IP Library Granted Patent US 9,800,613
Granted Patent B1
US 9,800,613 · App. 15/636,135 · Granted Oct 24, 2017

Systems and methods for performing a simulated phishing attack

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,800,613
App. No.
15/636,135
Granted
Oct 24, 2017
Kind
B1
Abstract

Systems and methods for performing a simulated phishing attack are provided. A simulated attack server can send a simulated attack email including a unique identifier to a target. The simulated attack server can receive a reply email including the unique identifier from the target. The simulated attack server can extract the unique identifier from the reply email. The simulated attack server can determine a match between the unique identifier and an identity of the target. The simulated attack server can record a target failure, responsive to determining the match between the unique identifier and the identity of the target.

Claims (52)

1. A method for identifying users that reply to a simulated phishing email, the method comprising:

(a) establishing, by one or more servers comprising a processor coupled to memory, a unique identifier for each user of a plurality of users to receive a simulated phishing email via a simulated phishing campaign;

(b) generating, by the one or more servers, for each user of the plurality of users a simulated phishing email to comprise the unique identifier of the respective user embedded in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email;

(c) communicating, by the one or more servers, the respective simulated phishing email to an email account corresponding to each user of the plurality of users, the respective simulated phishing email comprising an email address in a to field that corresponds to the one or more servers;

(d) receiving, by the one or more servers, a reply email to the email address communicated responsive to the respective simulated phishing email from the email account of at least one user of the plurality of users, the reply email comprising the unique identifier; and

(e) determining by the one or more servers, that the at least one user has replied to the simulated phishing email by comparing the unique identifier embedded in the reply email to the unique identifier established by the one or more servers for the at least one user.

2. The method of claim 1 , wherein (a) further comprises establishing, by the one or more servers, the unique identifier to identify a user corresponding to one or more email accounts.

3. The method of claim 1 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user to be invisible in the body of the simulated phishing email.

4. The method of claim 1 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in a file name of the attachment.

5. The method of claim 1 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in content of the attachment.

6. The method of claim 1 , wherein (d) further comprises receiving, by the one or more servers, the reply email sent to a domain of or hosted by the one or more servers.

7. The method of claim 1 , wherein (e) further comprises identifying, by the one or more servers, the unique identifier embedded in at least one of the subject line of the simulated phishing email, the body of the simulated phishing email or the attachment of the simulated phishing email.

8. A system for identifying users that reply to a simulated phishing email, the system comprising:

one or more servers comprising a processor coupled to memory, and configured to establish a unique identifier for each user of a plurality of users to receive a simulated phishing email via a simulated phishing campaign;

a campaign manager of the one or more servers configured to:

generate for each user of the plurality of users a simulated phishing email to comprise the unique identifier of the respective user embedded in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email; and

communicate the respective simulated phishing email to an email account corresponding to each user of the plurality of users, the respective simulated phishing email comprising an email address in a to field that corresponds to the one or more servers;

wherein the one or more servers are configured to receive a reply email to the email address communicated responsive to the respective simulated phishing email from the email account of at least one user of the plurality of users, the reply email comprising the unique identifier; and

wherein the campaign manager is configured to determine that the at least one user has replied to the simulated phishing email by comparing the unique identifier embedded in the reply email to the unique identifier established by the one or more servers for the at least one user.

9. The system of claim 8 , wherein the one or more servers are further configured to establish the unique identifier to identify a user corresponding to one or more email accounts.

10. The system of claim 8 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user to be invisible in the body of the simulated phishing email.

11. The system of claim 8 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user in a file name of the attachment.

12. The system of claim 8 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user in content of the attachment.

13. The system of claim 8 , wherein the one or more servers are further configured to receive the reply email sent to a domain of or hosted by the one or more servers.

14. The system of claim 8 , wherein the campaign manager is further configured to identify the unique identifier embedded in at least one of the subject line of the simulated phishing email, the body of the simulated phishing email or the attachment of the simulated phishing email.

15. A method for identifying users that reply to a simulated phishing email, the method comprising:

(a) establishing, by one or more servers comprising a processor coupled to memory, a unique identifier for each user of a plurality of users to receive a simulated phishing email via a simulated phishing campaign;

(b) generating, by the one or more servers, for each user of the plurality of users a simulated phishing email to comprise the unique identifier of the respective user embedded in an email address of one of a plurality of address fields of the simulated phishing email;

(c) communicating, by the one or more servers, the respective simulated phishing email to an email account corresponding to each user of the plurality of users, the respective simulated phishing email comprising an email address in a to field that corresponds to the one or more servers;

(d) receiving, by the one or more servers, a reply email to the email address communicated responsive to the respective simulated phishing email from the email account of at least one user of the plurality of users, the reply email comprising the unique identifier in an address field of the plurality of address fields; and

(e) determining by the one or more servers, that the at least one user has replied to the simulated phishing email by comparing the unique identifier embedded in the email address field of the reply email to the unique identifier established by the one or more servers for the at least one user.

16. The method of claim 15 , wherein (a) further comprises establishing, by the one or more servers, the unique identifier to identify one or more email accounts.

17. The method of claim 15 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in a to field of the simulated phishing email.

18. The method of claim 15 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in a cc field of the simulated phishing email.

19. The method of claim 15 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user prior to an @ sign in the email address in one of the plurality of address fields.

20. The method of claim 15 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user after an @ sign in the email address in one of the plurality of address fields.

21. The method of claim 15 , wherein (d) further comprises receiving, by the one or more servers, the reply email sent to a domain of or hosted by the one or more servers.

22. The method of claim 15 , wherein (e) further comprises identifying, by the one or more servers, the unique identifier embedded in the address field of the simulated phishing email comprising one of a from field or a cc field.

23. A system for identifying users that reply to a simulated phishing email, the system comprising:

one or more servers comprising a processor coupled to memory and configured to establish a unique identifier for each user of a plurality of users to receive a simulated phishing email via a simulated phishing campaign;

a campaign manager of the one or more servers configured to:

generate for each user of the plurality of users a simulated phishing email to comprise the unique identifier of the respective user embedded in an email address of one of a plurality address fields of the simulated phishing email; and

communicate the respective simulated phishing email to an email account corresponding to each user of the plurality of users, the respective simulated phishing email comprising an email address in a to field that corresponds to the one or more servers;

wherein the one or more servers are configured to receive a reply email to the email address communicated responsive to the respective simulated phishing email from the email account of at least one user of the plurality of users, the reply email comprising the unique identifier in an address field of the plurality of address field; and

wherein the campaign manager is further configured to determine that the at least one user has replied to the simulated phishing email by comparing the unique identifier embedded in the address field of the reply email to the unique identifier established by the one or more servers for the at least one user.

24. The system of claim 23 , wherein the one or more servers are further configured to generate the unique identifier to identify one or more email accounts.

25. The system of claim 23 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user in a to field of the simulated phishing email.

26. The system of claim 23 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user in a cc field of the simulated phishing email.

27. The system of claim 23 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user prior to an @ sign in the email address in one of the plurality of address fields.

28. The system of claim 23 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user after an @ sign in the email address in one of the plurality of address fields.

29. The system of claim 23 , wherein the one or more servers are further configured to receive the reply email sent to a domain of or hosted by the one or more servers.

30. The system of claim 23 , wherein the campaign manager is further configured to identify the unique identifier embedded in the address field of the simulated phishing email comprising one of a from field or a cc field.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2017
From: IRIMIE, ALIN; JACK, BRIAN; SJOUWERMAN, STU
To: KNOWBE4, INC.
Reel/Frame 042852/0977 →