IP Library Granted Patent US 12,627,708
Granted Patent B2
US 12,627,708 · App. 17/981,743 · Granted May 12, 2026

Systems, methods, and apparatuses for detection of data misappropriation attempts across electronic communication platforms

Inventors: Jinna Zevulun Kim (Charlotte, NC); Katherine Kei-Zen Dintenfass (Lincoln, RI); Jo-Ann Taylor (Godalming, GB); Christine D. Black (Brooksville, ME); Jennifer Tiffany Renckert (Middleburg, FL); Vijaya L. Vemireddy (Plano, TX)
Assignee: BANK OF AMERICA CORPORATION
H04L63/1483G06F40/205H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,708
App. No.
17/981,743
Granted
May 12, 2026
Kind
B2
Abstract

Systems, computer program products, and methods are described herein for detection of data misappropriation attempts across electronic communication platforms. The present invention is configured to identify a recipient user account, wherein the recipient user account has received a current communication; parse the current communication to identify at least one order for the recipient user account; identify at least one potential outcome based on the at least one order for the recipient user account; determine the potential outcome comprises a misappropriation; apply a misappropriation attempt engine to the current communication; and generate, by the misappropriation attempt engine, a misappropriation attempt rating for the current communication.

Claims (76)

1 . A system for detection of data misappropriation attempts across electronic communication platforms, the system comprising:

a memory device with computer-readable program code stored thereon;

at least one processing device operatively coupled to the memory device and at least one communication device, wherein executing the computer-readable program code is configured to cause the at least one processing device to:

identify a recipient user account and an associated recipient account identifier, wherein the recipient user account has received a current communication;

identify recipient account characteristics associated with the recipient account identifier;

parse the current communication to identify at least one order for the recipient user account;

identify at least one potential outcome based on the at least one order for the recipient user account;

determine the potential outcome comprises a misappropriation;

collect a set of previous recipient account identifiers associated with a set of previous threat communications and a set of previous recipient account characteristics associated with the set of previous recipient account identifiers;

create a recipient account threat training data set comprising the collected set of previous recipient account identifiers and the set of previous recipient account characteristics;

train a misappropriation attempt engine using the recipient account threat training data set;

apply the trained misappropriation attempt engine to the current communication, wherein the application of the trained misappropriation attempt engine comprises an analysis of the recipient account characteristics compared to the set of previous recipient account characteristics;

determine, by the trained misappropriation attempt engine, one or more of the recipient account characteristics matches at least one of the set of previous recipient account characteristics; and

generate, by the misappropriation attempt engine, a misappropriation attempt rating for the current communication based on the potential outcome comprising the misappropriation and the matching, using the trained misappropriation attempt engine, of the one or more recipient account characteristics with at least one of the set of previous recipient account characteristics.

2 . The system of claim 1 , wherein the current communication comprises at least one of a verbal electronic communication or an electronic message communication.

3 . The system of claim 1 , wherein the determination the potential outcome comprises a misappropriation further comprises an acceptance by the recipient user account of the at least one order of the current communication.

4 . The system of claim 1 , wherein the processing device is further configured to:

collect a set of previous threat communications, wherein the set of previous threat communications comprise at least one background tactic type;

create a background tactic training data set comprising the collected set of previous threat communications; and

train the misappropriation attempt engine using the background tactic training data set.

5 . The system of claim 4 , wherein the at least one background tactic type comprises at least one of a threat communication marker, a threat communication tone, a threat communication language, a threat communication noise, or a threat communication request type.

6 . The system of claim 5 , wherein the processing device is further configured to:

receive at least one current background tactic type associated with the current communication;

apply the at least one current background tactic type to the misappropriation attempt engine; and

generate, by the misappropriation attempt engine, the misappropriation attempt rating of the current communication based on the at least one current background tactic type.

7 . The system of claim 1 , wherein the processing device is further configured to:

collect a set of previous threat communications, wherein the set of previous threat communications comprise at least one previous order and at least one previous outcome;

create a previous outcome training data set comprising the collected set of previous threat communications; and

train the misappropriation attempt engine with the previous outcome training data set.

8 . The system of claim 1 , wherein the processing device is further configured to:

identify a current recipient account identifier based on the recipient user account associated with the current communication;

apply the current recipient account identifier to the misappropriation attempt engine; and

generate, by the misappropriation attempt engine, the misappropriation attempt rating of the current communication based on the current recipient account identifier.

9 . The system of claim 1 , wherein the processing device is further configured to:

collect a set of previous unverified sender account identifiers associated with a set of previous threat communications;

create a sender account threat training data set comprising the collected set of previous unverified sender account identifiers; and

train the misappropriation attempt engine using the sender account threat training data set.

10 . The system of claim 9 , wherein the processing device is further configured to:

identify a current unverified sender account identifier associated with the current communication;

transmit an authentication request to a verified sender user account associated with the unverified sender account identifier;

receive an authentication response from the verified sender user account; and

generate, based on the authentication response from the verified sender user account, a misappropriation attempt rating of the current communication.

11 . The system of claim 10 , wherein the misappropriation attempt rating of the current communication comprises a high rating, in an instance the authentication response comprises a negative response.

12 . The system of claim 10 , wherein the misappropriation attempt rating of the current communication comprises a low rating, in an instance the authentication response comprises a positive response.

13 . A computer program product for detection of data misappropriation attempts across electronic communication platforms, wherein the computer program product comprises at least one non-transitory computer-readable medium having computer-readable program code portions embodied therein, the computer-readable program code portions which when executed by a processing device are configured to cause the processing device to:

identify a recipient user account and an associated recipient account identifier, wherein the recipient user account has received a current communication;

identify recipient account characteristics associated with the recipient account identifier;

parse the current communication to identify at least one order for the recipient user account;

identify at least one potential outcome based on the at least one order for the recipient user account;

determine the potential outcome comprises a misappropriation;

collect a set of previous recipient account identifiers associated with a set of previous threat communications and a set of previous recipient account characteristics associated with the set of previous recipient account identifiers;

create a recipient account threat training data set comprising the collected set of previous recipient account identifiers and the set of previous recipient account characteristics;

train a misappropriation attempt engine using the recipient account threat training data set;

apply the trained misappropriation attempt engine to the current communication, wherein the application of the trained misappropriation attempt engine comprises an analysis of the recipient account characteristics compared to the set of previous recipient account characteristics;

determine, by the trained misappropriation attempt engine, one or more of the recipient account characteristics matches at least one of the set of previous recipient account characteristics; and

generate, by the misappropriation attempt engine, a misappropriation attempt rating for the current communication based on the potential outcome comprising the misappropriation and the matching, using the trained misappropriation attempt engine, of the one or more recipient account characteristics with at least one of the set of previous recipient account characteristics.

14 . The computer program product of claim 13 , wherein the current communication comprises at least one of a verbal electronic communication or an electronic message communication.

15 . The computer program product of claim 13 , wherein the determination the potential outcome comprises a misappropriation further comprises an acceptance by the recipient user account of the at least one order of the current communication.

16 . The computer program product of claim 13 , wherein the processing device is further configured to cause the processing device to:

collect a set of previous threat communications, wherein the set of previous threat communications comprise at least one background tactic type;

create a background tactic training data set comprising the collected set of previous threat communications; and

train the misappropriation attempt engine using the background tactic training data set.

17 . A computer-implemented method for detection of data misappropriation attempts across electronic communication platforms, the computer-implemented method comprising:

identifying a recipient user account and an associated recipient account identifier, wherein the recipient user account has received a current communication;

identifying recipient account characteristics associated with the recipient account identifier;

parsing the current communication to identify at least one order for the recipient user account;

identifying at least one potential outcome based on the at least one order for the recipient user account;

determining the potential outcome comprises a misappropriation;

collecting a set of previous recipient account identifiers associated with a set of previous threat communications and a set of previous recipient account characteristics associated with the set of previous recipient account identifiers;

creating a recipient account threat training data set comprising the collected set of previous recipient account identifiers and the set of previous recipient account characteristics;

training a misappropriation attempt engine using the recipient account threat training data set;

applying the trained misappropriation attempt engine to the current communication, wherein the application of the trained misappropriation attempt engine comprises an analysis of the recipient account characteristics compared to the set of previous recipient account characteristics;

determining, by the trained misappropriation attempt engine, one or more of the recipient account characteristics matches at least one of the set of previous recipient account characteristics; and

generating, by the misappropriation attempt engine, a misappropriation attempt rating for the current communication based on the potential outcome comprising the misappropriation and the matching, using the trained misappropriation attempt engine, of the one or more recipient account characteristics with at least one of the set of previous recipient account characteristics.

18 . The computer-implemented method of claim 17 , wherein the current communication comprises at least one of a verbal electronic communication or an electronic message communication.

19 . The computer-implemented method of claim 17 , wherein the determination the potential outcome comprises a misappropriation further comprises an acceptance by the recipient user account of the at least one order of the current communication.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2022
From: KIM, JINNA ZEVULUN; DINTENFASS, KATHERINE KEI-ZEN; TAYLOR, JO-ANN; BLACK, CHRISTINE D.; RENCKERT, JENNIFER TIFFANY; VEMIREDDY, VIJAYA L.
To: BANK OF AMERICA CORPORATION
Reel/Frame 061675/0657 →
Continuity (1)
Related Publication 20240155000A1 · May 9, 2024
References Cited (68)
US 9270696B2 · Fritzson · 2016 [cited by applicant]
US 9356947B2 · Shraim · 2016 [cited by applicant]
US 9635052B2 · Hadnagy · 2017 [cited by applicant]
US 9684888B2 · Shraim · 2017 [cited by applicant]
US 9787714B2 · Bach · 2017 [cited by applicant]
US 10033693B2 · Sengupta · 2018 [cited by applicant]
US 10158677B1 · DiCorpo · 2018 [cited by applicant]
US 10193923B2 · Wright · 2019 [cited by applicant]
US 10277628B1 · Jakobsson · 2019 [cited by examiner]
US 10404745B2 · Verma · 2019 [cited by applicant]
US 10574684B2 · Segal · 2020 [cited by applicant]
US 10708297B2 · Woods · 2020 [cited by examiner]
US 10805314B2 · Jakobsson · 2020 [cited by applicant]
US 10868820B2 · Sites · 2020 [cited by applicant]
US 10924517B2 · Epple · 2021 [cited by applicant]
US 10944789B2 · Correa Bahnsen · 2021 [cited by applicant]
US 10992780B1 · Rudrappa Goniwada · 2021 [cited by examiner]
US 11044267B2 · Jakobsson · 2021 [cited by applicant]
US 11159558B2 · Basavapatna · 2021 [cited by applicant]
US 11431738B2 · Jeyakumar · 2022 [cited by examiner]
US 11936604B2 · Jakobsson · 2024 [cited by examiner]
US 12074898B1 · Diao · 2024 [cited by examiner]
US 20070061125A1 · Bhatt · 2007 [cited by examiner]
US 20070078936A1 · Quinlan · 2007 [cited by examiner]
US 20110252043A1 · Webb-Johnson · 2011 [cited by examiner]
US 20120185611A1 · Reynolds · 2012 [cited by examiner]
US 20120278887A1 · Vitaldevara · 2012 [cited by examiner]
US 20160014151A1 · Prakash · 2016 [cited by examiner]
US 20160105396A1 · Hastings · 2016 [cited by examiner]
US 20170063920A1 · Thomas · 2017 [cited by applicant]
US 20170180398A1 · Gonzales, Jr. · 2017 [cited by examiner]
US 20180091453A1 · Jakobsson · 2018 [cited by examiner]
US 20180227324A1 · Chambers · 2018 [cited by examiner]
US 20180253659A1 · Lee · 2018 [cited by examiner]
US 20190020671A1 · Komárek · 2019 [cited by examiner]
US 20190068616A1 · Woods · 2019 [cited by examiner]
US 20190199745A1 · Jakobsson · 2019 [cited by examiner]
US 20190238571A1 · Adir · 2019 [cited by examiner]
US 20190244175A1 · Ogrinz · 2019 [cited by examiner]
US 20190281056A1 · Kursun · 2019 [cited by examiner]
US 20190311277A1 · Kursun · 2019 [cited by examiner]
US 20200012917A1 · Pham · 2020 [cited by examiner]
US 20200068031A1 · Kursun · 2020 [cited by examiner]
US 20200211076A1 · Eakin · 2020 [cited by examiner]
US 20200216027A1 · Deng · 2020 [cited by examiner]
US 20200311265A1 · Jones · 2020 [cited by applicant]
US 20200344251A1 · Jeyakumar · 2020 [cited by examiner]
US 20200349573A1 · Dong · 2020 [cited by examiner]
US 20200358820A1 · Kolingivadi · 2020 [cited by examiner]
US 20210075805A1 · Cavallari · 2021 [cited by examiner]
US 20210185078A1 · Sjouwerman · 2021 [cited by applicant]
US 20210266345A1 · Chen · 2021 [cited by examiner]
US 20210329015A1 · Devane · 2021 [cited by examiner]
US 20220094713A1 · Lee · 2022 [cited by examiner]
US 20220116420A1 · Weber · 2022 [cited by examiner]
US 20220279015A1 · Sambamoorthy · 2022 [cited by examiner]
US 20220400094A1 · Sampath · 2022 [cited by examiner]
US 20230025446A1 · Freire · 2023 [cited by examiner]
US 20230171212A1 · Hathaway · 2023 [cited by examiner]
US 20230179628A1 · Porras · 2023 [cited by examiner]
US 20230273843A1 · Srivastava · 2023 [cited by examiner]
US 20240046397A1 · McCurry · 2024 [cited by examiner]
US 20240056477A1 · Rangwala · 2024 [cited by examiner]
US 20240155000A1 · Kim · 2024 [cited by examiner]
US 20240179159A1 · Hulcoop · 2024 [cited by examiner]
US 20240223594A1 · Picard · 2024 [cited by examiner]
US 20250274467A1 · Francisco · 2025 [cited by examiner]
EP 1999609B1 · 2018 [cited by applicant]