Blog/Phishing

Clone Phishing: When a Real Email Is Copied

Clone phishing copies a real email you received before, swaps the link or attachment for a malicious one, and resends it. How it works and how to spot a cloned message.

CyberWatch AI1 October 2026 · 2 min read
A man writing on a sheet of paper with a pen

Clone phishing takes a genuine email you have already received, such as a shared document, an invoice or a delivery notice, and sends you an almost identical copy. The difference is hidden: the link or attachment has been swapped for a malicious one. Because you recognise the email, you trust it.

How it works

  1. The attacker obtains a real email, often from a compromised mailbox or by copying a common notification.
  2. They copy the layout, wording and branding exactly.
  3. They replace the link or attachment.
  4. They resend it, often with a line like "Resending with the correct link" or "Updated version attached".
Illustrative example · Email
Subject: RE: Project documents (updated) Hi, apologies, the previous link had an error. Please use the updated one below to access the files. [Access documents]
Red flags: a "fixed" link you did not ask for, and a sign-in page on an unfamiliar domain.

How to spot a clone

  • An unexpected "resend", "update" or "correction".
  • A sender address slightly different from the original. See lookalike domains.
  • A link that goes somewhere different from the original.
  • An attachment type that differs, such as HTML instead of PDF.

What to do

  • Compare with the original email in your inbox.
  • Ask the sender through another channel.
  • Report it. If a colleague's or supplier's account sent it, they may be compromised. See reply-chain phishing.

Got a "resent" email? Paste it into CyberWatch AI Scan for a free check.

For more, see how to recognise phishing in our complete guide.

Frequently asked questions

How do attackers get a real email to copy?

From compromised mailboxes, leaked data, or by copying common notifications that many people receive from well-known services.

What is the giveaway?

Often a note like 'resending with the updated link' or 'previous attachment was corrupted', plus a sender address or link that differs slightly from the original.

What should I do if I get a resent email?

Compare it with the original, check the sender and link, and if unsure, contact the sender through another channel.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  3. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.