← All terms

Clone Phishing

Clone phishing copies a real email the victim already received, swaps its links or attachments for malicious ones, and resends it as a follow-up.

Clone phishing is a phishing technique in which the attacker takes a legitimate email the victim has already received — a shipping notification, an invoice, a shared document alert — and creates a near-perfect duplicate, replacing the original links or attachments with malicious versions. The clone is then sent from a spoofed or look-alike address, often framed as a re-send: "Resending — updated attachment" or "Previous link expired."

How it works

The attacker first needs a template, which they obtain by compromising a mailbox in the conversation, intercepting messages, or simply subscribing to the same automated notifications the victim receives (order confirmations, SaaS alerts, newsletters). They copy the genuine email's design, wording, signature, and thread history exactly, so the message passes the recipient's visual memory check — I've seen this email before, and it was fine. Only the payload differs: the invoice PDF now carries malware, or the "View document" button points to a credential-harvesting page on a typosquatted domain.

Clone phishing is especially effective as a follow-up inside hijacked threads. When an attacker compromises one company's mailbox, they can reply to real, ongoing conversations with cloned formatting and a poisoned link — a tactic widely used to spread banking trojans and to redirect invoice payments in business email compromise.

How to defend against it

Technical controls come first: DMARC enforcement makes exact-domain spoofing fail, sandboxing detonates attachments before delivery, and link rewriting catches known-bad URLs even in visually perfect emails. But the decisive habit is behavioral — treat any re-sent or corrected message as a fresh trust decision. If an email claims to replace one you already acted on, verify through a second channel before clicking, and check the sender's actual address rather than the display name. Duplicate-message lures belong in your phishing simulation rotation, because they specifically defeat the "does this look familiar?" heuristic that most awareness training accidentally teaches people to rely on.

Related terms

PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.TyposquattingTyposquatting registers look-alike domains — misspellings or swapped characters — to catch mistyped URLs and lend fake emails and sites credibility.Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo