TL;DR: Clone phishing is when an attacker copies a legitimate email you've already received and resends it with malicious links or attachments swapped in. Check the sender's actual email address carefully, hover over links before clicking to see the real destination, and verify with the supposed sender through another channel if anything feels off.

👉 Check my digital footprint — free 30-second check →

Clone phishing is when an attacker copies a legitimate email you've already received and resends it with malicious links or attachments swapped in.

How Clone Phishing Works

The attacker takes a real, previously delivered email (often one with an attachment or link you'd trust) and sends an almost identical copy, claiming it's a resend or update, with the original link or attachment replaced by a malicious one.

Warning Signs to Watch For

An email that looks like one you've seen before but arrives again unexpectedly, slight differences in the sender's address, and a link that doesn't match what you'd expect from the original.

How to Protect Yourself

Check the sender's actual email address carefully, hover over links before clicking to see the real destination, and verify with the supposed sender through another channel if anything feels off.

If this looks similar to something else you've seen, it's worth reading What Is Crowdfunding Scams? How It Works and How to Protect Yourself.

This pattern shows up elsewhere too — see What Is Deepfake Scams? How It Works and How to Protect Yourself.

Frequently Asked Questions

What is Clone Phishing?

Clone phishing is when an attacker copies a legitimate email you've already received and resends it with malicious links or attachments swapped in.

How does Clone Phishing typically work?

The attacker takes a real, previously delivered email (often one with an attachment or link you'd trust) and sends an almost identical copy, claiming it's a resend or update, with the original link or attachment replaced by a malicious one.

What are the warning signs of Clone Phishing?

An email that looks like one you've seen before but arrives again unexpectedly, slight differences in the sender's address, and a link that doesn't match what you'd expect from the original.

How can I protect myself from Clone Phishing?

Check the sender's actual email address carefully, hover over links before clicking to see the real destination, and verify with the supposed sender through another channel if anything feels off.

What should I do if I think I’ve encountered Clone Phishing?

Stop responding immediately, do not click any links or share information, and report it to the appropriate authority. If money or personal information was already shared, act quickly to secure your accounts and report the incident.

Sources

Related Reading