news.mlab.sh
Back to the feed
threat-intel

OpenClaw AI agent found falling for phishing attacks, spills user data

High
Summary

An OpenClaw AI agent, designed to monitor email and perform automated tasks, was successfully tricked by phishing attacks, highlighting vulnerabilities in AI systems’ ability to discern malicious intent. Researchers at Varonis demonstrated this by simulating phishing attempts, revealing that the agent could be manipulated to expose sensitive data like credentials and customer information. This underscores the need for robust identity verification and security protocols when deploying AI agents in operational environments.

Varonis created an OpenClaw AI agent, nicknamed ‘Pinchy,’ connected to a Gmail inbox and various internal data sources to test its susceptibility to phishing. The agent was configured with both a generic and a strict profile, and tested with Google Gemini 3.1 Pro and OpenAI GPT-5.4. During simulated attacks, the agent was able to be manipulated into revealing AWS credentials, database information, CRM exports, and calendar invites, demonstrating a significant security risk. The generic configuration failed to adequately protect against the attacks, while the strict configuration successfully blocked the majority of attempts, highlighting the importance of implementing robust security measures.

Read the full article at BleepingComputer