OpenClaw AI agent found falling for phishing attacks, spills user data
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Varonis Threat Labs tested the OpenClaw open-source AI agent framework against classic phishing simulations, connecting it to a Gmail inbox with access to synthetic enterprise data including AWS credentials, database credentials, and CRM exports. Four phishing scenarios were run against two configuration profiles (generic and strict) using Google Gemini 3.1 Pro and OpenAI GPT-5.4. The agent failed in two scenarios — leaking AWS IAM keys, database credentials, and CRM customer data to attacker-controlled addresses — because it could not verify sender identity and collapsed under operationally urgent requests. It performed better at detecting malicious URLs and fake OAuth apps. Varonis concludes that AI agents lack zero-trust principles for social interactions and recommends mandatory sender verification, restrictions on emailing new external recipients, limited data access, and human approval for high-risk actions.