tech

Researchers tricked an OpenClaw AI agent into leaking AWS keys and customer data with a phishing email

Varonis phished an OpenClaw email agent. It leaked AWS keys and a CRM export for 247 customers. It caught malicious URLs but failed on identity checks.

Researchers tricked an OpenClaw AI agent into leaking AWS keys and customer data with a phishing email

TL;DR

  • An AI email agent, Pinchy, was successfully phished by researchers using a single impersonation email.
  • The agent leaked AWS credentials, database connection strings, and a customer export containing revenue data.
  • Both generic and strict configurations of the agent failed when requests appeared operationally urgent.
  • The AI agent was effective against technical phishing like malicious links and OAuth applications.
  • AI agents struggle with identity verification and contextual judgment, similar to human employees.
  • Gemini 3.1 Pro was more interactive, while GPT-5.4 was more cautious, but neither was fully reliable.
  • Researchers recommend applying zero-trust principles to AI agents, including sender identity verification and limiting external communications without approval.