IP Library › Granted Patent US 12,596,981
Granted Patent B1
US 12,596,981 · App. 18/762,012 · Granted Apr 7, 2026

Pre-data breach monitoring

Inventors: Michael John Dean (Torrance, CA); Mark Joseph Kapczynski (Santa Monica, CA)
Assignee: ConsumerInfo.com, Inc.
G06Q10/0635G06F16/958G06F21/604G06Q10/105G06Q30/0205G06Q50/01G06Q50/265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,981
App. No.
18/762,012
Granted
Apr 7, 2026
Kind
B1
Abstract

A method for providing pre-data breach monitoring provides information to businesses that is useful to predict portions of the company data that may not be secured well enough and other risks associated with data breaches, such as employees that may not be trustworthy.

Claims (43)

1 . A computer-implemented method comprising:

retrieving information identifying each of a plurality of individuals associated with an entity;

scanning a plurality of data sources for information regarding the plurality of individuals associated with the entity, wherein the plurality of data sources that are scanned include one or more dark web data sources that are accessible via particular browsing software, wherein automatically scanning the one or more dark web data sources comprises:

executing a particular browser that is configured to access dark address space that is not accessible via a standard browser configured to access public internet data sources; and

scanning at least a subset of the dark address space accessed via execution of the particular browser for at least a portion of data regarding the plurality of individuals;

generating a score for at least one of (a) a particular individual of the plurality of individuals or (b) the entity associated with the plurality of individuals, wherein the score is generated based at least in part on each of two or more categories of information found during the scanning of the plurality of data sources; and

based at least in part on the score, providing a notification to at least one of (i) the particular individual or (ii) the entity associated with the plurality of individuals, wherein the notification includes an indication of whether at least one of the scanning or the score suggests a likelihood that personal information has been compromised.

2 . The computer-implemented method of claim 1 , wherein the plurality of individuals are associated with a company, wherein the entity is the company.

3 . The computer-implemented method of claim 2 , wherein the method further comprises:

periodically automatically scanning the plurality of data sources with respect to other individuals associated with each of a plurality of other entities, wherein the plurality of other entities are similar to the entity in one or more categories; and

comparing the score for the entity to scores determined for the plurality of other entities.

4 . The computer-implemented method of claim 1 , wherein the plurality of data sources further comprise public internet data sources.

5 . The computer-implemented method of claim 1 , wherein the score is based at least in part on a difference in quantity of information found in the scanning relative to a prior quantity of information found in a prior scan.

6 . The computer-implemented method of claim 1 , wherein the notification comprises an indication of a change in the score over time.

7 . The computer-implemented method of claim 1 , further comprising determining a quantity of located data via the scanning for each of a plurality of data breach risk categories.

8 . The computer-implemented method of claim 1 , wherein the two or more categories of information include at least three of: public internet, dark web, social media sites, sex offender databases, heath care, or fraudulent activity sites.

9 . The computer-implemented method of claim 1 , further comprising tracking a potential data breach to a particular data source holding a portion of data associated with one or more of the plurality of individuals.

10 . The computer-implemented method of claim 1 , further comprising tracking a potential data breach over time, and in response to determining that a change to the score exceeds a threshold, generate another notification indicative of the change.

11 . The computer-implemented method of claim 1 , wherein generating the score comprises applying weights to different categories of information.

12 . A computing system comprising:

memory; and

a hardware processor configured to execute computer-executable instructions to:

retrieve information identifying each of a plurality of individuals associated with an entity;

scan a plurality of data sources for information regarding the plurality of individuals associated with the entity, wherein the plurality of data sources that are scanned include one or more dark web data sources that are accessible via particular browsing software, wherein automatically scanning the one or more dark web data sources comprises:

executing a particular browser that is configured to access dark address space that is not accessible via a standard browser configured to access public internet data sources; and

scanning at least a subset of the dark address space accessed via execution of the particular browser for at least a portion of data regarding the plurality of individuals;

generate a score for at least one of (a) a particular individual of the plurality of individuals or (b) the entity associated with the plurality of individuals, wherein the score is generated based at least in part on each of two or more categories of information found during the scanning of the plurality of data sources; and

based at least in part on the score, provide a notification to at least one of (i) the particular individual or (ii) the entity associated with the plurality of individuals, wherein the notification includes an indication of whether at least one of the scanning or the score suggests a likelihood that personal information has been compromised.

13 . The computing system of claim 12 , wherein generating the score comprises determining a plurality of scores that are each associated with a different data breach risk category of a plurality of data breach risk categories.

14 . The computing system of claim 13 , wherein a first of the plurality of data breach risk categories is associated with the public internet data sources, and wherein a second of the plurality of data breach risk categories is associated with the dark web data sources.

15 . The computing system of claim 14 , wherein a third of the plurality of data breach risk categories is associated with social media sources.

16 . The computing system of claim 13 , wherein the score is an average of the plurality of data breach category risk scores.

17 . The computing system of claim 13 , wherein a first of the plurality of data breach risk categories is weighted more heavily in determining the score than a second of the plurality of data breach risk categories.

18 . A non-transitory computer-readable medium storing computer executable instructions that, when executed by one or more computer systems, configure the one or more computer systems to perform operations comprising:

retrieving information identifying each of a plurality of individuals associated with an entity;

scanning a plurality of data sources for information regarding the plurality of individuals associated with the entity, wherein the plurality of data sources that are scanned include one or more dark web data sources that are accessible via particular browsing software, wherein automatically scanning the one or more dark web data sources comprises:

executing a particular browser that is configured to access dark address space that is not accessible via a standard browser configured to access public internet data sources; and

scanning at least a subset of the dark address space accessed via execution of the particular browser for at least a portion of data regarding the plurality of individuals;

generating a score for at least one of (a) a particular individual of the plurality of individuals or (b) the entity associated with the plurality of individuals, wherein the score is generated based at least in part on each of two or more categories of information found during the scanning of the plurality of data sources; and

based at least in part on the score, providing a notification to at least one of (i) the particular individual or (ii) the entity associated with the plurality of individuals, wherein the notification includes an indication of whether at least one of the scanning or the score suggests a likelihood that personal information has been compromised.

19 . The non-transitory computer-readable medium of claim 18 , wherein the operations further comprise:

providing the entity with an option to present a badge on a webpage provided by the entity, the badge indicating that the entity has taken measures to reduce risks of data breach in association with the automatically scanning of the plurality of data sources.

20 . The non-transitory computer-readable medium of claim 18 , wherein generating the score comprises determining a plurality of category risk scores that are each associated with a different category of information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2025
From: KAPCZYNSKI, MARK JOSEPH; DEAN, MICHAEL JOHN
To: CONSUMERINFO.COM, INC.
Reel/Frame 072628/0843 →
Continuity (5)
Continuation 18148073 · Dec 29, 2022
Continuation 17313775 · May 6, 2021
Continuation 16657057 · Oct 18, 2019
Continuation 13665636 · Oct 31, 2012
Provisional Application 61553761 · Oct 31, 2011
References Cited (65)
US 7433864B2 · Malik · 2008 [cited by examiner]
US 8473415B2 · Siegel · 2013 [cited by examiner]
US 8607353B2 · Rippert, Jr. · 2013 [cited by examiner]
US 8676699B2 · Philips · 2014 [cited by examiner]
US 8850539B2 · Bailey, Jr. · 2014 [cited by examiner]
US 8949981B1 · Trollope · 2015 [cited by examiner]
US 11941635B1 · Coleman et al. · 2024 [cited by applicant]
US 12045755B1 · Dean et al. · 2024 [cited by applicant]
US 12099940B1 · Chen et al. · 2024 [cited by applicant]
US 20050278786A1 · Tippett · 2005 [cited by examiner]
US 20060020814A1 · Lieblich · 2006 [cited by examiner]
US 20080103800A1 · Domenikos · 2008 [cited by examiner]
US 20090292568A1 · Khosravani et al. · 2009 [cited by applicant]
US 20100188684A1 · Kumara · 2010 [cited by examiner]
US 20100250509A1 · Andersen · 2010 [cited by examiner]
US 20100281248A1 · Lockhart et al. · 2010 [cited by applicant]
US 20100293090A1 · Domenikos · 2010 [cited by examiner]
US 20110131123A1 · Griffin · 2011 [cited by examiner]
US 20120198556A1 · Patel · 2012 [cited by examiner]
US 20130132060A1 · Badhe · 2013 [cited by examiner]
US 20140143134A1 · Yan · 2014 [cited by applicant]
US 20140180883A1 · Regan · 2014 [cited by applicant]
US 20150033297A1 · Sanso et al. · 2015 [cited by applicant]
US 20160063634A1 · Calibey · 2016 [cited by applicant]
US 20160125412A1 · Cannon · 2016 [cited by applicant]
US 20170161520A1 · Lockhart, III · 2017 [cited by applicant]
US 20170161746A1 · Cook · 2017 [cited by applicant]
US 20170331839A1 · Park et al. · 2017 [cited by applicant]
US 20180027001A1 · Park et al. · 2018 [cited by applicant]
US 20180131708A1 · Pirttilahti et al. · 2018 [cited by applicant]
US 20180218369A1 · Xiao et al. · 2018 [cited by applicant]
US 20190354982A1 · Gómez · 2019 [cited by applicant]
US 20190385170A1 · Arrabothu et al. · 2019 [cited by applicant]
US 20200005310A1 · Kumar et al. · 2020 [cited by applicant]
US 20200110870A1 · Girdhar · 2020 [cited by applicant]
US 20210150056A1 · Vax · 2021 [cited by applicant]
US 20210182857A1 · Tiwan · 2021 [cited by applicant]
US 20220180368A1 · Immaneni · 2022 [cited by applicant]
US 20230008975A1 · Crudele · 2023 [cited by applicant]
US 20230283628A1 · Johnston · 2023 [cited by applicant]
US 20230342605A1 · Sankaran et al. · 2023 [cited by applicant]
US 20230362014A1 · Knopf · 2023 [cited by applicant]
US 20230388131A1 · Knopf · 2023 [cited by applicant]
US 20230403276A1 · Vbh et al. · 2023 [cited by applicant]
AU 2011203185 · 2011 [cited by applicant]
AU 2021215125 · 2021 [cited by applicant]
EP 3092569 · 2024 [cited by applicant]
WO WO2008028179 · 2008 [cited by applicant]
WO WO2018163162 · 2018 [cited by applicant]
WO WO2019018420 · 2019 [cited by applicant]
WO WO2022261600 · 2022 [cited by applicant]
Security Risk Management in Online System; Computational Science/Intelligence and Applied Informatics/2nd Intl Conf on Big Data, Cloud Computing, Data Science (ACIT-CSII-BCD) (pp. 119-124); Arwa K. AlSalamah; Jul. 9, 20… [cited by examiner]
Exploring User Behavior and Cybersecurity Knowledge—An experimental study in Online Shopping; 2018 16th Annual Conference on Privacy, Security and Trust (PST) (pp. 1-10); Ghada El Haddad, Amin Shahab, Esma Aimeur; Aug. … [cited by examiner]
International Preliminary Report on Patentability in Application No. PCT/US2022/024277, dated Oct. 26, 2023. [cited by applicant]
Al-Zaben et al., “General Data Protection Regulation Complied Blockchain Architecture for Personally Identifiable Information Management,” 2018 International Conference on Computing, Electronics & Communications Enginee… [cited by applicant]
Chatzigeorgiou et al., “A Communication Gateway Architecture for Ensuring Privacy and Confidentiality in Incident Reporting,” 2017 IEEE 15th International Conference on Software Engineering Research, Management and Appl… [cited by applicant]
Chen et al., “Statistical Analysis of Identity Risk of Exposure and Cost Using the Ecosystem of Identity Attributes,” 2019 European Intelligence and Security Informatics Conference (EISIC), Oulu, Finland, 2019, pp. 32-3… [cited by applicant]
Crane et al., “A Customizable Reputation-based Privacy Assurance System using Active Feedback,” 2006 Securecomm and Workshops, Baltimore, MD, USA, 2006, pp. 1-8. [cited by applicant]
Li, “Threats and data trading detection methods in the dark web,” 2021 6th International Conference on Innovative Technology in Intelligent System and Industrial Applications (CITISIA), Sydney, Australia, 2021, pp. 1-9. [cited by applicant]
Peterson et al., “Introduction to Identity Management Risk Metrics,” in IEEE Security & Privacy, vol. 4, No. 4, Jul.-Aug. 2006, pp. 88-91. [cited by applicant]
Sakapertana et al., “Improving Rest API Security and Software Integrity through Automated PII Detection Tool Using Machine Learning Techniques,” 2025(ICoCSETI), Jakarta, Indonesia, 2025, pp. 404-409. [cited by applicant]
Sherly et al., “BOAT Adaptive Credit Card Fraud Detection System”, 2010 IEEE International Conference on Computational Intelligence and Computing Research, Dec. 2010, p. 7. [cited by applicant]
Silva et al., “Privacy in the Cloud: A Survey of Existing Solutions and Research Challenges,” in IEEE Access, vol. 9, 2021, pp. 10473-10497. [cited by applicant]
Trabelsi, “Monitoring Leaked Confidential Data,” 2019 10th IFIP International Conference on New Technologies, Mobility and Security (NTMS), Canary Islands, Spain, 2019, pp. 1-5. [cited by applicant]
Xu et al., “Research on Dark Web Monitoring Crawler Based on TOR,” 2021 IEEE 2nd International Conference on Information Technology, Big Data and Artificial Intelligence (ICIBA), Chongqing, China, 2021, pp. 197-202. [cited by applicant]