EP4139801A1

Detection and prevention of external fraud

Abstract

This record has no abstract on file.

EP4139801A1, drawing sheet 1
Sheet 1 of 27

Term

14.6 yearsto projected expiry

Projected expiry 23 April 2041, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

26 claims: 4 independent, 22 dependent

  1. 1
    Claims of equivalent WO 2021217049 A1 CLAIMSWhat is claimed is:1. A method comprising: obtaining an email that is addressed to a first email account associated with an enterprise;establishing that the email represents an instance of outreach by a second email account associated with a vendor for payment of an invoice by the enterprise;obtaining a metric that is indicative of the risk in communicating with the second email account based on a comparison of the email to a series of emails that are representative of past instances of outreach by the second email account;and determining, based on the metric, how to handle the email.
  2. 9
    A non-transitory medium with instructions stored thereon that, when executed by a processor of a computing device, cause the computing device to perform operations comprising:obtaining an email that is addressed to a first email account associated with an enterprise;establishing that the email was sent with a second email account associated with a vendor by examining content of the email;accessing a database to identify a digital profile that includes a record of past emails sent with the second email account;and determining, based on the digital profile, whether the email differs from the past emails in terms of context and/or content to such a degree that compromise of the second email account is likely.
  3. 17
    A method comprising:obtaining, by a threat detection platform, a first set of emails received by employees of an enterprise;examining, by the threat detection platform, content of the first set of emails so as to identify a second set of emails that contain invoices, wherein the second set of emails is a subset of the first set of emails;receiving, by the threat detection platform, input indicative of labels for the second set of emails that are provided through an interface, wherein each label indicates whether the corresponding email is representative of a legitimate request for payment;and training, by the threat detection platform, a model to identify legitimate requests for payment by providing (i) the second set of emails and (ii) the labels to the model as training data.
  4. 19
    A non-transitory medium with instructions stored thereon that, when executed by a processor of a computing device, cause the computing device to perform operations comprising:obtaining an email that is addressed to an email account associated with an enterprise;examining the email so as to identify a domain from which the email originated;determining, based on the domain, whether the email is representative of an attempt to impersonate a vendor;and prohibiting the email from reaching an inbox of the email account responsive to a determination that the email is representative of an attempt to impersonate the vendor.