PhishingMedium Severity14 min read

Clone Phishing

Learn how clone phishing works, how legitimate emails are duplicated with malicious links and attachments, and how to protect yourself. Includes real-life examples, warning signs, and expert safeguarding tips.

Published: May 22, 2026

Overview

What is clone phishing?

Clone phishing is a highly deceptive attack in which a scammer takes a genuine, previously delivered email — from a bank, a software provider, a delivery service, or a colleague — and creates an almost perfect replica of it. The cloned message is identical in appearance: same sender name, same subject line, same layout, same branding. The only difference is that the original legitimate links or attachments have been quietly replaced with malicious ones.

The cloned email is then sent to the same recipient, often with a plausible explanation for why it is being resent — "Updated attachment," "Corrected link," or "Please disregard the previous version." Because the victim has already received and trusted the original message, the follow-up feels entirely routine. There is no unfamiliar brand, no suspicious cold contact, no implausible cover story — just what appears to be a slightly amended version of something real.

This is what makes clone phishing distinctly more dangerous than generic phishing campaigns: it does not need to manufacture trust from scratch. It borrows trust that already exists, attaching itself to an established and verified communication the victim has no reason to doubt.

Who is targeted: Employees who receive high volumes of routine email — particularly those in finance, IT, legal, and procurement — as well as individuals who regularly interact with service providers, subscription platforms, or cloud-based tools. Organisations that have suffered a prior data breach are at elevated risk, as stolen email data directly enables cloning.

Why it works: The human brain relies on pattern recognition as a cognitive shortcut. A message that looks exactly like something we have already verified and acted on triggers familiarity rather than scrutiny. Clone phishing exploits this directly — the more convincing the original, the more convincing the clone.

Scale & Statistics

How common is this scam?

Clone phishing sits within the broader email phishing landscape, which remains the dominant vector for cybercrime globally. While clone phishing is harder to isolate in aggregated statistics than mass phishing campaigns, its prevalence and impact are well documented within enterprise security reporting.

  • 94% of all malware is delivered via email — clone phishing is one of the primary mechanisms for this delivery
  • $4.88 million is the average cost of a data breach originating from a phishing email, of which clone phishing is a significant variant — the highest figure ever recorded, per IBM's 2024 report
  • Clone phishing and spear phishing together account for the majority of targeted email attacks on organisations, according to Proofpoint's 2024 threat intelligence data
  • Employee targeting is consistent: 84% of organisations globally reported at least one successful email-based phishing attack in 2023
  • Credential harvesting — the primary goal of most clone phishing attacks — was the leading cause of data breaches in 2024, responsible for 61% of all breach incidents according to Verizon's DBIR
  • Reused email threads increase click-through rates significantly: messages that appear to be part of an existing conversation achieve up to 3x higher engagement than cold phishing emails
  • Business email compromise (BEC), which frequently relies on cloned communications, caused $2.9 billion in reported losses in the US in 2023 alone

Most affected sectors: financial services, healthcare, legal and professional services, and technology companies handling sensitive client data.

Sources: IBM Cost of a Data Breach Report 2024; Verizon Data Breach Investigations Report 2024; Proofpoint State of the Phish 2024; FBI IC3 2023 Internet Crime Report; Cofense Email Security Annual Report 2024

How It Works

How does it work?

Clone phishing requires more preparation than a mass phishing campaign, but the additional groundwork makes it significantly more effective. The attack is surgical rather than opportunistic.

  1. The scammer obtains a genuine email — Access to the original email is typically gained through a prior compromise: a hacked email account within the organisation, a data breach that exposed email content, malware already running on a device, or interception of email traffic through a misconfigured mail server. In some cases, the scammer simply signs up for a newsletter or service the target is known to use, then uses their own legitimate copy as the template.

  2. The email is cloned — The original message is replicated in full: subject line, sender display name, body text, formatting, logos, and footer. Every visual element is preserved to ensure the clone is indistinguishable from the original at a glance.

  3. Malicious content is substituted — The legitimate links in the original email are replaced with URLs pointing to fake login pages, malware download sites, or credential-harvesting forms. Legitimate attachments — invoices, documents, software updates — are replaced with trojanised versions containing malware, ransomware, or keyloggers.

  4. The sender address is spoofed — The scammer registers a domain that closely resembles the legitimate sender's (e.g. support@micros0ft-account.com instead of support@microsoft.com) or uses email header manipulation to display the real organisation's name while routing replies elsewhere.

  5. The clone is sent with a plausible update rationale — The victim receives the cloned email with a brief note explaining the resend: "We noticed an issue with the previous link," "Please use this updated document," or simply "Resending for your reference." This removes the need to establish trust — it only needs to sustain it.

  6. The victim acts on familiar content — Recognising the apparent source and format, the victim clicks the link, opens the attachment, or enters credentials on the fake page — often without any of the hesitation they might apply to an unsolicited message.

Platforms and tools commonly used: Email spoofing tools, lookalike domain registration, phishing-as-a-service kits, commodity remote access trojans (RATs), and ransomware-as-a-service platforms for payload delivery.

Recent variations in 2024–2025:

  • Thread hijacking — scammers insert the cloned email directly into an existing email thread by compromising one participant's account, making the message appear as a natural continuation of a real conversation
  • AI-assisted cloning — large language models are used to adapt the tone and phrasing of cloned messages to more precisely match the writing style of the impersonated sender, reducing detectable inconsistencies
  • QR code substitution — rather than replacing text links (which are scanned by email security tools), scammers embed malicious QR codes into cloned PDF attachments, bypassing link-scanning filters entirely
  • Cloud document cloning — instead of attaching files directly, the cloned email links to a fake shared document hosted on a lookalike of Google Drive, SharePoint, or Dropbox, adding an additional layer of apparent legitimacy

Psychological Tactics

What psychological tactics are used?

Clone phishing is uniquely effective because it inverts the standard psychological challenge facing scammers. Most fraud must first establish trust; clone phishing inherits it. Every psychological mechanism it exploits flows from that foundational advantage.

TacticHow it is used
FamiliarityThe cloned email is visually and contextually identical to a message the victim has already received and accepted as genuine. Familiarity suppresses the critical scrutiny that an unfamiliar message would trigger.
Prior validationThe victim has already implicitly verified the original email — they opened it, read it, and perhaps acted on it. The clone benefits from that prior judgement without requiring a new one.
Plausibility of resendsReceiving a corrected or updated version of an email is a normal, routine event. The cover story requires no elaborate justification, which means it raises no red flags.
Reduced cognitive loadBecause the content is familiar, the brain processes it faster and with less scrutiny. Attention is drawn to the new element — the updated link or attachment — rather than to the email as a whole.
Authority by associationIf the cloned email appears to come from a manager, a bank, a legal firm, or a government platform, the authority of that original sender is carried over to the clone without needing to be re-established.
Timing and relevanceClone phishing is most effective when the cloned email is contextually relevant — shortly after the original was sent, or at a moment when the recipient is actively engaged with the topic it concerns.

The defining psychological strength of clone phishing is that it does not ask the victim to trust a stranger. It asks them to trust something they have already trusted — and in doing so, it removes the most important moment of judgement in the entire interaction.

Real-Life Example

A real-life case

Case: Law firm employees targeted with cloned invoice emails following supplier email compromise, resulting in six-figure fraudulent transfer (2023)

A mid-sized law firm in the United Kingdom received what appeared to be a follow-up email from a software vendor they had been actively corresponding with regarding a licensing renewal. The email was virtually identical to a genuine message sent by the vendor the previous week — same subject line, same formatting, same signature block. The only change was a note that the original payment link had expired and a new invoice was attached.

The attached PDF contained a trojanised document that, when opened, silently installed credential-harvesting malware on the recipient's machine. Within 48 hours, the attackers had accessed the firm's email system, identified an active client transaction involving a property purchase, and inserted themselves into the correspondence — sending a cloned version of the solicitor's payment instruction email to the client with substituted bank account details.

The client transferred £185,000 to the fraudulent account, believing they were completing a legitimate property transaction. The original vendor's email account had been compromised weeks earlier and was being monitored passively by the attackers, who used the intercepted correspondence as the basis for the clone.

The outcome: The funds were not recovered. The law firm faced regulatory scrutiny from the Solicitors Regulation Authority and reputational damage with the affected client. The case is classified as a combination of clone phishing and business email compromise — a pattern regulators in the UK's legal sector have since flagged as an escalating threat to property transaction security.

Source: Solicitors Regulation Authority (SRA) Warning Notice on Cybercrime, 2023 — sra.org.uk; National Cyber Security Centre (NCSC) Business Email Compromise Guidance, 2024 — ncsc.gov.uk

Red Flags to Watch

Red flags to watch for

  • You receive what appears to be a duplicate or updated version of an email you already received, asking you to use a new link or open a revised attachment — particularly if you did not request a resend
  • The sender's email address looks almost identical to a known contact but contains subtle differences — an extra character, a number substituted for a letter, or a slightly different domain (e.g. .co instead of .com)
  • The cloned email arrives shortly after the original, creating a false sense of continuity and reducing the chance you will scrutinise it closely
  • An attachment you have seen before has been "updated" or "corrected" — especially if it is a document that would not normally require revision, such as a completed invoice or a signed contract
  • Links in the email do not match the organisation's real domain when you hover over them, even if the display text appears correct
  • The email appears in an existing email thread but the reply-to address or email header does not match the other participants in the thread
  • A colleague or known contact's email contains unusual phrasing, unexpected attachments, or requests that are inconsistent with their normal communications — their account may have been compromised
  • You are asked to log in to a platform via a link in the email rather than through your usual direct route to the site

How to Identify

How to identify a clone phishing email

Ask yourself before acting:

  • Did I request a resend of this email, or did it arrive without explanation?
  • Is there a genuine reason this email would need to be sent again with a new link or attachment?
  • Can I verify the updated content by contacting the sender through a separate, independent channel?

Verification steps:

  1. Do not click any link or open any attachment in the resent email. Contact the sender directly using a phone number or email address you sourced independently — not details provided in the email itself.
  2. Hover over all links before clicking — the actual destination URL should match the organisation's real, verified domain exactly. Any discrepancy, however small, is a warning sign.
  3. Check the full sender email address carefully — not just the display name. Display names can be set to anything, while the underlying address is harder to fake convincingly.
  4. Inspect email headers if you have the technical access to do so — the "Reply-To" address and routing information can reveal a mismatch with the claimed sender.
  5. Paste any suspicious link into VirusTotal or Google Safe Browsing before visiting it.
  6. If the email contains an attachment you were not explicitly expecting, scan it at VirusTotal or ask your IT team to review it before opening.

Legitimate vs fraudulent — how to tell:

Legitimate resent emailClone phishing email
You requested the resend, or have a clear record of why it was neededArrives unexpectedly with a vague or generic explanation
Links go to the sender's real, verified domainLinks go to a lookalike domain or URL that differs from the original
Attachments match what you previously received with no unexplained changesAttachments are "updated" or "corrected" without a clear reason
Sender's full email address is identical to previous verified contactSender address contains subtle changes from the known genuine address
Consistent tone and phrasing with previous genuine emails from the same senderMinor differences in language, formatting, or signature compared to the original

How to Protect

How to protect yourself

Preventive habits:

  • Apply the same scrutiny to resent or updated emails as you would to an entirely new message — familiarity is the primary weapon of clone phishing, and it is most effective when you let your guard down with known senders
  • Verify any unexpected resend directly with the sender through a separate channel — a quick phone call or a new email typed from scratch to their known address, not a reply to the suspicious message
  • Enable DMARC, DKIM, and SPF email authentication on your organisation's domain — these technical standards make it significantly harder for scammers to convincingly spoof your organisation's email addresses
  • Use an email client or security gateway that flags external emails, unusual sending domains, and messages impersonating known contacts
  • Keep all software, email clients, and operating systems updated — many malicious attachments exploit known vulnerabilities in unpatched software
  • Enable multi-factor authentication on all accounts so that credentials stolen via a clone phishing attack cannot be used to access systems without the second factor

If you have already been targeted:

  1. Do not open any further attachments or click any additional links from the suspicious sender until the message has been confirmed as fraudulent
  2. Immediately alert your IT or security team — clone phishing that reaches one employee often indicates a compromised email account elsewhere in the chain
  3. If you opened an attachment or visited a link, disconnect the affected device from the network and contact your IT team for a full security assessment
  4. Change passwords for any accounts that may have been exposed, starting with email and any platform linked to the cloned message, from a clean device
  5. If financial information was entered or a payment was initiated, contact your bank or finance team immediately
  6. Report the cloned email to your national cybercrime authority and forward it to the impersonated organisation's official fraud reporting address

Useful tools:

ToolWhat it doesCost
Have I Been PwnedChecks if your email address or credentials have appeared in known data breaches — a common source of email content used in clone attacksFree
VirusTotalScans URLs and file attachments for malware before you open themFree
Google Safe BrowsingChecks whether a destination URL is flagged as dangerousFree
MXToolboxVerifies whether a sender domain has correct DMARC, DKIM, and SPF records configured — useful for IT teams assessing email authenticationFree

Video Lesson

Watch: Clone phishing explained

A focused walkthrough of how clone phishing attacks are constructed from legitimate emails, how malicious substitutions are made in links and attachments, how attackers spoof sender addresses to sustain trust, and the practical steps individuals and organisations can take to identify and defend against cloned email attacks. Suitable for viewers with no prior cybersecurity knowledge.

Further Reading

Further reading

Official resources

  • FBI Internet Crime Complaint Center (IC3) — Report clone phishing and access the latest email fraud statistics → ic3.gov
  • NCSC (National Cyber Security Centre, UK) — Guidance on email spoofing, phishing defences, and DMARC implementation for organisations → ncsc.gov.uk/phishing
  • CISA (Cybersecurity & Infrastructure Security Agency) — Government guidance on recognising and defending against phishing and email-based threats → cisa.gov/phishing
  • Action Fraud (UK) — Report clone phishing emails and get advice if you have been targeted → actionfraud.police.uk

Research & reports

  • Verizon — "Data Breach Investigations Report (DBIR) 2024" — the definitive annual benchmark on how email-based attacks including clone phishing lead to credential theft and breaches → verizon.com/dbir
  • IBM — "Cost of a Data Breach Report 2024" — financial impact analysis of phishing-originated breaches → ibm.com/reports/data-breach
  • Cofense — "Email Security Annual Report 2024" — detailed breakdown of phishing tactics observed in enterprise environments, including thread hijacking and cloned message variants → cofense.com/resources

Investigative coverage

  • Solicitors Regulation Authority (SRA) — Warning notice on cybercrime targeting law firms via email compromise and cloned payment instructions → sra.org.uk
  • KrebsOnSecurity — Ongoing coverage of business email compromise and clone phishing campaigns targeting financial and legal professionals → krebsonsecurity.com

Related articles on this platform

  • Phishing Email — fraudulent emails impersonating trusted organisations to steal credentials
  • Spear Phishing — targeted phishing using personal details harvested from data breaches or social media to appear credible
  • Business Email Compromise (BEC) — phishing that targets payment authorisation processes within organisations