Clone Phishing: When a Real Email Is Copied
Clone phishing copies a real email you received before, swaps the link or attachment for a malicious one, and resends it. How it works and how to spot a cloned message.

Clone phishing takes a genuine email you have already received, such as a shared document, an invoice or a delivery notice, and sends you an almost identical copy. The difference is hidden: the link or attachment has been swapped for a malicious one. Because you recognise the email, you trust it.
How it works
- The attacker obtains a real email, often from a compromised mailbox or by copying a common notification.
- They copy the layout, wording and branding exactly.
- They replace the link or attachment.
- They resend it, often with a line like "Resending with the correct link" or "Updated version attached".
How to spot a clone
- An unexpected "resend", "update" or "correction".
- A sender address slightly different from the original. See lookalike domains.
- A link that goes somewhere different from the original.
- An attachment type that differs, such as HTML instead of PDF.
What to do
- Compare with the original email in your inbox.
- Ask the sender through another channel.
- Report it. If a colleague's or supplier's account sent it, they may be compromised. See reply-chain phishing.
Got a "resent" email? Paste it into CyberWatch AI Scan for a free check.
For more, see how to recognise phishing in our complete guide.
Frequently asked questions
How do attackers get a real email to copy?
From compromised mailboxes, leaked data, or by copying common notifications that many people receive from well-known services.
What is the giveaway?
Often a note like 'resending with the updated link' or 'previous attachment was corrupted', plus a sender address or link that differs slightly from the original.
What should I do if I get a resent email?
Compare it with the original, check the sender and link, and if unsure, contact the sender through another channel.
Sources
- Suspicious email actions, UK National Cyber Security Centre
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre


