Clone Phishing
Clone phishing copies a real email the victim already received, swaps its links or attachments for malicious ones, and resends it as a follow-up.
Clone phishing is a phishing technique in which the attacker takes a legitimate email the victim has already received — a shipping notification, an invoice, a shared document alert — and creates a near-perfect duplicate, replacing the original links or attachments with malicious versions. The clone is then sent from a spoofed or look-alike address, often framed as a re-send: "Resending — updated attachment" or "Previous link expired."
How it works
The attacker first needs a template, which they obtain by compromising a mailbox in the conversation, intercepting messages, or simply subscribing to the same automated notifications the victim receives (order confirmations, SaaS alerts, newsletters). They copy the genuine email's design, wording, signature, and thread history exactly, so the message passes the recipient's visual memory check — I've seen this email before, and it was fine. Only the payload differs: the invoice PDF now carries malware, or the "View document" button points to a credential-harvesting page on a typosquatted domain.
Clone phishing is especially effective as a follow-up inside hijacked threads. When an attacker compromises one company's mailbox, they can reply to real, ongoing conversations with cloned formatting and a poisoned link — a tactic widely used to spread banking trojans and to redirect invoice payments in business email compromise.
How to defend against it
Technical controls come first: DMARC enforcement makes exact-domain spoofing fail, sandboxing detonates attachments before delivery, and link rewriting catches known-bad URLs even in visually perfect emails. But the decisive habit is behavioral — treat any re-sent or corrected message as a fresh trust decision. If an email claims to replace one you already acted on, verify through a second channel before clicking, and check the sender's actual address rather than the display name. Duplicate-message lures belong in your phishing simulation rotation, because they specifically defeat the "does this look familiar?" heuristic that most awareness training accidentally teaches people to rely on.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo