IP Library Granted Patent US 11,856,025
Granted Patent B2
US 11,856,025 · App. 17/888,415 · Granted Dec 26, 2023

Systems and methods for simulated phishing attacks involving message threads

Inventor: Greg Kras (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1483H04L51/08H04L51/212H04L51/216H04L51/42H04L63/1416H04L63/1433H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,856,025
App. No.
17/888,415
Granted
Dec 26, 2023
Kind
B2
Abstract

Systems and methods are disclosed for simulating a phishing attack involving an email thread. An email thread of a plurality of email threads of an entity for use in a simulated phishing attack is identified. A simulation system generates a converted reply simulated phishing email to an email of the email thread. The converted reply simulated phishing email is generated to be from a user that is one of a recipient or a sender of one or more emails of the email thread and is communicated to a target user's email account, the converted reply simulated phishing email.

Claims (27)

1. A method comprising:

selecting, by a simulation system executing on one or more processors and configured to interface via one or more application programming interfaces (APIs) with an email system of an entity, an email thread from a plurality of email threads from the email system based at least on one or more parameters, the simulation system selecting the email thread to target a simulated phishing email;

identifying, by the simulation system using the one or more APIs, an email of the email thread from the email system for which to create a reply simulated phishing email from a user of one or more emails of the email thread; and

creating, by the simulation system, the reply simulated phishing email as a reply email to the email from the user, wherein the reply simulated phishing email comprises one or more display names identifying one or more non-recipient users of the email, the reply simulated phishing email being configured to prevent the reply simulated phishing email from being received by the one or more non-recipient users.

2. The method of claim 1 , further comprising identifying, by the simulation system, the one or more parameters configured in the simulation system for selecting the email thread.

3. The method of claim 1 , wherein the user is one of a recipient or a sender of the one or more emails of the email thread.

4. The method of claim 1 , wherein the reply simulated phishing email is further configured to display a correct name of the user but to use different email address of the user for routing any replies to the simulation system responsive to a recipient user replying to the reply simulated phishing email.

5. The method of claim 1 , wherein the reply simulated phishing email is further configured to display a correct name of the one or more non-recipient users but use a different email address of the one or more non-recipient users for routing any replies the simulation system responsive to a recipient user replying to the reply simulated phishing email.

6. The method of claim 1 , wherein the reply simulated phishing email is further configured to display a correct name of the one or more non-recipient users but use an incorrect email address for the one or more non-recipient users.

7. The method of claim 6 , wherein the incorrect email is a simulation system email address.

8. The method of claim 6 , wherein the incorrect email address is a variant of the correct email address of the one or more non-recipient users.

9. The method of claim 6 , wherein the incorrect email address is different from but mimics the correct email address of the one or more non-recipient users.

10. The method of claim 1 , wherein the simulation system is configured to not send the reply simulated phishing message to the email accounts of the one or more non-recipient users.

11. A system comprising:

a simulation system of one or more processors configured to interface via one or more application programming interfaces (APIs) with an email system of an entity and:

select an email thread from a plurality of email threads from the email system based at least on one or more parameters, the simulation system selecting the email thread to target a simulated phishing email;

identify, using the one or more APIs, an email of the email thread from the email system for which to create a reply simulated phishing email from a user of one or more emails of the email thread; and

create the reply simulated phishing email as a reply email to the email from the user, wherein the reply simulated phishing email comprises one or more display names identifying one or more non-recipient users of the email, the reply simulated phishing email being configured to prevent the reply simulated phishing email from being received by the one or more non-recipient users.

12. The system of claim 11 , wherein the simulation system is further configured to identify the one or more parameters configured in the simulation system for selecting the email thread.

13. The system of claim 11 , wherein the user that is one of a recipient or a sender of the one or more emails.

14. The system of claim 11 , wherein the reply simulated phishing email is further configured to display a correct name of the user but to use different email address of the user for routing any replies to the simulation system responsive to a recipient user replying to the reply simulated phishing email.

15. The system of claim 11 , wherein the reply simulated phishing email is further configured to display a correct name of the one or more non-recipient users but use a different email address of the one or more non-recipient users for routing any replies the simulation system responsive to a recipient user replying to the reply simulated phishing email.

16. The system of claim 11 , wherein the reply simulated phishing email is further configured to display a correct name of the one or more non-recipient users but use an incorrect email address for the one or more non-recipient users.

17. The system of claim 16 , wherein the incorrect email is a simulation system email address.

18. The system of claim 16 , wherein the incorrect email address is a variant of the correct email address of the one or more non-recipient users.

19. The system of claim 16 , wherein the incorrect email address is different from but mimics the correct email address of the one or more non-recipient users.

20. The system of claim 16 , wherein the simulation system is configured to not send the reply simulated phishing message to the email accounts of the one or more non-recipient users.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2022
From: KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 060812/0743 →
Continuity (4)
Continuation 17399739 · Aug 11, 2021
Continuation 16993958 · Aug 14, 2020
Provisional Application 62898145 · Sep 10, 2019
Related Publication 20230008987A1 · Jan 12, 2023