IP Library Granted Patent US 12,499,209
Granted Patent B2
US 12,499,209 · App. 18/128,394 · Granted Dec 16, 2025

System and methods for minimizing organization risk from users associated with a password breach

Inventor: Greg Kras (Dunedin, FL)
G06F21/46G06F21/577G09B9/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,209
App. No.
18/128,394
Granted
Dec 16, 2025
Kind
B2
Abstract

System and methods are disclosed for organizations to run a test against an active directory list to see if any user-provided passwords have been part of an existing data breach. Utilizing information from such a test identifies users that have weak passwords, reused passwords or shared passwords that have been associated with an earlier breach. With this information, the organization can seek to reduce risk by training staff for this specific issue in a timely and appropriate manner to significantly reduce the risk of a future breach by those identified users. Training can be customized and targeted at those users who attempt to use passwords that have been associated with a breach (either of their own account or of another account on the same or related domain.

Claims (29)

1 . A method comprising:

identifying, by one or more processors, one or more types of password breach that occurred as part of one or more existing data breaches;

selecting, by the one or more processors, one or more users having a type of password breach, of the one or more types of password breach, that occurred as part of the one or more existing data breaches;

communicating, by the one or more processors, an electronic training based at least on the type of password breach to the selected one or more users that occurred as part of the one or more existing data breaches; and

adjusting, by the one or more processors, a risk score of the selected one or more users based at least on results of the electronic training and at least on the type of password breach that occurred as part of the one or more existing data breaches.

2 . The method of claim 1 , further comprising determining, by the one or more processors, the adjustment to the risk score based at least on the type of password breach.

3 . The method of claim 1 , further comprising generating, by the one or more processors, the electronic training based at least on the type of password breach.

4 . The method of claim 1 , further comprising selecting, by the one or more processors, the one or more users from a group of users having a same type of password breach.

5 . The method of claim 1 , further comprising classifying, by the one or more processors, the one or more password breaches into a type of password breach.

6 . The method of claim 5 , further comprising determining, by the one or more processors, the electronic training based at least on the type of data breach.

7 . The method of claim 1 , further comprising identifying, by the one or more processors, the one or more users as having one or more passwords subject to the one or more data breaches.

8 . The method of claim 1 , further comprising identifying, by the one or more processors, the one or more users as having one or more weak passwords.

9 . The method of claim 8 , further comprising determining, by the one or more processors, the one or more users as having one work weak passwords based at least on one or more weak password tests.

10 . The method of claim 8 , further comprising adjusting, by the one or more processors, the risk score of the one or more users responsive to identifying the one or more users as having one or more weak passwords.

11 . A system comprising:

one or more processors, coupled to memory and configured to:

identify one or more types of password breach that occurred as part of one or more existing data breaches;

select one or more users having a type of password breach, of the one or more types of password breach, that occurred as part of the one or more existing data breaches;

communicate an electronic training, based at least on the type of password breach that occurred as part of the one or more existing data breaches, to the selected one or more users; and,

adjust, a risk score of the selected one or more users based at least on results of the electronic training and at least on the type of password breach that occurred as part of the one or more existing data breaches.

12 . The system of claim 11 , wherein the one or more processors are further configured to determine the adjustment to the risk score based at least on the type of password breach.

13 . The system of claim 11 , wherein the one or more processors are further configured to generate the electronic training based at least on the type of password breach.

14 . The system of claim 11 , wherein the one or more processors are further configured to select the one or more users from a group of users having a same type of password breach.

15 . The system of claim 11 , wherein the one or more processors are further configured to classify the one or more password breaches into a type of password breach.

16 . The system of claim 15 , wherein the one or more processors are further configured to determine the electronic training based at least on the type of data breach.

17 . The system of claim 11 , wherein the one or more processors are further configured to identify the one or more users as having one or more passwords subject to the one or more data breaches.

18 . The system of claim 11 , wherein the one or more processors are further configured to identify the one or more users as having one or more weak passwords.

19 . The system of claim 18 , wherein the one or more processors are further configured to identity the one or more users as having one work weak passwords based at least on one or more weak password tests.

20 . The system of claim 18 , wherein the one or more processors are further configured to adjust the risk score of the one or more users responsive to identifying the one or more users as having one or more weak passwords.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2023
From: KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 063162/0625 →
Continuity (5)
Continuation 17829925 · Jun 1, 2022
Continuation 17347158 · Jun 14, 2021
Continuation 16746662 · Jan 17, 2020
Continuation 16135757 · Sep 19, 2018
Related Publication 20230237147A1 · Jul 27, 2023
References Cited (114)
US 7599992B2 · Nakajima · 2009 [cited by applicant]
US 8041769B2 · Shraim et al. · 2011 [cited by applicant]
US 8464346B2 · Barai et al. · 2013 [cited by applicant]
US 8484741B1 · Chapman · 2013 [cited by applicant]
US 8615807B1 · Higbee et al. · 2013 [cited by applicant]
US 8635703B1 · Belani et al. · 2014 [cited by applicant]
US 8719940B1 · Higbee et al. · 2014 [cited by applicant]
US 8793799B2 · Fritzson et al. · 2014 [cited by applicant]
US 8910287B1 · Belani et al. · 2014 [cited by applicant]
US 8966637B2 · Belani et al. · 2015 [cited by applicant]
US 9053326B2 · Higbee et al. · 2015 [cited by applicant]
US 9246936B1 · Belani et al. · 2016 [cited by applicant]
US 9253207B2 · Higbee et al. · 2016 [cited by applicant]
US 9262629B2 · Belani et al. · 2016 [cited by applicant]
US 9325730B2 · Higbee et al. · 2016 [cited by applicant]
US 9356948B2 · Higbee et al. · 2016 [cited by applicant]
US 9373267B2 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 9398029B2 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 9398038B2 · Higbee et al. · 2016 [cited by applicant]
US 9591017B1 · Higbee et al. · 2017 [cited by applicant]
US 9635052B2 · Hadnagy · 2017 [cited by applicant]
US 9667645B1 · Belani et al. · 2017 [cited by applicant]
US 9674221B1 · Higbee et al. · 2017 [cited by applicant]
US 9729573B2 · Gatti · 2017 [cited by applicant]
US 9813454B2 · Sadeh-Koniecpol et al. · 2017 [cited by applicant]
US 9870715B2 · Sadeh-Koniecpol et al. · 2018 [cited by applicant]
US 9876753B1 · Hawthorn · 2018 [cited by applicant]
US 9894092B2 · Irimie et al. · 2018 [cited by applicant]
US 9912687B1 · Wescoe et al. · 2018 [cited by applicant]
US 9942249B2 · Gatti · 2018 [cited by applicant]
US 9998480B1 · Gates et al. · 2018 [cited by applicant]
US 10243904B1 · Wescoe et al. · 2019 [cited by applicant]
US 10904186B1 · Everton et al. · 2021 [cited by applicant]
US 10986122B2 · Bloxham et al. · 2021 [cited by applicant]
US 11044267B2 · Jakobsson et al. · 2021 [cited by applicant]
US 11184393B1 · Gendre et al. · 2021 [cited by applicant]
US 11297094B2 · Huda · 2022 [cited by applicant]
US 20070142030A1 · Sinha et al. · 2007 [cited by applicant]
US 20100211641A1 · Yih et al. · 2010 [cited by applicant]
US 20100269175A1 · Stolfo et al. · 2010 [cited by applicant]
US 20120124671A1 · Fritzson et al. · 2012 [cited by applicant]
US 20120258437A1 · Sadeh-Koniecpol et al. · 2012 [cited by applicant]
US 20130198846A1 · Chapman · 2013 [cited by applicant]
US 20130203023A1 · Sadeh-Koniecpol et al. · 2013 [cited by applicant]
US 20130219495A1 · Kulaga et al. · 2013 [cited by applicant]
US 20130297375A1 · Chapman · 2013 [cited by applicant]
US 20140173726A1 · Varenhorst · 2014 [cited by applicant]
US 20140199663A1 · Sadeh-Koniecpol et al. · 2014 [cited by applicant]
US 20140199664A1 · Sadeh-Koniecpol et al. · 2014 [cited by applicant]
US 20140201835A1 · Emigh et al. · 2014 [cited by applicant]
US 20140230061A1 · Higbee et al. · 2014 [cited by applicant]
US 20140230065A1 · Belani et al. · 2014 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150180896A1 · Higbee et al. · 2015 [cited by applicant]
US 20150229664A1 · Hawthorn et al. · 2015 [cited by applicant]
US 20160036829A1 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 20160142439A1 · Goutal · 2016 [cited by applicant]
US 20160164898A1 · Belani et al. · 2016 [cited by applicant]
US 20160173510A1 · Harris et al. · 2016 [cited by applicant]
US 20160234245A1 · Chapman · 2016 [cited by applicant]
US 20160261618A1 · Koshelev · 2016 [cited by applicant]
US 20160301705A1 · Higbee et al. · 2016 [cited by applicant]
US 20160301716A1 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 20160308897A1 · Chapman · 2016 [cited by applicant]
US 20160330238A1 · Hadnagy · 2016 [cited by applicant]
US 20170026410A1 · Gatti · 2017 [cited by applicant]
US 20170078322A1 · Seiver et al. · 2017 [cited by applicant]
US 20170104778A1 · Shabtai et al. · 2017 [cited by applicant]
US 20170140663A1 · Sadeh-Koniecpol et al. · 2017 [cited by applicant]
US 20170237776A1 · Higbee et al. · 2017 [cited by applicant]
US 20170244746A1 · Hawthorn et al. · 2017 [cited by applicant]
US 20170251009A1 · Irimie et al. · 2017 [cited by applicant]
US 20170251010A1 · Irimie et al. · 2017 [cited by applicant]
US 20170318046A1 · Weidman · 2017 [cited by applicant]
US 20170331839A1 · Park · 2017 [cited by examiner]
US 20170331848A1 · Alsaleh et al. · 2017 [cited by applicant]
US 20180041537A1 · Bloxham et al. · 2018 [cited by applicant]
US 20180063189A1 · Versteeg · 2018 [cited by examiner]
US 20180103052A1 · Choudhury et al. · 2018 [cited by applicant]
US 20190173819A1 · Wescoe et al. · 2019 [cited by applicant]
US 20190215335A1 · Benishti · 2019 [cited by applicant]
US 20190245885A1 · Starink et al. · 2019 [cited by applicant]
US 20190245894A1 · Epple et al. · 2019 [cited by applicant]
US 20200311260A1 · Klonowski et al. · 2020 [cited by applicant]
US 20210075827A1 · Grealish · 2021 [cited by applicant]
US 20210185075A1 · Adams · 2021 [cited by applicant]
US 20210194924A1 · Heinemeyer et al. · 2021 [cited by applicant]
US 20210407308A1 · Brubaker et al. · 2021 [cited by applicant]
US 20220005373A1 · Nelson et al. · 2022 [cited by applicant]
US 20220006830A1 · Wescoe · 2022 [cited by applicant]
US 20220078207A1 · Chang et al. · 2022 [cited by applicant]
US 20220094702A1 · Saad Ahmed et al. · 2022 [cited by applicant]
US 20220100332A1 · Haworth et al. · 2022 [cited by applicant]
US 20220116419A1 · Kelm et al. · 2022 [cited by applicant]
US 20220130274A1 · Krishna Raju et al. · 2022 [cited by applicant]
US 20220286419A1 · Stetzer et al. · 2022 [cited by applicant]
EP 3582468A1 · 2019 [cited by applicant]
WO WO2016164844A1 · 2016 [cited by applicant]
Abu-Nimeh et al., “A Comparison of Machine Learning Techniques for Phishing Detection,” eCrime '07: Proceedings of the anti-phishing working groups 2nd annual eCrime researchers summit, Oct. 4-5, 2007, pp. 60-69, ACM Di… [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 17/829,925 dtd Mar. 15, 2023. [cited by applicant]
Notice of Allowance on U.S. Appl. No. 17/347,158 dtd Feb. 27, 2023. [cited by applicant]
Palka et al., “Dynamic phishing content using generative grammars,” Software Testing, Verification and Validation Workshops (ICSTW), 2015 IEEE Eighth International Conference, Date of Conference: Apr. 13-17, 2015, IEEE … [cited by applicant]
US Final Office Action on U.S. Appl. No. 16/135,757 dated Apr. 25, 2019 (7 Pages). [cited by applicant]
US Final Office Action on U.S. Appl. No. 16/746,662 dated Jun. 18, 2020 (9 Pages). [cited by applicant]
US Final Office Action on U.S. Appl. No. 17/347,158 dated Mar. 4, 2022 (10 Pages). [cited by applicant]
US Final Office Action on U.S. Appl. No. 17/347,158 dated Nov. 7, 2022 (6 Pages). [cited by applicant]
US Non-Final Office Action on U.S. Appl. No. 16/135,757 dated Nov. 29, 2018 (7 Pages). [cited by applicant]
US Non-Final Office Action on U.S. Appl. No. 16/746,662 dated Apr. 1, 2020 (9 Pages). [cited by applicant]
US Non-Final Office Action on U.S. Appl. No. 17/347,158 dated Jun. 24, 2022 (10 Pages). [cited by applicant]
US Non-Final Office Action on U.S. Appl. No. 17/347,158 dated Oct. 28, 2021 (10 Pages). [cited by applicant]
US Notice of Allowance on U.S. Appl. No. 16/135,757 dated Aug. 12, 2019 (10 Pages). [cited by applicant]
US Notice of Allowance on U.S. Appl. No. 16/135,757 dated Nov. 20, 2019 (8 Pages). [cited by applicant]
US Notice of Allowance on U.S. Appl. No. 16/746,662 dated Apr. 19, 2021 (8 Pages). [cited by applicant]
US Office Action on U.S. Appl. No. 16/746,662 dated Dec. 28, 2020 (6 Pages). [cited by applicant]