Method and device for determining the risk of harm to a consumer resulting from a breach of consumer information data

BR112020003492B1Active Publication Date: 2026-08-25BREACH CLARITY INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
BR112020003492
Authority / Receiving Office
BR · BR
Patent Type
Patents
Current Assignee / Owner
Publication Date
2026-08-25

Smart Images

  • Figure 00000062_0000
    Figure 00000062_0000
  • Figure 00000062_0001
    Figure 00000062_0001
  • Figure 00000063_0000
    Figure 00000063_0000
Patent Text Reader

Abstract

Assessing the risk of consumer harm related to a data breach includes determining, for the particular data breach, a data breach score, referred to as a breach clarity score (bc), indicative of the risk of harm related to the particular breach. A data structure pairs a breached information element with at least one potential harm. Algorithms assign a harm risk score to the harm, determine an element risk score for the information element-harm pair, and determine a bc score using the harm risk and element risk scores, and an exposure score. The bc score can be modified by a scaling algorithm to generate a relative bc score. The system identifies and ranks mitigation actions ordered for the breach and transmits these with the bc score to the consumer.One of the consumer's demographic and / or behavioral characteristics may be taken into account in the exposure score and in the ranking of mitigation actions.
Need to check novelty before this filing date? Find Prior Art

Description

54 METHOD AND DEVICE FOR DETERMINING THE RISK OF HARM TO A CONSUMER RESULTING FROM A BREACH OF CONSUMER INFORMATION DATA Cross-reference to related orders

[001] This application claims priority to and benefit of U.S. Provisional Patent Application 62 / 548,656, filed August 22, 2017, which is hereby incorporated by reference in its entirety. Technical Field

[002] The present description refers to a method and a system for determining a risk of consumer harm that includes identifying theft resulting from a data breach or data compromise. Fundamentals

[003] Data breaches and data compromises are very different from each other in terms of both the overall relative risk and the specific nature of that risk to a consumer victim of the breach, and as a result, require that prioritized and unique steps of action be taken by a consumer victim in response to notification of a breach or compromise of the consumer victim's data. Currently, data breach victims only have access to overly general fraud protection advice or solutions, which may include inappropriate advice or solutions. The advice available to a data breach victim can be distracting because it may not be possible even for the most qualified individual human advisor to compute recommendations that precisely exploit, for example, include and reflect, the expertise of a wide range of fraud prevention and identity protection specialists. Summary of the Invention

[004] A method and a system for evaluating a violation of Petition 870260063687, dated 06 / 29 / 2026, page 13 / 145 / 54 data and provision of recommendations for mitigation actions to reduce a consumer risk of identity theft or other harm, following notification that the consumer has been exposed to risk as a result of a particular data breach or compromise, are described herein. The term “data breach” as used herein shall not be limiting and shall be interpreted broadly to encompass any incident in which data has been exposed in a manner that creates a possibility or potential for harm, damage, loss and / or injury to the data subject, including, for example, identity theft, financial loss, loss of privacy, extortion, etc.A “data breach,” as this term is used here, may also refer to, and / or encompass, one or more of a data theft, data compromise, unauthorized access to data, unauthorized exposure of data, a data hack, a data intrusion, a data penetration, lost or stolen physical personally identifiable information, etc. A “data breach” may also be referred to here as a “data compromise” and / or as a “breach event.” The system described here, which may be described as a data breach scoring system or application, includes a plurality of data structures, tabulation formats, quantitative and qualitative research, and algorithms that are used in combination to compute risk-related outputs designed to minimize risk to consumers, all of which can be transmitted to a consumer via a user interface (UI).In an illustrative example, the system described here is referred to as the Breach Clarity™ (BC) system. An output of the BC system is an overall risk score generated for a specific breach victim, which is also referred to here as a Breach Clarity™ (BC) score. The BC score can be generated using one or more algorithms and transmitted as an absolute value and / or as a relative value, for example, relative to a pre-determined scale. In one example, the BC score is generated as a... Petition 870260063687, dated 29 / 06 / 2026, p. 14 / 145 / 54 relative numerical value between 0 and an upper limit (such as 10, 50 or 100), where the upper limit represents a maximum relative risk created by any particular breach of a victim's information elements. In an illustrative example, the information elements that may be breached and / or compromised may include one or more pieces of personally identifiable information (PII), protected health information (PHI), payment card industry data (PCI), and other such information that, if breached and / or compromised, may expose the breached victim to risk, injury and / or harm.

[005] Another computer-generated output of the BC system described herein is a prioritized list of particular damages (such as tax refund fraud or existing credit card fraud) that are generated by an algorithm as the most likely, i.e., most probable, damages that may occur as a result of a particular breach event or a combination of breach events, based on the unique characteristics of this particular breach or this particular combination of breach events. Another output of the BC system is an element risk score for damage associated with a breached information element, wherein the element risk score is generated using one or more algorithms applied to the associated data in a data structure and / or an industry survey including qualitative, quantitative and non-quantitative research, and stored in a BC system data structure.The element risk scores for the information elements breached in a data breach event can be combined using an algorithm to derive the overall BC score for a breach event. Yet another output generated by the BC system using the data structure is a prioritized list of specific consumer fraud mitigation action steps, which may include, for example, actions such as obtaining a credit freeze, setting a fraud alert, initiating credit monitoring, etc., which are ranked to generate a prioritized defined action for. Petition 870260063687, dated 06 / 29 / 2026, page 15 / 145 / 54, identifies the relatively strongest protective actions against the identified risks and damages. The outputs generated by the BC system are presented, for example, displayed and / or transmitted, to the consumer-victim through a user interface designed in one example, in such a way that the consumer can view a consolidated display showing a BC score, the identified risks, the mitigation actions and, in one example, can trigger the mitigation actions and / or additional information through the user interface. This consolidation of the outputs presented for the consumer's viewing and use offers an advantage to the consumer, in contrast to ad-hoc, unconsolidated, unprioritized and / or generalized consumer data breach information that may not clearly identify to the consumer the severity of a breach action and / or the appropriate mitigation actions that should be taken in response.

[006] The BC system described herein includes an apparatus, comprising a computing device having a processor and non-transient memory, the non-transient memory storing the instructions executable by the processor in such a way that the apparatus is configured and / or operable to execute a method described herein which may also be referred to as a Breach Clarity™ (BC) process, or BC method. In an illustrative example, the method may involve populating, via a server, a data structure with breach information, wherein the breach information may include a plurality of information elements and a plurality of damages. Each information element of the plurality of information elements is paired in the data structure with each damage of the plurality of damages to generate a plurality of information element-damage data pairs.The method involves generating, using an algorithm, an element risk score for each respective element-information damage pair from the plurality of element-information damage data pairs, and associating, in the data structure, the element risk score with the respective element-information damage data pair.

[007] The data breach information may include a descriptor Petition 870260063687, dated 06 / 29 / 2026, page 16 / 145 / 54 of the breach event that identifies a breach event, and at least one breached information element, where the at least one breached information element is a respective information element of the plurality of information elements that was compromised by the breach event. The method may include receiving, through the server, the descriptor of the breach event and the at least one breached information element, and associating, in the data structure, the descriptor of the breach event with the at least one breached information element. The method may include associating, using the data structure, each pair of information element-damage data from the plurality of information element-damage data pairs that includes the at least one breached information element with the descriptor of the breach event.

[008] In one example, the method includes generating, using the algorithm, a damage risk score for the respective damage of each element-damage data pair associated with the breach event descriptor, associating, using the data structure, the damage risk score for each damage with the breach event descriptor, and storing in the data structure the damage risk score associated with the breach event descriptor. The method may include generating, using the algorithm, a data breach score for the breach event, where the generation of the data breach score includes summing the damage risk scores of the respective damages of each element-damage data pair associated with the breach event descriptor to generate the data breach score. In one example, the data breach score is calculated by the algorithm with an absolute value.In another example, the data breach score is calculated by the algorithm with a relative value, where the relative value can be generated using the algorithm by applying at least one scaling factor and a modifier to the data breach score. The method may include generating, using the algorithm, an exposure score for the breach event, and associating, in the data structure, the exposure score with the descriptor of the breach event.

[009] The method may include transmitting, via the server, the Petition 870260063687, dated 06 / 29 / 2026, page 17 / 145 / 54 data breach score for a user interface, where the user interface may be in communication with the server. In one example, the method includes generating, using the algorithm, at least one mitigation action to mitigate at least one damage associated with the breach event descriptor, and transmitting at least one damage and at least one mitigation action to the user interface. The method may include associating, in the data structure, at least one mitigation action with at least one damage to form a damage mitigation action data pair, and determining, using the algorithm, a prioritization factor for the damage mitigation action data pair.At least one mitigation action may include a plurality of mitigation actions, such that the method may include determining, using the algorithm, a respective prioritization factor for each respective mitigation action of the plurality of mitigation actions, and associating, in the data structure, the respective prioritization factor with each respective mitigation action. In one example, the method includes compiling, using the algorithm, a listing of the plurality of mitigation actions, where each respective mitigation action is ordered in the listing according to the respective prioritization factor associated with the respective mitigation action. The method may include associating, in the data structure, a user interface with at least one mitigation action, where the user interface is actionable to initiate at least one mitigation action.The user interface can be provided, via the server, to a user device, in such a way that a user can access the BC system through the user device.

[0010] The features and advantages noted above, and others in this description, become readily apparent from the following detailed description when taken in connection with the accompanying drawings. Brief Description of the Drawings

[0011] Figure 1 is a schematic illustration of an exemplary Breach Clarity™ (BC) system for generating risk-related outputs related to a breach event; Petition 870260063687, dated 06 / 29 / 2026, page 18 / 145 / 54, Figure 2 is a schematic illustration of a flowchart of an exemplary process for generating the outputs related to the risk associated with a breach event; Figure 3 is a schematic illustration of an exemplary data table that relates a list of violated entities and a list of violable information elements; Figure 4 is a schematic illustration of an exemplary data table showing a list of damages, a list of violable information elements, and a risk score for the exemplary element generated by an algorithm of the system in Figure 1 for each damage-information element combination; Figure 5 is a schematic illustration of a flowchart of an exemplary method for generating risk scores for a particular breach event; Figure 6 is a schematic illustration of an exemplary data table showing the risk outputs generated by the method in Figure 5; Figure 7 is a schematic illustration of a flowchart of an exemplary method for computing a Breach Clarity™ (BC) score for a particular breach event; Figure 8 is a schematic illustration of an exemplary user interface for displaying the outputs of the method in Figure 7; Figure 9 is a schematic illustration of an exemplary user interface for accessing risk outputs for a particular breach event using the BC system; Figure 10 is a schematic illustration of another exemplary user interface for accessing risk outputs for one or more violated information elements, using the BC system; Figure 11 is a schematic illustration of an exemplary data table showing a list of damages, a list of mitigation actions, and an exemplary action priority factor generated by a Petition 870260063687, dated 06 / 29 / 2026, page 19 / 145 / 54 algorithm of the system in figure 1 for each damage-mitigation action combination; Figure 12 is a schematic illustration of an exemplary user interface for accessing the BC system of Figure 1; Figure 13 is a schematic illustration of another exemplary user interface for accessing the BC system in Figure 1; Figure 14 is a schematic illustration of another exemplary user interface for accessing the BC system in Figure 1; Figure 15 is a schematic illustration of an exemplary user interface that displays the risk outputs for a first example breach event accessed through the user interface in Figure 12; Figure 16 is a schematic illustration of an exemplary user interface that displays the risk outputs for a second example breach event accessed through the user interface in Figure 12; Figure 17 is a schematic illustration of an exemplary user interface that displays the risk outputs for the first example violation event accessed through the user interface in Figure 13; Figure 18 is a schematic illustration of an exemplary user interface that displays the risk outputs for the second example breach event accessed through the user interface in Figure 13; Figure 19 is a schematic illustration of an exemplary user interface that displays the risk outputs for the first example violation event accessed through the user interface in Figure 14; Figure 20 is a schematic illustration of an exemplary user interface that displays the risk outputs for the second example breach event accessed through the user interface in Figure 14; Figure 21 is a schematic illustration of an exemplary user interface that displays the risk outputs for a third example breach event accessed through the user interface in Figure 14; Figure 22 is a schematic illustration of an exemplary user interface displaying the risk outputs for a fourth event of Petition 870260063687, dated 06 / 29 / 2026, page 20 / 145 / 54 example violation accessed through the user interface in Figure 14; and Figure 23 is a schematic illustration of an exemplary user interface that displays the consolidated risk outputs of the plurality of violation events shown in Figures 19 through 22. Detailed Description

[0012] A method and system for assessing a data breach and providing recommendations for mitigation actions to reduce a consumer risk of identity theft or other harm, following awareness and / or notification that a consumer has been exposed to risk as a result of a data breach or compromise, in particular of one or more of the consumer's information elements, are described herein. By way of illustrative, non-limiting example, the information elements that may be breached and / or compromised may include one or more of the Personally Identifiable Information (PII), Protected Health Information (PHI), Payment Card Industry Data (PCI), and other such information that, if breached and / or compromised, may expose the breached victim to risk, injury and / or harm. A consumer who has been the victim of a data breach may be referred to herein as a consumer, as a consumer-victim and / or as a victim.The term “data breach,” as used herein, should not be limiting and should be interpreted broadly to encompass any incident in which data has been exposed in a way that creates a possibility or potential for harm, damage, loss, and / or injury to the data subject, including, for example, identity theft, financial loss, loss of privacy, etc. A “data breach,” as the term is used herein, may also refer to and / or encompass one or more data thefts, data compromises, unauthorized access to data, unauthorized exposure of data, data hacks, data intrusions, data penetrations, etc. A “data breach” may also be referred to herein as a “data compromise,” a “data compromise event,” and / or as a “breach event.” Petition 870260063687, dated 06 / 29 / 2026, page 21 / 145 / 54

[0013] In relation to drawings in which equal reference numbers represent equal components across all the different figures, the elements shown in Figures 1-23 are not necessarily to scale or proportion. Therefore, the dimensions and particular applications provided in the drawings presented here should not be considered limiting. As used herein, the terms “a”, “an”, “the”, “at least one”, and “one or more” are interchangeable and indicate that at least one of an item is present. A plurality of such items may be present unless the context clearly indicates otherwise. All numerical values ​​of parameters, quantities, or conditions in this description, including the appended claims, should be understood as being modified in all instances by the term “about” or “approximately” whether or not “about” or “approximately” actually appears before the numerical value.“About” and “approximately” indicate that the stated numerical value allows for some slight imprecision (e.g., with some approach to accuracy in the value; reasonably close to the value; almost; essentially). If the imprecision provided by “about” or “approximately” is not otherwise understood with this meaning, then “about” and “approximately,” as used here, indicate at least the variations that may arise from the methods of measurement and use of such parameters. Additionally, the terminology “substantially” also refers to a slight imprecision of a condition (e.g., with some approach to accuracy in the condition; approximately or reasonably close to the condition; almost; essentially). Furthermore, the numerical ranges described include the description of all values ​​and additionally subdivided ranges within the entire described range. Each value in a range and the endpoints of a range are all described as separate modalities.The terms “comprising,” “includes,” “including,” “has,” and “having” are inclusive and therefore specify the presence of declared items, but do not preclude the presence of other items. As used in this description, the term “or” includes any and all combinations of one or more of these items. Petition 870260063687, dated 06 / 29 / 2026, page 22 / 145 / 54 listed.

[0014] In relation to Figure 1, a system, which can be described here as a data breach scoring system, is generally indicated as 100. In an illustrative example, the 100 system is also referred to here as a Breach Clarity™ (BC) system and / or as a BC 100 system. The BC 100 system includes a BC server 12, which includes one or more data structures, generally indicated as 22 (see also Figures 3, 4, 6, 11), and one or more algorithms 10 configured to compute risk-related outputs designed to minimize the risk to consumers who are the victim of a breach event 70 (see Figure 3).The risk to a consumer resulting from a data breach may also be referred to here as damage or injury, such that the terms risk, damage, and injury should be broadly interpreted to include all types of damage to the consumer that may result from a data breach, including, but not limited to, the damages described herein and shown in the figures. Each of the risk-related outputs may be generated by the BC 100 system for each breach event and / or as a summary output for a plurality of breach events experienced by a consumer-victim, the latter being shown in a non-limiting example illustrated by Figure 23. A breach event may also be identified herein by a breach descriptor, for example, by a name or description by which the breach event is identified.The risk-related outputs may include, in an illustrative example and described here in further detail, one or more breach descriptors 70 (see Figures 3, 9, 13-23), a set of breachable information elements 68 (see Figures 3 and 4), one or more sets of damage descriptors 72 (see Figures 4, 5 and 11), an exemplary element risk score 74 (see Figure 4) generated for each pairwise combination of a breachable information element 68 and a damage descriptor 72, an exemplary damage risk score 76 (see Figure 6) generated for each damage descriptor 72 that considers all information elements 68 breached in a breach event. Petition 870260063687, dated 06 / 29 / 2026, page 23 / 145 / 54 particular 70, an exposure score of 132, an overall data breach score of 80 also referred to here as a Breach Clarity™ (BC) score of 80 (see figures 6 and 8) generated for the particular breach event 70.

[0015] As shown in Figure 1, the BC 12 server includes a memory 16 and a central processing unit (CPU) 14. The memory 16 of the BC 12 server may include, for example, Read-Only Memory (ROM), Random Access Memory (RAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), etc., that is, non-transient / tangible machine memory of a size and speed sufficient to store the data structure 22, the algorithms 10, the tabulation formats included in the data structure 22, such as the data tables 22A, 22B, 22C, 22D shown respectively in Figures 3, 4, 6 and 11, quantitative, qualitative and other industry and / or breach-related research, breach event data, mitigation action information, one or more BC 20 applications, etc.Memory 16 is of sufficient size and speed to handle data structure 22, to execute algorithms 10 and / or BC applications 20 to generate risk-related outputs, and to generate one or more user interfaces (UI) 90, including, for example, user interfaces 90A-90E shown in the figures. The BC server includes a BC interface 18, which, in an illustrative example, can be configured as a modem, browser, or similar device suitable for accessing a network 130. In one example, the network 130 is the Internet. The BC server 12, in a non-limiting example, is administered and / or operated by a BC service provider. In one example, a victim-consumer can access the risk outputs and other services of the BC system 100 through a user device 30 and / or by personal contact with the BC service provider.

[0016] A consumer, also referred to herein as a consumer, may access the BC 100 system, for example, by means of a user device 30, to view the breach information which includes the risk outputs generated by the BC 100 system for one or more breach events 70. Petition 870260063687, dated 06 / 29 / 2026, page 24 / 145 / 54 In one example, a consumer accessing the BC 100 system might be a victim of a breach event 70 who accesses the BC 100 system to view information transmitted by the BC 100 system related to this breach event 70. In another example, it is not required that the consumer be a victim of a breach 70; for example, any consumer can access the BC 100 system to view breach information, including risk outputs generated by the BC 100 system for one or more breach events 70. In another example, the BC 100 system can be configured in such a way that a consumer is not required to enter identifying information and / or identify themselves as a victim of a breach event 70 as a prerequisite for accessing the BC 100 system.In another example, the BC 100 system is configured to provide an option for a consumer to subscribe to the BC 100 system, such that the subscription information for the subscriber-consumer can be stored in memory 16 of the BC 12 server in data structure 22, for example, in a consumer profile created in data structure 22 for the subscriber-consumer. The term "subscription" is intended to have a broad meaning, including, for example, one or more actions such as creating an account, creating a login name and password, registering and / or signing up as a user of the BC 100 system and / or to receive notifications from the BC 100 system, creating a consumer profile, etc. The term "subscription" may include, but is not limited to, a subscription under which the subscriber is assessed with a fee to access the BC 100 system. In one example, a consumer may subscribe without paying a subscription fee.In another example, the BC 100 system and / or a subscription to the BC 100 system may be offered to the consumer by a sponsor or other entity, such as a resource provider, which may be a financial organization, commercial entity, or healthcare service organization. In one example, the sponsoring entity and / or other entity may host a portal to the BC 100 system on the sponsor's / other entity's website, through which a consumer can access the BC 100 system. Petition 870260063687, dated 06 / 29 / 2026, page 25 / 145 / 54

[0017] In a non-limiting example, subscriber-consumer subscription information and / or subscriber-consumer consumer profile are associated in data structure 22 with at least one breach event 70 in which the subscriber-consumer was a known victim, and with each of the subscriber-consumer information elements 68 that were breached or compromised. The consumer profile may also be referred to here as a consumer risk profile and / or a subscriber risk profile. During the subscription process, the subscriber-consumer may enter into the BC system 100 the subscriber-consumer information elements 68 that were compromised and / or breached that are not associated with a publicly reported breach, for example, credit card theft information from a stolen purse or wallet, loss of payment information due to skimming fraud, inappropriate disposal of personal information records, etc.In one non-limiting example, subscription information for a subscriber-consumer may include identifying information to identify the subscriber-consumer, which includes, for example, name, address, email address, telephone number, other social media contact information (Twitter®, Instagram®, etc.).) of the subscriber-consumer, a listing of the breach events 70 in which the subscriber-consumer was victimized, including the number, type, frequency, and timing of each of these breach events 70, a listing of the subscriber-consumer information elements 68 that were breached or compromised by the breach events 70 in which the subscriber-consumer was victimized, actual damage or injury incurred by the subscriber-consumer due to a data breach or compromise, behavioral and / or demographic-based information for the subscriber-consumer that, in one example, may be used by the BC system 100 and / or algorithms 10 to generate, rank, weight, and / or otherwise prioritize mitigation actions 116 that may be delivered to the subscriber-consumer. In this last example, behavioral information may include, by way of non-limiting example, the behaviors of. Petition 870260063687, dated 06 / 29 / 2026, page 26 / 145 / 54 subscriber-consumer information security, including, for example, password behaviors, including password reuse, frequency of password changes, password security messages used by the subscriber-consumer, the subscriber-consumer's use of antivirus, security, and anti-malware products, the subscriber-consumer's use of identity theft tools, such as credit score monitoring, frequency and scope of online communication methods used by the subscriber-consumer (private and public networks, including Wi-Fi, email, chat rooms, blogs, social media, instant messaging systems, etc.).Frequency and scope of subscriber-consumer online use and / or communication of personally identifiable information (PII), protected health information (PHI), payment card industry data (PCI), including online access to and manipulation of this information, mechanisms for accessing subscriber-consumer data, including the type, model, etc. of devices (cell phones, personal computers, personal digital assistants, tablets, laptops, modems, routers, smart appliances, smart home devices and systems, smart vehicles, etc.) used by the subscriber-consumer, etc. In this last example, demographic information may include, by way of non-limiting example, the subscriber-consumer's geographic location, demographic data on income, age, gender, marital status, occupation, etc.One or more algorithms of the BC 100 system can be configured to incorporate subscriber-consumer signature information in the generation of one or more risk outputs, for example, in the generation of an exposure score 132, a list of recommended mitigation actions 116, a ranking of damages 72, etc., where the signature information can be used by the algorithm as a modifier and / or additional factor in the calculation and / or generation of risk outputs by the BC 12 server. The example of using subscriber information in the calculation and / or generation of risk outputs is illustrative and not limiting. For example, one or more algorithms of the BC 100 system can be configured to associate, in the data structure 22, a... Petition 870260063687, dated 06 / 29 / 2026, page 27 / 145 / 54 non-subscribing consumer identification information, with one or more of the violation events 70, of the violated information elements 68, etc., in the generation of one or more of the risk outputs, for example, in the generation of an exposure score 132, a list of recommended mitigation actions 116, a ranking of damages 72, etc., in which the consumer information can be used by the algorithm as a modifier and / or an additional factor in the calculation and / or generation of risk outputs by the BC server 12.

[0018] User device 30 includes a memory 26, a central processing unit (CPU) 28, one or more user applications 24, a communications interface 126, and an input / output interface 128. User device 30 may be a user device such as a mobile phone, a personal digital assistant (PDAs), a handheld or portable device (iPhone, Blackberry, etc.), a notebook, a personal computer, a notepad, or other user device configured for mobile communications, including communication with the network 130. User device 30 is configured to communicate with the network 130 through the communications interface 126, which may be a modem, a mobile browser, a wireless internet browser, or a similar device suitable for accessing the network 130.The user device memory 26 may include, for example, Read-Only Memory (ROM), Random Access Memory (RAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), etc., that is, a non-transient / tangible machine memory of sufficient size and speed to run a BC application 20 that can be activated on the user device 30, including, for example, one or more user interfaces 90 and / or to perform the mitigation actions 116, as described herein in further detail. The user device input / output interface 128 may include, for example, one or more numeric keypads and displays, a touch screen, or a combination thereof configurable to transmit and / or display, for example, one or more. Petition 870260063687, dated 06 / 29 / 2026, page. 28 / 145 / 54 user interfaces 90 associated with one or more BC 20 applications and / or to display content received by the user device 30 from the BC 12 server, a report server 40 and / or a resource server 50, including, for example, web pages, images, information selected for transmission via the input / output interface 128 and / or a user interface 90 of the user device 30. Illustrative examples of the user interfaces 90 that can be generated by and transmitted from the BC 100 system are included in the figures, and shown as user interfaces 90A, 90B, 90C, 90D, 90E, 90F, 90G, 90H, 90J, 90K, 90L, 90M, 90N, 90P, 90Q, 90R, and 90S.These examples are not exhaustive, and it will be understood that other configurations and / or arrangements of the risk outputs generated by the BC 100 system may be displayed through one or more user interfaces 90 different from those shown in the figures for illustration.

[0019] System 100 may include one or more reporting servers 40 configured and / or operable to report information relating to a data breach, which may include, for example, a breach descriptor 70 of the breached entity, such as a company name (e.g., “Azure Jewelers” or “XYZ Bank”), breach event information including breached date(s), information elements 68 breached and / or compromised by the breach (personally identifiable information (PII), protected health information (PHI), payment card industry data (PCI), etc.), information relating to the breaching entity (hacker, criminal, etc.), post-breach exposure and / or use of the breached data (availability for sale on criminal online marketplaces), etc. Each of the reporting servers 40 is administered and / or operated by a reporting entity that is reporting a breach event.The reporting entity that administers a 40 reporting server could be, for example, a breached entity reporting information related to a breach of its own data, or a regulatory or governmental organization configured to receive information from breached entities and / or to report on them. Petition 870260063687, dated 06 / 29 / 2026, page 29 / 145 / 54 information for consumer-victims, a financial institution, a government organization, a health organization, a retail entity, etc., that reports violations of their respective data, etc. The BC 100 system collects the information from the violation event, for example, through communication between the BC 12 server and one or more of the 40 reporting servers, for use in generating the risk-related BC outputs described herein. In an illustrative example, the 40 reporting server includes a 32 memory and a 34 central processing unit (CPU). The 32 memory of the 40 reporting server may include, for example, Read-Only Memory (ROM), Random Access Memory (RAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), etc.That is, non-transient / tangible machine memory of sufficient size and speed to store violation event information collected by the reporting entity related to a violation event 70 in a reporting database 36. Memory 32 is of sufficient size and speed for the handling and reporting of violation event information by the reporting entity that administers the reporting server 40. In an illustrative example, the reporting server 12 receives the violation information related to a violation event 70 at the time the violation is initially reported, and may continue to receive the information periodically thereafter related to the violation event 70, such that the violation information related to the violation event 70 can be periodically updated in the data structure 22 as additional violation information is learned and / or becomes available.In one example, server BC 12 receives exposure information and / or accesses exposure information stored in data structure 22, and uses an algorithm 10 to assign an initial exposure score 132 (see Figures 19-23) to each breach event 70, where the exposure score 132 indicates to the consumer the probability of exposure of their data from this breach event 70. Exposure information may include, for example, information received from the breached entity regarding the extent to which the elements of... Petition 870260063687, dated 06 / 29 / 2026, page 30 / 145 / 54 information violated 68 were exposed, for example, distributed in an unauthorized manner, the types of exposures that occurred and / or are expected to occur, for example, the exposure of the violated information elements 68 through a network, Internet page, by unauthorized publication, etc., qualitative and / or quantitative research related to exposure patterns for violations and / or violated data similar to the violation event 70, etc. The exposure score 132 may be a relative number, for example, on a scale that has an upper limit.In the example shown in Figures 19-23, the exposure score 132 is expressed as a relative number on a scale of 1 to 10, with an exposure score 132 of “10” corresponding to the most severe score, for example, the relatively highest probability of data exposure from this breach event 10, and an exposure score 132 of “1” corresponding to the least severe score, for example, the relatively lowest probability of data exposure from this breach event 10. Server BC 12 may continue to monitor and / or receive breach information periodically after the occurrence of each particular breach event 70, relating to the observed availability of the breached data (for this particular breach event 70) on unauthorized Internet pages, for example, in unauthorized circulation.In one example, server BC 12 receives breach information regarding the observed availability of the breached data on “dark” web pages, on the darknet, or through other sources that include locations outside the network, including, for example, the availability of the breached data for sale or other distribution for unauthorized use. Server BC 12 and / or algorithms 10, in response to the breach information regarding the observed availability of the breached data, may, for example, modify the exposure score 132, restart the mitigation actions 116, and / or modify the probability of harm, for example, the risk distribution 134 (see figures 15-23) of the risks associated with this particular breach event 70. Petition 870260063687, dated 06 / 29 / 2026, page 31 / 145 / 54

[0020] Report server 40 includes a reporting interface 38, which, in an illustrative example, can be configured as a modem, a browser, or a similar device suitable for accessing a network 130. In an example, the BC server 12 collects the violation event information from one or more reporting servers 40 via the network 130 and stores the collected violation event information in BC memory 16 and / or data structure 22 for use in generating BC risk-related outputs using BC algorithms 10 and / or applications 20. The BC data structure 22 may include one or more data mapping tables, functions, and / or BC applications 20 to mediate the import of data from a reporting server 40 and / or a reporting database 36, and may include BC applications 20 for mapping the data fields of a particular reporting database 40 to the corresponding fields in the BC data structure 22.The BC 22 data structure can include a plurality of data mapping applications, where each application can be configured for a specific reporting database 36, to improve the efficiency and effectiveness of importing and consolidating data into the BC 22 data structure from multiple reporting databases 36 managed by multiple reporting entities. For example, the BC 22 data structure can include a first data mapping application to mediate the import of data from a first reporting database 36 managed by a government regulatory agency that receives reports of data breach events 70 from various types of organizations (banks, brokerages, etc.).In the financial industry, a second data mapping application was used to mediate the import of data from a retail entity that experienced a data breach event 70, a third data mapping application was used to mediate the import of breached data reported by an individual consumer (see Figure 10), and a fourth data mapping application was used to mediate the import of breached data reported by a medical institution and similar entities. As such, the BC 22 data structure and the BC method for generating the... Petition 870260063687, dated 06 / 29 / 2026, page 32 / 145 / 54 risk outputs provide a standardized database of breach information and an efficient and standardized approach to quantifying the risks and damages 72 to a consumer-victim associated with a data breach event 70, for this breach event 70 and in relation to other breach events 70.

[0021] System 100 may include one or more resource servers 50 configured to provide resources, including mitigation actions 116 (see Figure 8), to consumer-victims of a data breach. Each of the resource servers 50 is administered and / or operated by a resource provider. A resource provider may be, by way of non-limiting example, a financial institution, such as a bank or brokerage firm, that provides a notification service to a consumer-victim subject to a breach of the financial institution's customer information, a credit bureau or similar organization that monitors the consumer-victim's account for fraud and / or identity theft detection, an identity protection software provider, and / or the breached entity, for example, to change a password or other breached information, such as a payment card account number, etc.In an illustrative example, resource server 50 includes a memory 42 and a central processing unit (CPU) 44. The memory 42 of resource server 50 may include, for example, Read-Only Memory (ROM), Random Access Memory (RAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), etc., that is, non-transient / tangible machine memory of sufficient size and speed for the provision of resource services, which may include mitigation actions 16, related to the breach event and / or the breached information, which may be stored and / or accessed through a resource database 46. Resource server 50 includes a resource interface 48 which, in an illustrative example, may be configured as a modem, a browser, an internet page or a similar device suitable for accessing a network 130. In an illustrative example, resource server 50 may be accessed. Petition 870260063687, dated 06 / 29 / 2026, page 33 / 145 / 54 through a user interface 90 provided by the BC system to a consumer-victim user device 30, to activate a mitigation action 116. In one example, the resource server 50 and the BC server 12 are integrated through one or more application programming interfaces (APIs) in such a way that one or more mitigation actions 116 can be automatically activated in one of the consumer's accounts based on the violation status information and the preferences of the consumer and / or the resource provider.By way of illustration, resource server 50 could be an administrator of a specific consumer account, such as a financial, healthcare, or other type of account that includes sensitive and / or private information (PII), where the administrative functions of resource server 60 include customizing alerts for the specific consumer account, threshold limits for transfers and other activities, etc., based on input and / or preferences of the consumer and / or resource provider. Server BC 12, in this example, could be integrated with resource server 50, for example, a banking institution or healthcare provider, in such a way that the settings for the specific consumer account could be made automatically based on the consumer risk profile determined by server BC 12.In one example, the integration of BC server 12 with resource server 50 for consumer-specific account customization can occur during a subscription process, during which the consumer subscribes to the BC system 100 and authorizes the automatic integration and updating of the resource provider's consumer-specific account settings by BC server 12 based on the subscriber-consumer's BC risk profile. As changes occur in the consumer's risk profile on BC server 12 over time, for example, as a consumer becomes a victim of a breach event 70 for which a damage 72 and / or a mitigation action 116 are identified by BC system 100 related to the consumer-specific account managed by resource server 50 and integrated with BC server 12, BC server 12, through the integration API, automatically changes the settings in the account. Petition 870260063687, dated 06 / 29 / 2026, page 34 / 145 / 54 specific to the consumer, for example, to review alert definitions, change authorization limits, notify the integrated resource provider of violation information that potentially affects the specific consumer account administered by resource server 50, etc.

[0022] In another illustrative example, resource server 50 may incorporate a third-party source of breach status information or other details, such as IDtheftcenter.org, a credit reporting agency, an activity monitoring system for online monitoring of activity related to one of the consumer's online accounts, email addresses, etc., such as www.haveIbeenpwnd.com, an internet page of the breached entity itself established for a consumer to obtain breach information from this breached entity, such as the internet page https: / / trustedidpremier.com / eligibility / eiligibility.html established for victims of the Equifax breach event. In this example, resource server 50 may be integrated with BC server 12, via an API or similar system, in such a way that resource server 50 can automatically provide breach information to BC server 12.In one example, the BC 100 system is operable and / or configured in such a way that, when breach information related to a specific consumer account is received by the BC 12 server from an integrated resource server 50, the BC 12 server updates the consumer's BC risk profile, including recommended mitigation actions 116, exposure scores 132 and the like, and automatically provides notifications to the affected consumer.

[0023] In the example shown in Figure 1, server BC 12, user device 30, report server 40, and resource server 50 can selectively communicate with each other via network 130. The example shown in Figure 1 is non-limiting, such that one or more of server BC 12, user device 30, report server 40, and resource server 50 can be selectively connected directly, for example, to directly access each other and / or for communication.Petition 870260063687, dated 06 / 29 / 2026, page 35 / 145 / 54 data outside the network between one or more of the BC 12 server, the user device 30, the reporting server 40, the resource server 50. The example shown in Figure 1 is not limiting, such that a consumer victim may contact a BC provider that has access to the BC 12 server using a means other than a user device 30, for example, using one or more personal contact methods, telephone, fax, short message service (SMS), multimedia messaging service (MMS), recorded (forwarded) mail, etc., to obtain the services and risk outputs provided by the BC 100 system and / or the BC 12 server.Similarly, a consumer-victim may contact a resource provider that has access to resource server 50 to obtain resource services that may include triggering one or more mitigation actions 116 (see Figure 8) and / or may contact a reporting provider that has access to reporting server 40 to obtain reporting services that may include determining whether the consumer was a victim of a data breach event and / or reporting a data breach event, using a user device and / or means 30, such as one or more personal contact devices, telephone, fax, short message service (SMS), multimedia messaging service (MMS), recorded (forwarded) mail, etc. In one example, one or more of the services provided by reporting server 40 and / or resource server 50 may be integrated with the consumer's BC risk profiles and / or BC server 12, via an API, etc....in such a way that the consumer can receive notifications through the BC 12 server and / or the BC 100 system and / or access information from the reporting server 40 and / or the resource server 50 through the BC 12 server and / or the BC 100 system, including notifications of breach activity which include breach events 70, advice to activate mitigation actions 116, changes to exposure scores 132 due to observed activities, including, for example, fraudulent transactions, unauthorized distribution of the consumer's breached information, etc. For example, the reporting of an occurrence of a particular type of damage in a specific consumer account by a... Petition 870260063687, dated 06 / 29 / 2026, page 36 / 145 / 54 reporting provider for the BC 100 system, such as a fraudulent transaction in the consumer's account, for example, through the integration of reporting server 40 with BC server 12, can trigger a review by BC server 12 of the exposure score 132 for this consumer's BC risk profile. BC server 12, using the revised exposure score 132, can apply algorithms 10 to update the consumer's mitigation actions 116 and / or rankings of these mitigation actions 116, and can transmit notifications to the consumer and / or to a resource server 50 or resource provider associated with and / or potentially affected by the reported occurrence.For example, the occurrence of a fraudulent in-store payment card transaction, using tampered codes stored on the magnetic stripe of a consumer payment card and reported via a reporting server 40 to the BC server 12, may initiate a review by the BC server 12 of the consumer exposure score 132 and / or mitigation actions 116, including transmitting a notification to a resource server 50 of a resource provider, such as the payment card issuer, to modify fraud alerts and / or authorization requirements for in-store transactions where the consumer payment card is presented for use.In another example, the BC 100 system can transmit a mitigation action 116 and / or provide a notification or alert to a consumer-victim of a breach event 70 that includes their phone number and / or email address as the breached information elements 68, to advise the consumer-victim that they are at increased risk of receiving phone calls or emails from identity criminals.

[0024] With regard to figures 1 and 2, figure 2 is a flowchart 200A illustrating a high-level overview of the Breach Clarity™ process, including both consumer input and output as supports, with an abbreviated overview of the BC 10 algorithm in the middle. The Breach Clarity™ process includes a method 200 described herein, which, by way of non-limiting example, comprises flowcharts 200A, 200B, and 200C. Petition 870260063687, dated 06 / 29 / 2026, page 37 / 145 / 54. As shown in Figure 2, in step 52, a consumer-victim, also referred to here as a consumer, enters the name of the violation event 70 into a user interface, for example, into one of the user interfaces 90C, 90D in communication with the BC server 54. In step 54, the BC server 12 retrieves the violation event information about the particular violation event 70 from the BC data structure 22, in machine-readable format. In one example, the violation event information can be organized and stored in the BC server's data structure 22 using a data table, such as the data table 22A shown in Figure 3, which, in one example, can be transmitted for viewing on the user device 30 as a user interface 90A. Data table 22A shows a set of information elements 68 that may be subject to violation, and a listing of violation events 70.In an illustrative example, the information elements 68 may include one or more of the personally identifiable information (PII), protected health information (PHI), payment card industry data (PCI), and other such information that, if breached, could expose the breached victim to risk and / or harm. In step 56, for the particular breach 70 selected by the consumer, the BC server 12 executes one or more algorithms 10 to compute the probability of the consumer encountering harm related to the particular identity, and prioritizes risks and recommendations. Algorithm 10, in one example, uses the data table 22B shown in Figure 4 and described here in more detail, to determine an element risk score 74 assigned to each data pair in the table, where a data pair consists of an information element 68 and a potential harm 72.For example, with respect to Figure 4, algorithm 10 assigned a risk score of “10” to the data pair consisting of damage 72B “New Account Creation” and information element 68A “Social Security Number”. The risk score for each data pair consisting of a damage 72 associated with a violated information element 62 can be derived based on one or more industry-reported and / or qualitative research information. Petition 870260063687, dated 06 / 29 / 2026, page 38 / 145 / 54 quantitative, and stored in the BC 22 data structure, for example, in data table 22B.

[0025] In step 58, an algorithm 10 is applied to rank the order and / or identify the main predicted damages 72. The BC server 12 can transmit the same for visual presentation, and display for viewing by the consumer as a user interface 90. The main predicted damages 72, including treatments such as the element risk score 74, the rank order, the size and color that indicate the damages 72 that require primary surveillance, can be displayed as shown in a first non-limiting example in data table 22C and / or in other non-limiting examples, as shown in user interface 90C illustrated in figure 8 and in user interfaces 90J, 90K, 90L, 90M, 90N, 90P, 90Q, 90R, 90S illustrated in figures 15-23.The displayed list of particular damages 72 (such as tax refund fraud or existing credit card fraud) is prioritized and / or ranked based on these damages 72 that are predicted by algorithm 10 as most likely based on the unique characteristics of any particular breach event 70. In step 60, and as shown in Figure 6, method 200 sums, for each damage 72, the element risk score 74 for all information elements 68 determined by algorithm 10 as susceptible to this damage 72, to generate a damage risk score 76. In the example shown, algorithm 10 totals the damage risk scores 76 to generate a data breach score 80, which, in the example shown in Figure 6, is an absolute data breach score 80A that has a value, in the example, of 83.In one example, algorithm 10 might include applying a modifier to the total sum of the damage risk scores 76 to generate the data breach score 80, where the modifier might, for example, be based on the number and / or types of information elements 68 exposed by the breach event 70, the number and / or types of damage 72 associated by algorithm 10 with the breached information elements 68, an exposure score 132 applied to the breach event 70, etc., such that example one. Petition 870260063687, dated 06 / 29 / 2026, page 39 / 145 / 54 totalization or sum algorithm 10 is illustrative and not limiting. The data breach score 80, which, in the illustrative example, is referred to as a Breach Clarity™ score or a BC 80 score, is the overall risk score of the breach victim for the particular breach event 70. In step 60, algorithm 10 can generate a relative BC score 80B, as shown in figure 8, where the relative BC score 80B is expressed as a numerical value relative to a fixed scale between 0 and an upper limit (such as 10, 50, 100 or other scale limit). Algorithm 10 can apply a modifier and / or scaling factor to the absolute value of the BC score 80 to derive a scaled BC score for the violation event 70.In one example, the modifier is a division factor that can be applied to convert the absolute value into a scaled BC score 80, where the division factor is derived, for example, from breach industry data, qualitative research and / or quantitative research and / or derived from one or more of all, a part of, or a sample of the breach data stored in data structure 22. In one example, the modifier might include based on an exposure score 132 identified for this breach event 70 and / or the number and / or severity of the damages 72 and / or the breached information elements 68 associated in data structure 22 with this breach event 70.In an illustrative example shown in Figure 8, the relative BC score value 80B is 72 / 100, where 100 is the upper limit of the BC scale, and is displayed in the user interface 90C both as a numerical value “72” and graphically on a BC scale 122, such as the graphical exponential scale indicated in 122A, which can be color-coded, for example, Red-Yellow-Green, based on the magnitude and / or risk associated with the displayed BC score 80B. In an illustrative example shown in Figures 15-23, the relative BC score value 80C uses a scale that has an upper limit of ten (10), and is displayed in the user interface 90 on a graphical BC scale 122B, as a circular icon positioned relative to a slider bar (graphical BC scale 122B), and as a numerical value displayed on the circular icon. The slider bar... Petition 870260063687, dated 06 / 29 / 2026, page 40 / 145 / 54 slippage, for example, the BC 122B scale, can be color-coded, for example, Red-Yellow-Green, based on the magnitude of and / or risk associated with the BC 80C score that is displayed. For example, with regard to figure 15, a BC 80C score of “10” for a violation event 70 described as “OPM No. 2” (Personnel Management Office No. 2) is displayed in a red circular icon 80C positioned at the far right end (as shown on the page) of the “red” shaded yellow-orange-red BC scale 122B, wherein the BC 122B scale has an upper limit of ten (10), which indicates that the violation event 70 described as “OPM No. 2” has a BC 80C score of “10” in relation to other violation events 70 in the BC 100 system.In a related example, with respect to figure 16, a BC 80C score of “4.9” for a breach event 70 described as “Citibank, NA” is displayed in a yellow circular icon 80C located in an intermediate position (as shown on the page) in the orange part between the extremes of the BC scale shaded in yellow-orange-red 122B, where the BC scale 122B has an upper limit of ten (10), which indicates that the breach event 70 described as “Citibank, NA” has a BC 80C score of “4.9” in relation to other breach events 70 in the BC system 100, for example, presents relatively less risk to the consumer than the breach event “OPM n° 2” 70 shown in figure 15.

[0026] In step 62, the process continues with a prioritized list of consumer fraud mitigation actions specifically 116, which may include, for example, actions such as obtaining a credit freeze, setting a fraud alert, or credit monitoring, which is generated by the BC 100 system using data structure 22. The mitigation actions specifically 116 identified for the particular breach event 70 are ranked to generate an action set of mitigation actions 116 (see Figure 8) that represents the relatively strongest protection against the risks and damages specifically 72 identified by the BC 100 system for the particular breach event 70. In one example, algorithm 10 uses a table Petition 870260063687, dated 06 / 29 / 2026, page 41 / 145 / 54 of data 22D, as shown in Figure 11, which can be included in data structure 22, to determine a prioritization factor for action 136 for each data pair in table 22D, where a data pair consists of mitigation action 116 and potential harm 72. For example, with respect to Figure 11, algorithm 10 assigned a prioritization factor for action 136 of “10” to the data pair consisting of harm 72B “New Account Creation” and mitigation action 116A “Set Fraud Alerts”. The prioritization factor for action 136 for each data pair consisting of a damage 72 associated with a mitigation action 116 can be derived based on one or more of the information reported by the industry and / or from qualitative and quantitative research, and stored in the BC 22 data structure, for example, in data table 22D.In one example, algorithm 10 uses the prioritization factors 136 assigned to each damage-mitigation data pair associated with a breach event 70 in determining the ranking order, for example, in prioritizing, of the mitigation actions 116 generated as a risk output by server BC 10 for this breach event 70. The example is non-limiting, and algorithm 10 may use other inputs, such as the exposure score 132 of breach event 10, in determining the ranking order of the recommended mitigation actions 116.

[0027] In step 64, the BC outputs, including the BC score 80, the most likely, for example, the main predicted damages 72, the prioritized mitigation actions 116, and the exposure score 132 (see examples shown in Figures 19-23) are presented to the consumer-victim through a user interface 90 and, advantageously, in a presentation format designed for consumer use. The examples of user interface 90 provided here are favored by organizing the BC outputs in an easily understood and graphically summarized format, as opposed to ad-hoc, segmented, and / or otherwise generalized consumer data breach advice and / or information to which a consumer may, under other circumstances, be presented from multiple sources. Additionally, exemplary user interfaces 90 that can be Petition 870260063687, dated 06 / 29 / 2026, page 42 / 145 / 54 generated by the BC server 12, as shown in figures 12-23, include one or more graphical user interfaces (GUIs) that include links to reporting and resource servers 40, 50, etc., for the convenience of the consumer in accessing reporting and resource information, for example, from account providers, setting alerts and / or initiating other mitigation actions 116 that can be identified as BC outputs to the consumer by the BC system 100.With respect to Figure 1 and the non-limiting examples of the elements of data structures 22A, 22B, 22C, and 22D shown in Figures 3, 4, 6, and 11, data structure BC 22 includes the data and information compiled from a comprehensive listing of breach events 70 and is augmented with additional breach information as breach events 70 are reported, such that data structure BC 22 can be continuously updated to include breach information from substantially all current data breach events 70. The breach information stored in data structure BC 22 is uniquely syntactically parsed to identify the fields of the information element that correspond to the breached information elements 68 that are publicly reported in the data breach notification letters distributed to consumer victims.Publicly reported breach notifications are generated, in an illustrative example, by a reporting entity using breach information that may be stored in a reporting database 36. As previously described, this breach information may be obtained by the BC server 12 from the reporting database 36, for example, via the network 130 or by other means of data transfer, and stored by the BC server 12 in the BC data structure 22. The BC data structure 22, compared with existing publicly reported data breach lists, is substantially favored by being substantially expanded in content and extensively modified to include quantitative search, including search quantitatively related to a breached information element 68 with one or more potential harms 72. The information. Petition 870260063687, dated 06 / 29 / 2026, page 43 / 145 / 54 reported for each violation event 70, for example, by a reporting entity and / or from a reporting database 36 about the violation event 70 is syntactically parsed in approximately 40 or more record fields in the BC 22 data structure, appended with additional information on each violation event 70 that may have a material result on victimization, and tabulated in one of the machine-readable formats, such as the non-limiting examples shown in figures 3, 4 and 6 designed specifically for use with the BC 10 algorithms.Currently, the contents of all publicly available data breach notifications, such as those reported by individual reporting entities, are not available in a single database, and may not be available in a machine-readable format to allow algorithms (such as those described in this document) to compute predictions or recommendations. Additionally, the data breach information that is available from a database, such as a reporting database 36, may vary in format and structure, presenting a substantial challenge to consolidating breach information for risk analysis and quantification.The BC 22 data structure, which maps data received from a plurality of differently configured reporting databases 36 into a standardized data structure 22, and the BC method for generating risk outputs, provide a standardized and up-to-date database 22 of breach information and an efficient and standardized approach to quantifying the risks and damages 72 to a consumer victim associated with a data breach event 70, for this particular breach event 70 and in relation to other breach events 70. In one example, the BC 12 server can be integrated with one or more of the reporting servers 40 and resource servers 40, via APIs or, in other circumstances, to automatically receive up-to-date information, updates, etc. from these servers 40, 50, in such a way that the breach information stored in the BC 22 data structure is updated in real time or near real time with the updates made. Petition 870260063687, dated 06 / 29 / 2026, page 44 / 145 / 54 in the data on servers 40, 50. As such, the BC 100 system is favored by near real-time reporting of breach events 70, to minimize the time between the occurrence of a breach event 70 and the time the BC 100 system has completed the assessment of this breach event 70 which includes the generation of breach outputs, such as a BC score 80, a listing of the breached information elements 68, the ranking of potential damages 72, the exposure score 132 and the prioritized mitigation actions 116.

[0028] With regard to figure 3, in the example shown, a consumer initiates the Data Breach Score 100 system by providing the name of a particular data breach (such as “Azure Jewelers”, breach event 70F in the hypothetical example shown in figure 3), for example, through a user interface 90, where the entry for “Azure Jewelers” is associated via data structure BC 22 with information elements 68A and 68I that were reported as breached in the Azure Jewelers breach event 70F, and a program-ready information form that can be designed as “a Social Security number (SSN) (element 68A) and email address (element 68I)” is generated. The data breach in particular 70F (in the current example) can be stored in data structure 22, associated with the compromised information element fields in particular 68A, 68I.Server BC 12 applies algorithms 10 to the violated element fields 68A, 68I and the other unique characteristics of the particular data breach 70F (in the current example) to compute the BC outputs which include potential damages 72 most strongly enabled by the exposure of the SSN and email address, element risk scores 74 for each damage-information element combination, damage risk scores 76 for each damage that considers all information elements 68 violated in the particular breach event 70F, an exposure score 132, action prioritization factors 136 and / or a total BC score 80 for the Azure Jewelers breach event 70F, as illustrated in the example. Petition 870260063687, dated 06 / 29 / 2026, page 45 / 145 / 54 shown in figure 6.

[0029] Note that, for the sake of brevity, only a subset of the many publicly reported breachable information elements 68A, 68B,...68n are listed in the information element fields of data table 22A shown in Figure 3. The scope of breachable information elements 68 is not intended to be limited to the specific examples provided herein, and it will be understood that all types and / or categories of breachable information elements 68, including personally identifiable information (PII), protected health information (PHI), payment card industry (PCI), and other forms of breachable information, such as consumer biometric information, social identity information, online images, etc., which can be used to cause harm 72 to the consumer if breached, are included in the scope of information elements 68 that can be collected.stored and analyzed by the BC 100 system and method 200. By way of illustrative example, the 68 information elements that can be stored in the BC 22 data structure and used in the analysis of breach information and in the generation of risk outputs by the BC 10 algorithms and applications 20 include, but are not limited to, a consumer's Social Security Number (SSN or equivalent outside the US government); date of birth (DOB); place of birth, birth certificate number,Passport number; credit report; driver's license number; state ID information; citizenship documents or related data; voter registration or affiliation; related government or state security permit; taxpayer ID; employer; employee number; work address and phone number; income (including 1099 and W-2 and other salary information or the equivalent thereof outside the U.S. government); work address; email address; email password; student ID; other non-financial account number; credit, debit, or prepaid account number; cardholder or other financial account holder name; card expiration date; card secret code; Petition 870260063687, dated 06 / 29 / 2026, page 46 / 145 / 54 Card PIN; financial account bank routing number; loan or mortgage account information, such as balance and payment history; financial aid information; medical provider or insurance company account number, password, medical history, medical procedures, diagnosis, prescriptions; other medical provider (such as Medicare); residential address (current or previous); home, work, or mobile phone numbers; 401k and other investment account data; name in conjunction with other PII data; account numbers, usernames, passwords, and activity for accounts other than financial, payment card, medical, and email accounts (e.g., social media, internet access, utilities, or online shopping); professional license number, credentials and certifications, and similarly related information; biometric identifiers; and similar.In the non-limiting example shown in Figure 3, data table 22A uses indicator 66, illustrated in Figure 3 by an exemplary “X”, to indicate the particular information elements 68 that were violated in a particular breach event 70. In an illustrative example, breach event 70E identifies the breached entity as “ACME Health” and the information elements 68 that were violated in breach event 70E as place of birth, medical account number, and consumer name.

[0030] With regard to Figure 4, it should be noted that, for the sake of brevity, only a subset of the many potential risks and damages 72A.. 72n are listed in the damage fields of data table 22B shown in Figure 4. By way of illustrative example, possible damages 72 that may be stored in data structure BC 22 and used in the analysis of breach information and in the generation of risk outputs by algorithms BC 10 and applications 20 include, but are not limited to, tax fraud (including federal, state, county and municipal); new account financial fraud; new account fraud for non-financial accounts (such as utilities or cable); existing account fraud, including payment cards, deposit accounts, investment accounts, loan and mortgage accounts, insurance accounts; fraud of Petition 870260063687, dated 06 / 29 / 2026, page 47 / 145 / 54 other account, including Internet, merchant, online shopping (such as Amazon); social media, utility; fraud in government benefits, such as Social Security, Welfare, or Medicare; issuance or abuse of fraudulent identity credentials (such as passport or driver's license); property rental fraud, and similar. As illustrated in Figure 4, the BC 100 system includes algorithms 10 and / or applications 20 to create a data structure 22, shown in a non-limiting example as a data table 22B in Figure 4, which includes a risk score of element 74 determined by the BC 10 algorithms and / or quantitative research, wherein the risk score of element 74 is derived from and represents a risk value of the relationship between a particular violated information element 68 and a particular damage 72.Examples of damages 72 are shown in Figure 4, including tax refund fraud identified as damage 72A, new account fraud identified as damage 72B, health privacy violations, legal action fraud, and the like, as shown for the potential damage listing 72A, 72n. By way of illustration, and in relation to Figure 4, a violation of a Social Security Number (identified as information element 68A in the figure) as generating a potential tax refund fraud risk (identified as damage 72A in the figure) is assigned a value of “10” to its element 74 risk score, where the element 74 risk score may have a value on a pre-determined scale, for example, from 0-10, with an assigned value of “10” representing the highest potential risk of the damage occurring.In another example, and in relation to Figure 4, a breach of an email address (identified as information element 68I in the figure) as generating potential fraud damage to an existing payment card account is assigned a value of “3”, thus presenting a relatively lower risk of damage on the 0-10 risk scoring scale. It should be noted that the value assigned to each risk score of element 74 for each particular information element-damage pair is derived from aggregated research that includes examinations of... Petition 870260063687, dated 06 / 29 / 2026, page 48 / 145 / 54 quantitative research specifically designed for the development of the BC process, which is conducted with industry professionals experienced in the prevention or detection of abuse of particular information elements 68 (including PII, PHI or PCI fields), for particular harm 72, including those information elements 68 and harm 72 listed herein, in such a way that it would be perceived that the development of the risk score of element 74 for a particular information element harm pair is not a simple mathematical calculation nor based on publicly available information, but instead, the result of extensive quantitative research that consolidates and analyzes input collected from a variety of data breach experts, diverse data breach information sources and structures, and additional secondary research, as further described herein, including,For example, research related to the violating party, the timing relationship between a violation event and the risk of a particular harm occurring, etc.

[0031] The data structure 22B represented by the table shown in Figure 4 is populated with the element risk score 74 determined for each particular pairing of an information element 68 and a damage 72, using quantitative and secondary research, and is used by algorithms 10 to compute BC risk outputs for each breach event 70 entered into the BC 100 system and the data structure 22, including publicly reported data breach events, such as, for example, breach events 70A, 70B, 70E, 70F,...70n shown in Figure 3, and to compute BC risk outputs for an individual consumer breach event 70, for example, theft of a consumer wallet that includes information elements such as an SSN, driver's license numbers, account numbers, etc., that can be entered into the BC 100 system by a consumer-victim via a user interface 90E, as shown in figure 10.For each information element 68, the table shown in figure 4 illustrates which particular damages 72 are most strongly affected. Petition 870260063687, dated 06 / 29 / 2026, page 49 / 145 / 54 (or weakly) enabled by the criminal's possession of the breached information element 68 (with examples showing an upper limit, such as '10' representing the highest risk and '0' representing negligible risk or no risk). Reading table 22B to the right for any particular type of harm 72, the element risk values ​​74 entered for each information element 68 show which of the information elements 68, when breached, create the highest risk of this harm 72 being carried out by a victim of the data breach. The example shown in figure 4 is for illustrative purposes only, such that the particular values ​​entered for each element risk score 74 in data table 22B are illustrative and not limiting.It should be understood that the quantitative research from which the value of each element 74 risk score is derived is conducted periodically, such that the element 74 risk score can be updated as newly collected research results are incorporated into the BC 22 data structure and / or the BC 10 algorithms. Additionally, the 10 algorithms used to determine the BC risk outputs can be updated and revised based on inputs and results from ongoing and periodically conducted quantitative research, current and recently acquired breach information, and current and recently acquired secondary research, including research related to breaching entities (hackers, criminal organizations, etc.).), and in the potential risks and damages 72, including, for example, research and information related to the sale and use of breached information elements 68, in such a way that the algorithms 10 and / or the risk score values ​​of the element 74 for the information element-damage pairs can be dynamically updated as new research and data breach information is introduced.

[0032] Now, with regard to figures 5 and 6, an illustrative example using the fictitious breach event 70 referred to in the figures as the “Azure Jewelry Breach” event 70F is shown. Method 200, which includes flowchart 200B shown in figure 5 and which includes steps 82, 84, 86 and 88 Petition 870260063687, dated 06 / 29 / 2026, page 50 / 145 / 54 illustrates the application of the BC 100 system in the Azure Jewelers 70F breach event to generate the risk outputs shown in data table 22C of figure 6, including a listing of damages 72 associated with each of the breached information elements 68A, 68I, and the element risk score for each damage-information element pair obtained from data table 22B shown in figure 4. Data table 22 also shows a damage risk score 76 for each damage 72, which indicates the risk of this particular damage 72 based on the combination of information elements 68 that were breached during the breach event 72.In the illustrative example, the damage risk score 76A for fraud in a tax refund (damage 72A in the figure) is the sum of the risk score of element 74A for the damage risk 72A of violating an SSN number, which has a value of “10” in the example, and the risk score of element 74I for the damage risk 72A of violating an email address, which has a value of “6” in the example, generating a damage risk score 76A that has a value of “16” related to the damage 72A of tax refund fraud. In the example shown, the damage risk scores 76 are summed to generate an overall BC score 80, which, in the illustrative example, is an absolute BC score 80A. In the example shown, the data table 22C may include a comments field 78 to record and / or associate comments, observations, etc. with the particular damage 72.

[0033] As previously described, the BC 10 algorithm can be configured to generate a relative BC score 80B, wherein the relative BC score 80B can be derived from the absolute BC score 80A and expressed as a value on a fixed scale, such as a scale of 0 to 50, a scale of 0 to 10, a scale of 0 to 100, etc., as shown in the examples in Figure 8 and Figures 15-23, in such a way that the BC score 80B of a particular breach event 70 can be compared with the BC scores 80B generated for other breach events 70, to understand the relative risk of a breach event 70 compared to another breach event 70. In one example, data table 22C Petition 870260063687, dated 06 / 29 / 2026, page 51 / 145 / 54, can be displayed to the consumer-victim as a user interface 90B, for example, through the input / output interface 128 of a user device 30 accessing the BC system 100. The use of a simple summation algorithm to determine a damage risk score 76, and to determine an overall absolute BC score 80A is illustrative and not limiting.For example, the damage risk score 76 and / or the BC score 80A can be generated using an algorithm 10 that includes other operators, modifiers and / or operands, in addition to, and / or applied in conjunction with, the summation functions, wherein the operators, modifiers and / or operands can be derived from the breach information related to the particular breach event 70 for which the damage risk score 76 and the BC score 80 are being calculated, such as information related to the breaching organization or the post-breach containment actions taken by the breached entity 70 and / or other information related to the breach, such as research, current market conditions and / or industry intelligence related to the availability and exposure of the breached information, for example, for sales on the Dark web, of the breached information elements 68.As such, several additional factors can be applied by the BC 10 algorithms and / or incorporated into the 22C data structure in order to generate the risk outputs and BC results, as shown in Figure 6, which are timely, relevant, accurate, and easily understood by the consumer-victim. In the example 22C data table, additional algorithms 10 and / or proprietary research can be used to identify and / or prescribe consumer mitigation actions 116 that best address the areas of highest risk score for the consumer-victim.

[0034] Now, with regard to Figure 7, a flowchart 200C, which is included in the BC 200 method, is provided including steps 92 through 114, as described in Figure 7, which illustrates the aspects and / or features of the BC 10 algorithm that can be used with and / or incorporated into the basic methodology illustrated by flowchart 200A in Figure 2, where flowchart 200A is included in the BC 200 method described herein. In a Petition 870260063687, dated 06 / 29 / 2026, page 52 / 145 / 54 example, the BC 10 algorithm illustrated by flowchart 200C generates the BC 80 score as a relative BC 80B score, as a numerical score from 0 to an upper limit (such as 50 or 100), taking into account those damages 72 most commonly encountered by data breach victims, specific damages 72 that are most strongly predicted as determined by the BC methods described herein, and the mitigation actions with the highest reward 116.Flowchart 200C illustrates the use of the BC 10 algorithms to generate risk outputs for a known, for example, public and / or reported, data breach event 70, using steps 92 to 112 shown in Figure 7, and further provides the use of the BC 10 algorithms to generate risk outputs for an individual consumer breach event 70, using step 114 where a consumer-victim enters the breached information elements 68 through an example user interface 90E shown in Figure 10, and the BC algorithm is applied as described in steps 94 to 112 shown in Figure 7, to generate risk outputs for the individual data breach event 70.

[0035] As shown in Figure 7, in step 92, the violation event 70 is entered into the BC system 100 by the consumer-victim, through a user interface 90, which may be, for example, the user interface 90C shown in Figure 8 where the consumer enters the name of the violation event 70 in a violation input field 124, or the user interface 90D shown in Figure 9 where the consumer selects a violation input field 124 associated with the consumer's violation event 70 from a violation event menu that may include additional descriptive violation information, such as the date of the violation event 70 and / or the information elements 68 violated during the violation event 70.In other examples shown in Figures 12-23, the user interface 90 may include a violation input field 124 configured as a test box, a search field, and / or a drop-down menu that lists known violation events 70 included in the BC system 100. The consumer-victim may, for example, obtain the violation information from there. Petition 870260063687, dated 06 / 29 / 2026, page 53 / 145 / 54 of a notification of the breach event 70 provided by a reporting entity. Optionally, the consumer may enter, in step 114, the compromised (breached) information elements 68 through a user interface 90, such as the user interface 90E shown in figure 10. The victim-consumer may be asked to enter other essential information, such as a category of compromise, a method of breach, the time at which the compromise of the information elements 68 occurred and / or was detected, which may be stored in the data structure 22 associated with the victim-consumer, and used by the BC algorithms 10 in the generation of risk outputs.This provides an option for the consumer-victim to receive an assessment of the damages 72 and mitigation actions 116 that can be initiated by the consumer, in a circumstance where the breach event 70 is an individual breach, for example, the theft of an individual's wallet, and / or when the name of the breach event 70 is unavailable or unknown. The option illustrated in step 114 can be used by individuals who may have self-compromised their own information elements 68, for example, by description via social media, in an insecure disposition of a personal computing device, through the loss of a payment card or other personal information, such as medical records. Note that the example of user interface 90D in figure 10 shows only a partial list of all commonly reported exposed information elements 68, for brevity of illustration.The use of the optional consumer insertion method shown in step 114 will produce results, for example, risk outputs, that are substantially similar to those generated by the BC 100 system for a particular breach event 70 that has the same characteristics and / or combination of the breached information elements 68 inserted via step 114.

[0036] After receiving the consumer input through either of steps 92 and 114, the method continues to step 94, where, using the information that identifies the violation event 70, the BC server Petition 870260063687, dated 06 / 29 / 2026, page 54 / 145 / 54 12, for example, through an application BC 20, accesses the data structure BC 22 to retrieve the information associated with the breach event 70, including the specific information elements 68 exposed in the breach event 70, if not already received from the consumer through the user interface 90D. In one example, server 12 retrieves other unique characteristics of the breach event 70 for use by algorithms 10 in generating risk outputs. For example, the method of data exposure and / or the availability of breached data in so-called “Dark web” marketplaces where criminals sell the breached information elements 68, etc., can be retrieved from data structure 22 for use by algorithms 10, which may include an algorithm 10 to generate an exposure score 132.

[0037] In step 96, application BC 20, for each of the information elements 68 that was compromised by the breach event 70, retrieves a risk score of element 74 for each potential damage associated in the data structure 22 with the breached information element 68, as described in figure 4, where a risk score of element 74 is generated for each information element-damage pair. The risk score of element 74 is generated by algorithm BC 10.

[0038] In each of steps 98, 102, and 104, algorithm BC 10 can use the data breach information retrieved from data structure BC 22 to modify, weight, and / or filter the element risk scores 74 generated in step 96, before generating a damage risk score 76 for each potential damage 72 identified.

[0039] For example, in step 98, algorithm BC 10 may apply a weighted percentage to account for the overall availability of exposed information element 68, where overall availability is determined from quantitative research and may reflect the overall availability of exposed information element 68 from non-violating sources. For example, for an exposed information element 68 of a residential address, the factor applied may reflect the overall availability of the address. Petition 870260063687, dated 06 / 29 / 2026, page 55 / 145 / 54 consumer's residential address from publicly available records and / or other publicly available information resources, such as online directories.

[0040] For example, in step 102, algorithm BC 10 can apply a weighted percentage to account for the overall prevalence of each potential harm 72 associated in data structure 22 with the violated information element 68.

[0041] For example, in step 104, the BC 10 algorithm can apply a weighted percentage to account for the expected personal harm of each potential harm 72 to the individual consumer. The expected personal harm can be quantified in the data structure 22, for example, as the potential financial loss in dollars due to fraud, etc., or as expense incurred in implementing mitigation actions 116 and / or time in hours lost to contain, prevent and / or rectify the harm 72 or execute the mitigation actions 116. The expected personal harm can be quantified, for example, as the result of quantitative research collected from multiple resources and / or reporting entities and / or supplemented from publicly available information and / or information collected by the BC 100 system from consumer-victims through the user interface 90, or modified using an exposure score 132 determined for the particular violation 70.In one example, demographic and / or behavioral information collected from and / or about the individual consumer-victim, as previously described herein, and / or other information in the consumer-victim's risk profile stored on the BC server 12, including, for example, other violation events 70 by which the consumer-victim was victimized, may be taken into account in an algorithm 10 in estimating and / or determining the expected personal harm of each potential harm 72 to the individual consumer-victim.

[0042] In step 106, algorithm 10 calculates a damage risk score 76 for each potential damage 72 identified for the violated information elements 68, where the numerical value of the damage risk score Petition 870260063687, dated 06 / 29 / 2026, page 56 / 145 / 54 represents the predicted probability that the victim of a violation will experience the particular harm 72 for which the harm risk score 76 is provided. In a modification of the method described for generating the harm risk score 76 in Figure 6, algorithm 10, in step 106, generates a harm risk score 76 for each particular harm 72 by applying the factors described for steps 98, 102, and 104, to determine a finalized risk score 76 for each potential harm 72. The main harms 72, for example, the harms 72 that generate the relatively higher harm risk scores 76, are presented in visual representation to the consumer. In one example, the main damages 72 can be presented as the highest consumer risks, as illustrated by the user interface 90C shown in Figure 8.

[0043] In step 108, a total BC score of 80 is generated, representing the risk associated with all potential damages 72 associated by the BC algorithms 10 with all information elements 68 that were compromised by the breach event 70. In the user interface example 90C shown in Figure 8, the BC score 80 can be presented as a numerical value, and in a graphical representation 122. The numerical value of the BC score can be a relative BC score 80B, for example, expressed relative to a fixed BC scale. In relation to the example shown in Figure 8, the relative BC score value 80B is 72 / 100, where 100 is the upper limit of the BC 122A scale, and is displayed in the user interface 90C both as a numerical value “72” and graphically on a BC 122A scale, which can be color-coded, for example, Red-Yellow-Green, based on the magnitude and / or risk associated with the displayed BC 80B score.In relation to the examples shown in figures 15-23, the relative BC score value 80C is expressed on a scale that includes an upper limit of “10”, and is displayed in the user interface 90 both as a numerical value shown in a circular icon and graphically on a color-coded BC scale 122B, which can be color-coded, for example, Yellow-Orange-Red, based on the. Petition 870260063687, dated 06 / 29 / 2026, page 57 / 145 / 54 magnitude of and / or risk associated with the BC 80C score that is displayed. In relation to the example of user interfaces 90Q, 90R shown in figures 21 and 22, the violation event 70 described in figure 21 as “Lighthouse Management Services” has an overall BC score of 7.3 indicated by the red circular icon positioned near the right end (as shown on the page) of the graphical BC scale 122B, and the violation event 70 described in figure 22 as “Tarte Cosmetics” has an overall BC score of 1.5 indicated by the yellow circular icon positioned near the left end (as shown on the page) of the graphical BC scale 122B, such that it is understood that the risk of harm from the violation event “Tarte Cosmetics” 70 is assessed as relatively lower than the risk of harm from the violation event of “Lighthouse Management Services” 70.

[0044] In step 110, algorithm BC 10, which uses the risk scores of element 74 of the violated information elements 68, determines the recommended consumer action steps, including, for example, mitigation actions 116, as illustrated by the examples shown in Figure 8 and Figures 15-23. The consumer action steps and / or mitigation actions 116 are based on information that can be stored in data structure BC 22, including, for example, the results of research interviews, qualitative and quantitative input, and / or examinations by impartial industry experts working in the field of protecting consumer harm related to identity.

[0045] In step 112, the BC 12 server transmits the risk outputs generated by the BC 10 algorithms and / or BC 20 applications to the victim-consumer, through a user interface 90 configured by the BC 100 system. In one example, the user interface 90C shown in Figure 8 is displayed to the victim-consumer through the input / output interface 128 of the user device 30. As illustrated by the examples shown in Figure 8 and Figures 15-23, the BC risk outputs are displayed in such a way that the name of the violation event 70, the listing of risks and damages 72 in Petition 870260063687, dated 06 / 29 / 2026, page 58 / 145 / 54, in order of ranking, beginning with the damages 72 for which the highest risk score of 76 was determined, the BC score 80, displayed as a relative BC score 80B both numerically and on a graphical BC scale 122, and a list of mitigation actions 116 determined to have the relatively highest potential to mitigate the identified damages 72 are all viewable in a summary format by the consumer-victim to provide a comprehensive overview of the violation event 70 as it affects the consumer-victim.The example shown in Figure 23 illustrates an example of the 90S user interface that can be generated for a consumer-victim who has been victimized by a plurality of 70 violation events, wherein, in this example, the individual BC scores 80 and exposure scores 132 are shown for each of the 70 violation events, in the manner previously shown for each of the individual violation user interfaces for those 70 violation events in Figures 19-22. In contrast to Figures 19-22, in the 90S summary user interface shown in Figure 23, the predicted risks 72 identified for the individual 70 violation events have been consolidated using an algorithm 10 into a consolidated risk distribution 134, and the key action steps 116 have been consolidated using an algorithm 10 into a prioritized consolidated rank-ordered listing, for example, of the mitigation actions 116 recommended for action by the consumer-victim.The algorithms used to generate the consolidated risk distribution and / or the consolidated list of ranked mitigation actions may include, for example, operands, modifiers, and / or other weighting factors that account for the frequency of exposure of the violated information elements through the multiple violation events experienced by the consumer-victim, the exposure scores of the multiple violation events, the demographic and / or behavioral characteristics of the consumer-victim stored in a BC risk profile of the subscriber-consumer in the data structure and / or otherwise received by the BC server, etc. The summary BC user interface provides the consumer-victim who was... Petition 870260063687, dated 06 / 29 / 2026, page 59 / 145 / 54 victimized by multiple violation events 70 with a consolidated risk assessment that includes the BC risk outputs that have been ranked, quantified and / or otherwise prioritized for this consumer-victim's individualized situation, thus advantageously focusing the consumer on the main ranked mitigation actions 116, for example, most effective to be taken to reduce the risk of harm to the consumer through the total of multiple violation events 70 experienced by the consumer.

[0046] By a non-limiting example, user interface 90 may include one or more graphical user interfaces (GUIs) that may be used by the victim-consumer to interact with user interface 90 to view information relating to the breach event 70 and / or risk outputs BC and / or action mitigation steps 116. By way of a non-limiting example, user interfaces 90, including 90a through 90S, may include one or more of graphical user interfaces 118, 120, 122, 124, 132, 134, as described herein in further detail. The term “graphical user interface” or “GUI” shall be interpreted broadly and may include, for example, one or more graphical icons, links, buttons, switches, input fields, widgets, menus, lists, text windows, dialog boxes, etc.The consumer-victim can interact with the GUI, for example, by entering the GUI via a touch on a touchscreen displaying the user interface 90, by entering from a keyboard, which could be a virtual keyboard displayed on the input / output interface 128, or by entering from a pointing device such as a mouse, pointing stick, voice input, etc. In an illustrative example shown in Figure 8, the user interface 90C can include multiple GUIs. As shown in the examples in Figures 8, 9, 12-14, and 23, a user can enter a violation descriptor 70 into an input field 124 to search for a violation event, or a plurality of violation events. By way of non-limiting example, the input field 124 can be a search field, can include a drop-down menu, or be linked to a pop-up screen listing the violation events 70, which includes... Petition 870260063687, dated 06 / 29 / 2026, page 60 / 145 / 54 data structure BC 22, etc. In the example shown in Figure 8, a user entry in the field displaying the breach descriptor 70E, “ACME Data Breach”, can trigger user interface 90C to display additional information about the breach event 70E, the ACME data breach. The additional information can be displayed, for example, in a snapshot window or by expanding the breach event field in user interface 90C. The additional breach information may include, for example, the date(s) of the breach, the number of consumers affected by the breach, information (if known) about the breaching organization, a listing of the information elements 68 compromised by the breach event 68, contact information for the breached entity (in the current example, ACME), etc.

[0047] For example, a user input in a GUI associated with the field displaying “Your Highest Risks” can actuate the user interface 90C to display additional information about the damage list 72, for example, by expanding the window to show the full list of potential damages 72 associated with the ACME breach event 70E by the BC system 100. In one example, a field for a particular damage 72, such as “Tax Fraud,” can be actuated by the consumer in such a way that the user interface 90C displays the additional information associated with the “Tax Fraud” damage 72A, which may include a description of the particular damage 72A, the damage risk score 76 assigned to the particular damage 72A by the BC algorithm 10, the mitigation actions 116 recommended for the particular damage 72A, etc.

[0048] For example, a user input in a GUI associated with the field displaying “Your To-Do List” (see Figure 8) or the field displaying “Key Action Steps” (see Figures 15-23) can trigger user interface 90 to display additional information about the list of mitigation actions 116, for example, by expanding the window to show the full list of mitigation actions 116 recommended to the consumer victim of the ACME 70E breach event by the BC 100 system. In a Petition 870260063687, dated 06 / 29 / 2026, p. 61 / 145 / 54 For example, a field for a particular “to-do” item, such as the field listing mitigation action 116 “Set fraud alerts through a credit bureau”, can be configured as an actionable touch input, for example, by the consumer's touch input, in such a way that the user interface 90C displays the additional information associated with the mitigation action “Set fraud alerts through a credit bureau” 116, which may include an explanation of the mitigation action 116, the expected benefits and / or the mitigating effect of completing the action, etc., the particular harms 72 that are potentially mitigated by completing the particular action “Set fraud alerts through a credit bureau”, a list of resource entities, for this example, a list of credit bureaus through which a fraud alert can be set, etc.and / or may open a link to a resource provider and / or a resource server 50 in such a way that the consumer can immediately initiate the mitigation action 116 by viewing the BC outputs for the violation event 70. For example, the user interface 90C can be configured in such a way that the consumer can initiate a particular mitigation action 116 through the user interface 90C, for example, by connecting through the user interface 90C to a resource interface 48 (see Figure 1) configured to provide the particular mitigation action 116. In the present example, the user interface 90C can be configured in such a way that, when the consumer acts on the GUI associated with the mitigation action 116 displayed as “Set fraud alerts through a credit bureau”, an actionable link to one or more credit bureaus (resource entities) can be displayed to the consumer.Selecting the link to one of the credit bureaus can direct the consumer to the credit bureau's online interface 48, so that the consumer can immediately take the steps to complete the mitigation action 116 "Setting up fraud alerts through a credit bureau".

[0049] The user interfaces 90, in the examples shown, can be acted upon by the consumer to export at least part of the Petition 870260063687, dated 06 / 29 / 2026, page 62 / 145 / 54 information on BC violation due to the consumer's activation of the "Export" icon 120 in the present illustration. In the example of user interface 90C shown in figure 8, the BC 20 application is configured to export the "tasks" from the mitigation actions list 116 to a calendar application when the Export icon 120 is activated, for monitoring by the consumer. In another example, the BC 20 application is configured to generate and display a menu listing when the "Export" icon 120 is activated.The menu listing may include one or more of the violation event name 70, the BC score 80, the damage listing 72, and the to-do list which includes mitigation actions 116, in such a way that the consumer can select which items of violation information, risk outputs and / or actions the consumer would like to have exported by the BC application 20 to an export format that can be selected by the consumer, wherein the export format may be, for example, a downloadable file, a printable version of the user interface 90C, calendar entries, etc. Additional examples of export icons 120 are shown in figures 15-23.

[0050] Figures 12-14 illustrate non-limiting examples of user interfaces 90F, 90G, 90H through which a consumer can access the BC 100 system and the BC risk outputs previously described herein. The example shown in Figure 12 illustrates a BC 90F interface that can be used to provide introductory information to a consumer, which may include a violation input field 124 to enter the name of a violation to be searched, or to actuate a drop-down menu of violation events 70 for which violation information can be retrieved from the BC 100 system. The BC 90F user interface may include one or more actuatable links 118 to connect the consumer to third-party resources, including, for example, report servers 40 and / or resource servers 50, from which the consumer can obtain additional violation information.In an illustrative example, the BC user interface shown in Figure 13 may include the GUI links 118a. Petition 870260063687, dated 06 / 29 / 2026, page 63 / 145 / 54 third-party providers, such as financial or health institutions, that may offer subscription-based and / or sponsored access to the BC 100 system to consumers affiliated with the sponsoring institution, such as bank clients and / or health system participants, as a service to raise awareness of breach risks and mitigation actions 116.

[0051] Figures 15-23 are provided as illustrative examples of user interfaces 90G, 90H, 90J, 90K, 90L, 90M, 90N, 90P, 90Q, 90R, and 90S that can be generated by server BC 12 and transmitted to a user device 30 for display to and / or access by a victim consumer, including the BC risk outputs previously described herein.As shown in Figures 15-23, risk outputs BC may include, for example, a descriptor of the breach event 70, a Breach Clarity™ score 80 shown numerically and / or graphically 80C, a listing of the information elements 68 exposed by the breach event 70, a listing of the damages and / or risks 72 which may also be shown as a risk distribution graph 134 which, in the illustrative examples, is a pie chart or segmented ring graph (doughnut), a listing of mitigation actions 116 which are ordered by rank of effectiveness in protecting the consumer from harm, an exposure score 132 based on the type and / or nature of the breach event 70 (hacking, unauthorized access, theft, Internet exposure, etc.), and one or more GUIs or links that can be acted upon by the consumer through the user device 30 to access affiliated Internet pages, Internet pages, resources, third-party providers, etc., including, for example, one or more reporting and / or resource servers 40, 50.

[0052] The examples provided here are not exhaustive. For example, the 10 algorithms described here are illustrative and may include additional factors, operands and / or operators gathered from the quantitative research that was conducted in the development of the violation system. Petition 870260063687, dated 06 / 29 / 2026, page 64 / 145 / 54 data 100. For example, a BC 10 algorithm can be configured to include a persistence factor for each information element 68, where the persistence factor quantifies the persistence of the value of a particular information element 68, for example, the probability that the value of the particular information element 68 remains constant over time. For example, an information element 68, such as a Social Security number, which typically remains the same throughout the consumer's life, has relatively high persistence. Conversely, an information element 68, such as a payment card number, which may change regularly, has relatively low persistence.Data structure 22 will be populated with additional information from future data breach events, and quantitative research will continue to be conducted, such that algorithms 10 should be considered dynamic; for example, the method described here includes periodically reviewing algorithms 10 based on new and additional information gathered from quantitative research and new information related to breach events and the damage associated with these events.For example, a risk score of 72 for element 72 associated with a particular information element-damage pair in data structure 22 may be modified as additional information becomes available from reporting entities and / or resource entities regarding the availability of the breached information elements and / or regarding actions taken by the breached entity to contain the damage associated with its breach event, government identity protection actions, coercion efforts against criminals to reduce the availability of the breached information, etc.

[0053] The detailed description and drawings or figures are for supporting and descriptive purposes of the description, but the scope of the description is defined exclusively by the claims. Although some of the best ways and other embodiments for carrying out the claimed description have been Petition 870260063687, dated 06 / 29 / 2026, p. 65 / 145 / 54, described in detail, several alternative designs and embodiments exist to carry out the description defined in the appended claims. Furthermore, the embodiments shown in the drawings or the features of the various embodiments mentioned in this description should not necessarily be understood as embodiments independent of each other. Instead, it is possible that each of the features described in one of the examples of an embodiment may be combined with one or a plurality of other desired features from other embodiments, resulting in other embodiments not described in words or by reference to the drawings. In this way, such other embodiments fall within the scope of the appended claims. Petition 870260063687, dated 06 / 29 / 2026, p. 66 / 145

Claims

1 / 7 CLAIMS 1. A method for determining a risk of harm to a consumer resulting from a data breach of consumer information, characterized in that it comprises: populating, by means of a server, a data structure with the breach information; wherein the breach information includes: a plurality of consumer information elements; and a plurality of consumer harms (72); wherein each consumer harm (72) is defined as harm suffered by a consumer resulting from the breach of at least one consumer information element; wherein each consumer information element of the plurality of consumer information elements is paired with each consumer harm (72) of the plurality of consumer harms (72) to generate a plurality of information element-harm data pairs;generate, using a set of instructions, a risk score of the element (74) for each respective element-information damage pair of the plurality of element-information damage data pairs; associate, in the data structure, the risk score of the element (74) with the respective element-information damage data pair; wherein the breach information additionally includes: a breach event descriptor (70), wherein the breach event descriptor (70) identifies an occurrence of a breach event during which at least one consumer information element is compromised; and at least one breached information element (68), wherein the at least one breached information element (68) includes at least one consumer information element from the plurality of consumer information elements that was compromised by the breach event;the method further comprising: Petition 870260063687, dated 06 / 29 / 2026, page 67 / 145 2 / 7 receiving, through the server, the descriptor of the violation event (70) and at least one violated information element (68); associating, in an additional data structure, the descriptor of the violation event (70) with at least one violated information element (68); and associating, using the data structure, each pair of information-damage element of the plurality of information-damage element data pairs that includes at least one violated information element (68) with the descriptor of the violation event (70).; 2. Method according to claim 1, characterized in that it further comprises: generating, using the instruction set, an exposure score (132) for the violation event; and associating, in the data structure, the exposure score (132) with the violation event descriptor (70): wherein the exposure score (132) is associated with the exposure probability of the violated information element (68).

3. Method according to claim 1, characterized in that it further comprises: generating, using the instruction set, a risk score (76) for the respective consumer damage (72) of each element-damage data pair associated with the violation event descriptor (70); associating, using the data structure, the damage risk score (76) for each consumer damage (72) with the violation event descriptor (70); and storing in the data structure the damage risk score (76) associated with the violation event descriptor (70).

4. Method according to claim 3, characterized in that generating the damage risk score (76) includes summing the element risk scores (74) of the respective damage-element data pairs of Petition 870260063687, dated 06 / 29 / 2026, page 68 / 145 3 / 7 information, including the respective damage.

5. Method according to claim 3, characterized in that it further comprises: generating, using the instruction set, a data breach score (80) for the breach event; and wherein the generation of the data breach score (80) includes summing the harm risk scores (76) of the respective consumer harms (72) of each information element-harm data pair associated with the breach event descriptor (70) to generate the data breach score (80).

6. Method according to claim 5, characterized in that the data violation score (80) is calculated by the instruction set with an absolute value.

7. Method according to claim 5, characterized in that the data violation score (80) is calculated by the instruction set as a relative value.

8. Method according to claim 7, characterized in that it further comprises: generating the relative value, using the instruction set, by applying at least one of a scaling factor and a modifier to the data violation score (80).

9. Method according to claim 5, characterized in that it further comprises: transmitting, via the server, the data violation score (80) to a user interface (90); wherein the user interface (90) is in communication with the server; and wherein the user interface (90) is configured to be accessible by a consumer who owns the violated information element (68).

10. Method according to claim 9, characterized in Petition 870260063687, dated 06 / 29 / 2026, page 69 / 145 4 / 7 by the fact that it further comprises: generating, using the instruction set, at least one mitigation action (116) to mitigate at least one consumer harm (72) associated with the violation event descriptor (70); and transmitting at least one consumer harm (72) and at least one mitigation action (116) to the user interface (90).

11. Method according to claim 10, characterized in that it further comprises: associating, in the data structure, at least one mitigation action (116) with at least one consumer damage (72) to form a damage mitigation action data pair; determining, using the instruction set, a prioritization factor (136) for the damage mitigation action data pair.

12. Method according to claim 11, characterized in that at least one mitigation action (116) includes a plurality of mitigation actions (116); determine, using the instruction set, a respective prioritization factor (136) for each respective mitigation action (116) of the plurality of mitigation actions (116); and associate, in the data structure, the respective prioritization factor (136) with each respective mitigation action (116).

13. Method according to claim 12, characterized in that it further comprises: compiling, using the instruction set, a listing of the plurality of mitigation actions (116); wherein each respective mitigation action (116) is ordered in the listing according to the respective prioritization factor (136) associated with the respective mitigation action (116).

14. Method according to claim 10, characterized in that it further comprises: associating, in the data structure, a user interface (90) Petition 870260063687, dated 06 / 29 / 2026, page 70 / 145 5 / 7 with at least one mitigation action (116); wherein the user interface (90) is configured to be actionable by the proprietary consumer to initiate at least one mitigation action (116).

15. Device for determining a risk of harm to a consumer resulting from a data breach of consumer information, characterized in that it comprises a processor and non-transient memory, the non-transient memory storing instructions executable by the processor which, when executed by the processor, cause the device to perform the steps of: filling a data structure with the breach information; wherein the breach information includes: a plurality of consumer information elements; and a plurality of consumer harms (72); wherein each consumer harm (72) is defined as harm suffered by a consumer resulting from a breach of at least one consumer information element;wherein each consumer information element of the plurality of consumer information elements is paired with each consumer damage (72) of the plurality of consumer damages (72) to generate a plurality of information element-damage data pairs; generate, using a set of instructions, an element risk score (74) for each respective information element-damage pair of the plurality of information element-damage data pairs; and associate, in the data structure, the element risk score (74) with the respective information element-damage data pair; wherein the violation information additionally includes: a violation event descriptor (70), wherein the violation event descriptor (70) identifies a violation event;and at least one violated information element (68), in Petition 870260063687, dated 06 / 29 / 2026, page 71 / 145 6 / 7 that the at least one violated information element (68) is a respective consumer information element of the plurality of consumer information elements that was compromised by the violation event; wherein the device is additionally configured to: receive the violation event descriptor (70) and the at least one violated information element (68); associate, in the additional data structure, the violation event descriptor (70) with the at least one violated information element (68); and associate, using the data structure, each pair of information-damage element of the plurality of information-damage element data pairs that includes the at least one violated information element (68) with the violation event descriptor (70).; 16. Device according to claim 15, characterized in that the instructions additionally cause the device to perform the following steps: generate, using the instruction set, a damage risk score (76) for the respective consumer damage (72) of each element-damage data pair associated with the violation event descriptor (70); associate, using the data structure, the damage risk score (76) for each consumer damage (72) with the violation event descriptor (70); and store in the data structure the damage risk score (76) associated with the violation event descriptor (70).

17. Device according to claim 16, characterized in that the instructions additionally cause the device to perform the steps of: generating, using the instruction set, a data breach score (80) for the breach event; and wherein the generation of the data breach score (80) includes Petition 870260063687, dated 06 / 29 / 2026, page 72 / 145 7 / 7 summing the harm risk scores (76) of the respective consumer harms (72) of each information element-harm data pair associated with the breach event descriptor (70) to generate the data breach score (80).

18. Device according to claim 15, characterized in that the instructions additionally cause the device to perform the steps of: generating, using the instruction set, an exposure score (132) for the violation event; and associating, in the data structure, the exposure score (132) with the violation event descriptor (70). Petition 870260063687, dated 06 / 29 / 2026, p. 73 / 145