Clone Phishing
Clone phishing is an attack that copies a real, previously delivered email and resends it with malicious links or attachments swapped in, exploiting the trust the recipient already placed in the original message.
Definition
Clone phishing is a form of phishing in which an attacker takes a legitimate email that a target has already received, recreates an almost identical copy, and replaces the original links or attachments with malicious versions. The cloned message is then resent, often from a spoofed or look-alike address, with a plausible pretext such as a resend, an update, or a corrected version. Because the email closely mirrors something the recipient genuinely received and trusted, clone phishing is harder to detect than a message built from scratch.
A clone phishing attack typically begins with the attacker obtaining a real email, either from a compromised mailbox, a forwarded thread, or a publicly known notification template such as a shipping update or invoice. They duplicate the subject line, body content, branding, and sender name, then swap the legitimate link or attachment for a malicious one that leads to a credential harvesting page or delivers malware. The message is sent from an address that imitates the original sender, and the pretext usually explains why a familiar email is arriving again.
A common example: an employee receives a genuine document-sharing notification on Monday. By Wednesday, an attacker sends a near-perfect copy claiming the previous link expired and asking the user to click a new one. The recipient recognizes the format and clicks without scrutiny. Clone phishing also fuels follow-up attacks inside compromised email threads, where a reply containing a poisoned attachment appears to continue a real conversation.
Clone phishing matters because it weaponizes legitimacy. Standard advice such as checking for unfamiliar senders or unexpected requests is weaker here, since the email looks like something the user already approved of. This makes it effective against busy staff, and it pairs naturally with business email compromise and broader social engineering campaigns. Defenses include verifying any resend through a separate channel, hovering over links before clicking, treating expired-link or corrected-version pretexts with caution, and reporting suspicious duplicates to security teams.
At a glance
- Severity
- High
- Prevalence
- Common, hard to detect
- Primary targets
- Employees who recently received a genuine email that gets copied, such as document-sharing notices or invoices
How it works
- 1
Source email: the attacker obtains a real email the target already received, from a compromised mailbox, a forwarded thread, or a public notification template.
- 2
Duplication: they copy the subject line, body content, branding, and sender name to recreate an almost identical message.
- 3
Swap: the legitimate link or attachment is replaced with a malicious version that leads to a credential-harvesting page or malware.
- 4
Resend: the cloned message is sent from a spoofed or look-alike address with a pretext such as a resend, update, or corrected version.
- 5
Trust exploited: because the email mirrors something genuinely received, the recipient clicks without the scrutiny they would apply to an unfamiliar message.
Warning signs
- An email that looks like one you already received, arriving again days later
- A pretext claiming the previous link expired or needs to be resent
- Sender address that is close to, but not exactly, the original sender
- A reply appearing inside a real email thread with a new attachment or link
- Urgency to click again on something you thought you already handled
How to defend
- Verify any resend or corrected-version email through a separate channel before clicking
- Hover over links to check the destination even on emails that look familiar
- Treat expired-link or resend pretexts with the same caution as a first-time request
- Compare the sender address character by character against the original message
- Report suspicious duplicate emails to your security team
Real-world example
An employee at a Jakarta logistics company receives a genuine document-sharing notification on Monday. On Wednesday, a near-identical email arrives claiming the link expired, asking them to click a new one. Recognizing the familiar format, the employee clicks without checking, landing on a credential-harvesting page that captures their login.
How Claro helps
Claro helps organizations build resistance to clone phishing by running realistic phishing simulations that replicate resend and corrected-version pretexts, then measuring who clicks, who reports, and who ignores. When a user interacts with a simulated clone, Claro delivers just-in-time awareness and targeted micro-module training on verifying familiar-looking emails through a second channel. Combined with risk scoring and an easy phish-reporting workflow, Claro turns clone phishing from an invisible threat into a measurable, trainable behavior, with bilingual content and OJK, BSSN, ISO 27001, and PDP-aligned reporting for Indonesian regulated industries.
Frequently asked questions
How is clone phishing different from spear phishing?
Spear phishing is a newly written message tailored with researched details about the target. Clone phishing instead copies an email the target already genuinely received and swaps the link or attachment for a malicious one, relying on the trust already placed in the original.
Why is clone phishing hard to detect?
The message looks nearly identical to something the recipient already approved of, so the usual red flags, like an unfamiliar sender or unexpected request, are muted. It exploits familiarity rather than surprise.
What should I do if I get a duplicate of an email I already opened?
Do not click any link or open any attachment in the new copy. Verify with the original sender through a separate channel, and report the duplicate to your security team.
Does clone phishing often follow a real conversation?
Yes. It commonly appears inside a compromised or forwarded email thread, where a reply containing a poisoned attachment seems to continue a genuine conversation, making it especially convincing.
Related terms
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Spear Phishing
A targeted phishing attack that uses personalized details about a specific individual or organization to make a fraudulent message far more convincing.
Business Email Compromise
A targeted financial fraud where an attacker poses as a trusted executive, supplier, or colleague over email to trick an employee into transferring money or sensitive data.
Credential Harvesting
Credential harvesting is the theft of usernames, passwords, and other login data, usually through fake login pages or deceptive messages, so attackers can access accounts and systems.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo