OpenClaw AI agent tricked into phishing attacks, with user data compromised



  • Varonis’ “Pinchy” OpenClaw agent fell for identity‑based phishing despite strict settings
  • Models blocked malicious links/OAuth apps but granted sensitive access when requests felt urgent
  • Researchers say AI agents need enforced identity verification before acting

Security researchers tested an OpenClaw email agent to see if it’s naive enough to fall for the same phishing scams regular employees fall for and it succeeded. Or failed, depending on how you look at it.

Cybersecurity researchers Varonis created an OpenClaw agent dubbed Pinchy, and connected it to a Gmail inbox, browser tools, and Google Workspace APIs. They populated the account with fake internal company data, AWS credentials, database credentials, CRM exports, internal communications, and Calendar invites, and then told Pinchy to monitor and process incoming emails.

https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img