What is a clone phishing email and how do I spot one?
Clone phishing exactly copies a real email you may have received before, replacing links or attachments with malicious ones. It is one of the hardest phishing types to spot.
Last reviewed: 1 August 2026
Explanation
Clone phishing takes a legitimate email — such as a shipping notification, bank statement, or invoice — that you actually received at some point and produces an almost identical copy. The sender address is spoofed to match the original, the branding is identical, and the only change is that real links are replaced with phishing URLs or the attachment is swapped for a malware file. Because the email closely resembles something you trust and have seen before, it bypasses the scepticism you might apply to a novel approach. The tell-tale sign is that the link destination differs from the legitimate domain — hover over any link before clicking to verify the URL. If in doubt, navigate to the service directly through your browser rather than through any link in an email.
Clone phishing marks a shift in what phishing filters and instincts must catch, because familiarity — the strongest trust signal most people use — is exactly what it counterfeits. Your practical defences are habits that do not depend on novelty detection: treating every link as unverified regardless of how familiar the email looks, keeping bookmarks for the services you actually use and reaching them only that way, and being especially careful with 'resend' or 'updated' framing, which exists to explain why you are seeing a message twice. If a cloned email references a real transaction of yours, also consider whether the account that received the original has been compromised.
Common red flags
- Email looks nearly identical to a real message you received previously
- Subject line is 'Resend' or 'Updated' version of a prior email
- Hovering over links reveals a different domain from the real company
- Attachment has a new or different filename from the original
What to do now
- Hover over links to verify the destination before clicking
- Navigate to the service directly rather than through email links
- Report the email to the impersonated organisation's phishing address
- Mark as phishing in your email client to train spam filters
Frequently asked questions
How did the scammer get a copy of the original email?
Clone phishing often follows account compromise — the attacker reads your mailbox and identifies real messages to clone. It can also use publicly available email templates from known services.
Why would attackers bother cloning an email I already acted on?
Because your past interaction is exactly what makes the clone credible — you recognise the message and remember it being safe. 'Updated invoice' and 'resent notification' framings exploit that memory to lower your guard on the swapped link or attachment.