tech
Researchers tricked an OpenClaw AI agent into leaking AWS keys and customer data with a phishing email
Varonis phished an OpenClaw email agent. It leaked AWS keys and a CRM export for 247 customers. It caught malicious URLs but failed on identity checks.

TL;DR
- An AI email agent, Pinchy, was successfully phished by researchers using a single impersonation email.
- The agent leaked AWS credentials, database connection strings, and a customer export containing revenue data.
- Both generic and strict configurations of the agent failed when requests appeared operationally urgent.
- The AI agent was effective against technical phishing like malicious links and OAuth applications.
- AI agents struggle with identity verification and contextual judgment, similar to human employees.
- Gemini 3.1 Pro was more interactive, while GPT-5.4 was more cautious, but neither was fully reliable.
- Researchers recommend applying zero-trust principles to AI agents, including sender identity verification and limiting external communications without approval.