Clone phishing: when a real email comes back poisoned
Clone phishing is one of the sneakier variants because it weaponises something you already trust: a real email. The attacker copies a legitimate message you have seen before, swaps the link or attachment for a malicious one, and resends it under a plausible excuse. Familiarity does the rest.
How the trick works
- Copy — an attacker replicates a genuine email: the wording, logo, signature and layout.
- Swap — the original link or attachment is replaced with a malicious one.
- Pretext — it arrives as a "resend," "updated invoice," or "corrected link," explaining the repeat.
- Trust — because you recognise the message, you are far more likely to click.
Why it beats normal caution
Most phishing advice is about spotting the unfamiliar. Clone phishing inverts that: the message is familiar, which is exactly why it slips through. If the original came from a trusted brand, the clone inherits that trust — and the swapped link often leads to a cloaked page that looks clean to scanners.
Clone phishing turns your own trusted correspondence into the lure. The one thing that changed — the link — is the one thing to verify.
How to defend
- Authenticate your domain (SPF, DKIM, DMARC) so attackers struggle to send clones as you.
- Be wary of "resend/updated" messages, especially ones that add urgency.
- Verify links out of band before acting on a repeat of something you already handled.
- Take down the destination — the swapped link points to a page you can get removed.
Phish Plug targets the pages behind clone-phishing links — the cloaked clones and lookalike domains — capturing evidence and filing takedowns so the swapped link stops working.
The takeaway
Clone phishing succeeds by copying what you already trust and changing only the payload. Authenticate your domain so your messages are hard to clone, treat "resends" with a healthy pause, and remove the pages the malicious links lead to.
Keep reading
Related articles
QR code phishing (quishing): the scan-and-steal scam
A QR code hides its destination until you scan it. How quishing abuses that trust, where fake codes appear, and how to defend your brand and customers.
Read article Threats · 7 minPharming: when the right address sends you to a fake site
Pharming poisons the path between a correct address and the real server. How DNS-based redirection works, why it is hard to spot, and how to reduce the risk.
Read article Threats · 7 minMalvertising: fake ads that impersonate your brand
Attackers buy ads on your own brand terms to outrank you and send customers to clones. How malvertising works and how to detect and take it down.
Read articleRemove the clones targeting your brand
Run a free clone check on one domain — Phish Plug proves the cloaking and files the takedown.