04L63/1433H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,418,541
App. No.
17/399,739
Granted
Aug 16, 2022
Kind
B2
Abstract

Systems and methods are disclosed for simulating a phishing attack involving an email thread. An email thread of a plurality of email threads of an entity for use in a simulated phishing attack is identified. A simulation system generates a converted reply simulated phishing email to an email of the email thread. The converted reply simulated phishing email is generated to be from a user that is one of a recipient or a sender of one or more emails of the email thread and is communicated to a target user's email account, the converted reply simulated phishing email.

Claims (27)

1. A method comprising:

identifying, by a simulation system executing on one or more processors and configured to interface via an application programming interface (API) with an email system of an entity, one or more parameters configured in the simulation system for selecting an email thread from a plurality of email threads of the email system of the entity to target a simulated phishing email;

selecting, by the simulation system via the API with the email system of the entity, the email thread from the plurality of email threads from the email system based at least on the one or more parameters; and

converting, by the simulation system, an email of the email thread from the email system into a reply simulated phishing email from a user that is one of a recipient or a sender of one or more emails of the email thread.

2. The method of claim 1 , further comprising providing, by the simulation system, the converted reply simulated phishing email to an email account of a target user.

3. The method of claim 1 , further comprising communicating, by the simulation system, the reply simulated phishing email to one of another recipient or sender of one or more emails of the email thread.

4. The method of claim 1 , further comprising accessing, by the simulation system, the email system to identify the plurality of email threads.

5. The method of claim 1 , further comprising receiving, by the simulation system, identification of the plurality of email threads from the email system.

6. The method of claim 1 , wherein converting the email of the email thread into the reply simulated phishing email comprises generating from the user's email account the reply simulated phishing email.

7. The method of claim 1 , further comprising converting the email of the email thread into the reply simulated phishing email to display a correct name of the user but use a different email address for routing any replies communicated responsive to replying to the reply simulated phishing email.

8. The method of claim 1 , wherein the one or more parameters comprises one or more attributes of one of an entity of the user or one or more users participating in the email thread.

9. The method of claim 1 , wherein the one or more parameters comprises a subject matter of one or more emails of the email thread or an attachment to the one or more emails.

10. The method of claim 1 , wherein the one or more parameters comprises one or more characteristics of one or more emails.

11. A system comprising:

a simulation system on one or more processors, coupled to memory and configured to configured to interface via an application programming interface (API) with an email system of an entity, the simulation system configured to:

identify one or more parameters configured in the simulation system for selecting an email thread from a plurality of email threads of the email system of the entity to target a simulated phishing email;

select, via the API with the email system of the entity, the email thread from the plurality of email threads from the email system based at least on the one or more parameters; and

convert an email from the email system of the email thread into a reply simulated phishing email from a user that is one of a recipient or a sender of one or more emails of the email thread.

12. The system of claim 11 , wherein the simulation system is further configured to provide the converted reply simulated phishing email in an email account of a target user.

13. The system of claim 11 , wherein the simulation system is further configured to communicate the reply simulated phishing email to one of another recipient or sender of one or more emails of the email thread.

14. The system of claim 11 , wherein the simulation system is further configured to access the email system to identify the plurality of email threads.

15. The system of claim 11 , wherein the simulation system is further configured to receive identification of the plurality of email threads from the email system.

16. The system of claim 11 , wherein the simulation system is further configured to convert the email of the email thread into the reply simulated phishing email by generating from the user's email account the reply simulated phishing email.

17. The system of claim 11 , wherein the simulation system is further configured to convert the email of the email thread into the reply simulated phishing email to display a correct name of the user but use a different email address for routing any replies communicated responsive to replying to the reply simulated phishing email.

18. The system of claim 11 , wherein the one or more parameters comprises one or more attributes of one of an entity of the user or one or more users participating in the email thread.

19. The system of claim 11 , wherein the one or more parameters comprises a subject matter of one or more emails of the email thread or an attachment to the one or more emails.

20. The system of claim 11 , wherein the one or more parameters comprises one or more characteristics of one or more emails.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2021
From: KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 057151/0114 →