7:26-cv-00275
Zapfraud Inc v. Trend Micro Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: ZapFraud, Inc. (Delaware)
- Defendant: Trend Micro Incorporated (California)
- Plaintiff's Counsel: Cherian Harkins Dunham LLP
- Case Identification: 7:26-cv-00275, W.D. Tex., 07/20/2026
- Venue Allegations: Plaintiff alleges venue is proper in the Western District of Texas because Defendant Trend Micro has committed alleged acts of infringement in the District and maintains a regular and established place of business at an office in Austin, Texas.
- Core Dispute: Plaintiff alleges that Defendant's email and cloud security products infringe two patents related to advanced methods for detecting Business Email Compromise (BEC) and other targeted email fraud.
- Technical Context: The technology addresses the detection of sophisticated, low-volume phishing attacks, such as BEC or "CEO fraud," which are designed to evade traditional, volume-based spam filters by appearing legitimate and targeting specific individuals within an organization.
- Key Procedural History: The complaint notes that U.S. Patent No. 11,595,336 is a continuation of the application that issued as U.S. Patent No. 10,721,195, and that the two patents share the same specification.
Case Timeline
| Date | Event |
|---|---|
| 2016-01-26 | Priority Date for '195 and '336 Patents |
| 2020-07-21 | U.S. Patent No. 10,721,195 Issued |
| 2023-02-28 | U.S. Patent No. 11,595,336 Issued |
| 2026-07-20 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 10,721,195 - "Detection of Business Email Compromise"
The Invention Explained
- Problem Addressed: The patent's background section states that traditional spam filters are ill-suited to detect targeted Business Email Compromise (BEC) scams Compl. ¶25 '195 Patent, col. 3:17-27 Unlike high-volume spam, BEC attacks are often highly customized, low-volume, and designed to appear realistic to both the recipient and the filter, evading detection methods that rely on email volume or simple keyword matching '195 Patent, col. 3:41-59
- The Patented Solution: The invention proposes a system that first establishes whether an email sender is "trusted" by a recipient, based on factors like belonging to the same organization or a history of communication '195 Patent, Claim 1 The system then applies a "non-monotonic" risk analysis logic; certain risk indicators are evaluated differently depending on this trust relationship '195 Patent, col. 5:21-41 '195 Patent, Fig. 5 For example, the system performs a risk determination by comparing the display or domain names of the purported sender with a trusted party and automatically performs a security action like quarantining or warning if a risk is found '195 Patent, abstract
- Technical Importance: This context-aware approach, which distinguishes between trusted and untrusted senders, allowed for more nuanced detection of sophisticated, low-volume attacks that mimic legitimate correspondence '195 Patent, col. 3:17-27
Key Claims at a Glance
- The complaint asserts infringement of at least independent Claim 1 Compl. ¶41
- Essential elements of Claim 1 include:
- A processor configured to automatically determine that a "first party is trusted by a second party" based on organizational affiliation and a threshold number of past messages.
- Receive a message for the second party from a distinct "third party."
- Perform a risk determination by assessing the similarity of the display or domain names between the first and third parties.
- Automatically perform a security action (e.g., warning, quarantine) and a report generation action if the first party is trusted and the message poses a risk, all without user input.
- The complaint reserves the right to assert other claims, which may include dependent claims Compl. ¶30
U.S. Patent No. 11,595,336 - "Detecting of Business Email Compromise"
The Invention Explained
- Problem Addressed: As the '336 Patent shares its specification with the '195 Patent, it addresses the same problem of BEC scams evading traditional spam filters Compl. ¶21 Compl. ¶25
- The Patented Solution: The '336 Patent also claims a system for detecting email risk that relies on establishing a "trusted" relationship. Claim 1 of the '336 Patent defines a trusted party based on presence on a whitelist or in an address book '336 Patent, Claim 1 A key element of its risk determination process is "determining whether the message comprises a hyperlink" in addition to display/domain name similarity '336 Patent, abstract If a risk is detected, the claimed security action includes "replacing the hyperlink in the message with a proxy hyperlink" '336 Patent, Claim 1
- Technical Importance: This invention adds hyperlink analysis and modification to the trust-based framework, providing a specific mechanism to neutralize potentially malicious links embedded in otherwise convincing scam emails '336 Patent, abstract
Key Claims at a Glance
- The complaint asserts infringement of at least independent Claim 1 Compl. ¶55
- Essential elements of Claim 1 include:
- A processor configured to automatically determine a "first party is considered by the system to be trusted by a second party" based on presence on a whitelist or in an address book.
- Receive a message for the second party from a distinct "third party."
- Perform a risk determination by checking if the message "comprises a hyperlink" and assessing display/domain name similarity.
- Automatically perform a security action that "comprises replacing the hyperlink in the message with a proxy hyperlink" if the first party is trusted and the message poses a risk.
- The complaint reserves the right to assert other claims Compl. ¶30
III. The Accused Instrumentality
Product Identification
- The complaint identifies a suite of Trend Micro products, including Trend Micro Email Security, Cloud App Security, Hosted Email Security, InterScan Messaging Security, and Deep Discovery Email Inspector, among others (collectively, the "Accused Products") Compl. ¶3
Functionality and Market Context
- The complaint alleges the Accused Products provide email security, threat detection, and specific BEC detection functionality Compl. ¶3 Compl. ¶27 A screenshot from Trend Micro's website is provided to show that its "InterScan Messaging Security" product is marketed as protecting against Business Email Compromise Compl. ¶31
- The core accused functionality involves automatically determining sender trust using "approved sender lists, approved domains, managed domains, organizational sender lists, allowlists/whitelists, [and] address-book-type information" Compl. ¶32 A screenshot from Trend Micro's documentation shows a feature for "Configuring Approved and Blocked Sender Lists" Compl. ¶32
- The complaint further alleges that the Accused Products perform risk determinations that include rewriting hyperlinks for "Time-of-Click Protection," where URLs in emails are rewritten for further analysis when clicked Compl. ¶33 When a risk is identified, the products allegedly perform security actions such as marking up messages with warnings, quarantining, and reporting Compl. ¶34
IV. Analysis of Infringement Allegations
The complaint references, but does not attach, claim chart exhibits mapping the Accused Products to the asserted claims Compl. ¶43 Compl. ¶58 The following analysis is based on the narrative allegations in the complaint.
'195 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| automatically determine that a first party is trusted by a second party, based on at least one of determining that the first party and second party belong to the same organization and that at least a threshold number of messages have been transmitted... | The Accused Products allegedly determine trust using "approved sender lists, approved domains, managed domains, organizational sender lists, allowlists/whitelists, address-book-type information, and/or historical or administrative trust relationships." | ¶32 | col. 47:39-48 |
| receive a message addressed to the second party from a third party... | The Accused Products are email security systems that necessarily receive and process email messages. | ¶3 | col. 47:49-51 |
| perform a risk determination... by determining that a display name... or that a domain name... are similar... | The Accused Products are alleged to perform BEC detection, which includes performing risk determinations on incoming messages. | ¶31; ¶35 | col. 47:52-59 |
| responsive to the first party being trusted... automatically perform a security action... comprising marking the message up with a warning or quarantining the message... [and] a report generation action... | The Accused Products allegedly perform security actions such as "marking up messages with warnings, ... quarantining messages, ... and/or including information about the message in administrator-accessible reports." | ¶34 | col. 47:60-48:5 |
'336 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| automatically determine that a first party is considered by the system to be trusted by a second party, based on at least one of determining that the first party is on a whitelist and that the first party is in an address book... | The Accused Products allegedly determine trust using "allowlists/whitelists" and "address-book-type information." | ¶32 | col. 47:6-12 |
| receive a message addressed to the second party from a third party... | The Accused Products are email security systems that necessarily receive and process email messages. | ¶3 | col. 47:13-15 |
| perform a risk determination... by determining whether the message comprises a hyperlink and by determining whether a display name... or that a domain name... are similar... | The Accused Products allegedly perform "Time-of-Click Protection," which involves determining that a message comprises a hyperlink (URL) for analysis, and perform BEC detection. | ¶33; ¶35 | col. 47:16-24 |
| responsive to the first party being trusted... automatically perform a security action... comprises replacing the hyperlink in the message with a proxy hyperlink... | The Accused Products allegedly include "Time-of-Click Protection," which "rewrites URLs in email messages for further analysis." | ¶33 | col. 47:25-33 |
Identified Points of Contention
- Scope Questions: A central question for both patents will be whether Trend Micro's use of "approved sender lists" or "whitelists" Compl. ¶32 meets the specific definitions of a "trusted" party as recited in the claims. For the '195 Patent, this includes determining if the functionality is based on organizational belonging and message thresholds. For the '336 Patent, this includes determining if it is based on whitelists and address book status as claimed.
- Technical Questions: The infringement analysis may turn on the specific technical implementation of Trend Micro's BEC detection and URL rewriting. For instance, do the Accused Products perform risk determination using the claimed "string distance" or "conceptually similar" analysis for display and domain names? Compl. ¶42 Compl. ¶56 Similarly, for the '336 Patent, does Trend Micro's "Time-of-Click Protection" function as the claimed "replacing the hyperlink... with a proxy hyperlink," or does it operate in a technically distinct manner? Compl. ¶33 Compl. ¶56
V. Key Claim Terms for Construction
The Term: "trusted"
Context and Importance: The concept of a "trusted" party is foundational to the logic of both asserted patents, as the risk analysis differs for trusted versus untrusted senders. The definition of this term will be critical to determining the scope of the claims and whether the "approved sender" functionality of the Accused Products Compl. ¶32 infringes.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification provides a broad, exemplary list of what can constitute a trusted party, including a "friend," an "internal" party, someone in an address book, or a connection on a social network, suggesting the term is not limited to the specific examples in the claims '195 Patent, col. 6:5-10
- Evidence for a Narrower Interpretation: The claims themselves provide specific bases for determining trust. Claim 1 of the '195 Patent recites trust based on "belong[ing] to the same organization" and a "threshold number of messages" transmitted. Claim 1 of the '336 Patent recites trust based on being on a "whitelist" or in an "address book." A party may argue that the scope of "trusted" in each claim is defined and limited by these explicit recitations.
The Term: "similarity" / "conceptually similar"
Context and Importance: Both asserted claims require a risk determination based on whether display or domain names are "similar," which is further defined as having a "string distance below a first threshold, or being conceptually similar." Practitioners may focus on this term because the infringement allegation depends on whether Trend Micro's BEC detection uses this specific type of comparison, as opposed to a different analytical method.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The term "string distance" is a well-known concept in computer science with many potential implementations, suggesting the claim is not tied to one specific algorithm. The alternative prong, "conceptually similar," is also open-ended.
- Evidence for a Narrower Interpretation: The specification provides a concrete example of "conceptually similar" by explaining that "Bill" and "William" are related even if not close in a traditional string-comparison sense '195 Patent, col. 6:59-65 It also discusses visual similarity, such as "m" and "rn" '195 Patent, col. 7:4-7 A party may argue that these examples define and limit the scope of what qualifies as a "conceptually similar" comparison.
VI. Other Allegations
- Indirect Infringement: The complaint alleges that Trend Micro induces infringement by encouraging and instructing customers and end-users on how to use the Accused Products in a manner that allegedly infringes the patents Compl. ¶44 Compl. ¶59 Contributory infringement is also alleged on the basis that the Accused Products are not staple articles of commerce suitable for substantial non-infringing use Compl. ¶45 Compl. ¶60
- Willful Infringement: Willfulness is alleged based on Trend Micro's continued infringement after having "knowledge of the Asserted Patents and ZapFraud's infringement allegations no later than service of this Complaint" Compl. ¶48 Compl. ¶63 This frames the allegation as post-suit willfulness.
VII. Analyst's Conclusion: Key Questions for the Case
- A central issue will be one of definitional scope: can the term "trusted" as defined in the patents-which recite specific criteria such as message thresholds ('195 Patent) or whitelist status ('336 Patent)-be construed to read on Trend Micro's "approved sender" functionality, and what evidence will be required to prove that equivalence?
- A key evidentiary question will be one of technical implementation: does the BEC detection in the Accused Products actually perform the specific "display name... similarity" analysis required by the claims, or does it rely on a different, non-infringing method to assess risk?
- A further technical question, specific to the '336 Patent, will be whether Trend Micro's "Time-of-Click Protection" feature, which allegedly "rewrites URLs," constitutes "replacing the hyperlink in the message with a proxy hyperlink" as claimed, raising a potential dispute over the precise operational meaning of "proxy hyperlink."