Clone Phishing

An attack where a legitimate previously delivered email is duplicated with malicious links or attachments and resent to the victim.

Clone phishing is a sophisticated phishing technique in which an attacker creates a near-identical copy of a legitimate email that the victim has previously received. The cloned message replaces genuine links or attachments with malicious versions while preserving all other elements — sender display name, subject line, formatting, and content — to make the fraudulent email appear authentic. The attacker typically claims the message is a resend or an updated version of the original.

This technique is especially dangerous because it leverages existing trust. When a recipient has already interacted with the original email, they are far less likely to scrutinize a seemingly identical follow-up. Clone phishing often occurs after an attacker has gained access to a victim's mailbox or has intercepted email communications, allowing them to identify which legitimate messages to clone. The attack can also be used to propagate laterally within an organization by cloning internal communications.

Clone phishing is frequently used in targeted attacks against businesses, where internal email communications follow predictable patterns. An attacker who has compromised one account can clone a legitimate email thread and distribute malware or credential-harvesting links to everyone in the conversation. Detection requires careful attention to email headers, link destinations, and attachment hashes, combined with email security solutions that can compare incoming messages against previously delivered content.

Examples

  • A resend of a legitimate invoice email where the PDF attachment has been replaced with a malware-laden file.
  • A cloned internal team update email with modified links pointing to a credential-harvesting page.
  • A duplicate of a real shipping confirmation where the tracking link redirects to a phishing site.

Prevention

  • Verify unexpected resends or updated emails by contacting the sender through a separate channel.
  • Hover over links to check URLs before clicking, even in emails that appear familiar.
  • Deploy email security tools that detect duplicate messages with altered links or attachments.
  • Enable email authentication protocols (SPF, DKIM, DMARC) to reduce spoofed resends.

Try These Tools

Phishing URL Scanner Domain Lookalike Finder

Related Terms

Phishing Spear Phishing Email Spoofing

Stay Protected with Beacky

Detect phishing clones of your website in real-time with invisible beacon technology.

Get Started with Beacky