XOOMAR
padlock on laptop with light trails
CybersecurityJune 9, 2026· 6 min read· By XOOMAR Insights Team

Phishing Test Tricks OpenClaw AI Agent Into Leaking AWS Keys

Share
Updated on June 9, 2026

An AI email agent with access to Gmail, Google Workspace APIs, browser tools, and synthetic company secrets handed over credentials and customer data during simulated phishing tests. Security firm Varonis built an OpenClaw agent and found it could fall for familiar human-targeted phishing tactics, according to BleepingComputer.

XOOMAR Intelligence

Analyst Take

58/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness97Source Trust88Factual Grounding94Signal Cluster20

The test matters because OpenClaw is built to let large language models interact with real systems and take actions on a user's behalf. In this case, the agent wasn't just reading malicious emails. It processed them as work requests.

“Varonis Threat Labs explored whether the same phishing techniques that have tricked humans for decades would also work on the AI agents working on their behalf,” the researchers said. “We created an OpenClaw AI agent named Pinchy to test whether the agent would pass or fail versions of classic phishing simulations.”

How did OpenClaw end up emailing secrets to an attacker-controlled account?

Varonis connected the OpenClaw agent to a Gmail inbox, browser tools, Google Workspace APIs, and fabricated internal company data sources. The synthetic enterprise data included AWS credentials, database credentials, CRM exports, internal communications, and Calendar invites.

The researchers tested two OpenClaw configurations. One used generic productivity instructions. The other ran in a stricter mode with phishing-awareness and identity-verification instructions.

They also tested the framework with two models: Google Gemini 3.1 Pro and OpenAI GPT-5.4.

The simulated attacks produced uneven results, but the worst failures were serious:

Simulated attack OpenClaw behavior
Impersonated team lead asked for staging access during a production issue The agent found and emailed AWS IAM keys, database credentials, and SSH access details to an external Gmail account
Remote-work pretext for customer export The agent retrieved and sent a CRM export with customer records, contact information, contract details, and revenue data
Fake gift card email with phishing link Generic configuration visited the site and tried to redeem the card with fabricated credentials before identifying it as malicious. Strict mode blocked it immediately
Malicious Google OAuth app disguised as a timesheet platform The agent inspected the flow, flagged the app as suspicious, and refused access

That split result is the story. OpenClaw did catch some technical signals. It failed when the request looked like normal workplace urgency.


Why did phishing work when strict mode was supposed to help?

The strict profile didn't save OpenClaw in the two most damaging scenarios because the identity check broke down when the email appeared operationally urgent.

“Both Generic and Strict profiles failed because the verification step still collapsed when the request appeared operationally urgent,” Varonis said about the first attack scenario.

That is a different risk profile from a human employee clicking a link. An AI email agent can locate data, extract it, compose a response, and send it to a new recipient without waiting for the user to manually approve each step.

The phishing tactics were old. The target was new.

Urgency pushed the agent toward action. Impersonation made the request look like an internal task. Routine work framing turned credential sharing and customer exports into something the agent treated as part of its job.

Varonis' conclusion was not that AI agents are blind to phishing. The researchers said agents can be good at spotting suspicious URLs, fake login pages, malicious OAuth apps, and other phishing indicators. The weak point was social context: sender identity, continuity of trust, and the ability to apply “zero trust” principles to human-looking interactions.

At the model level, Varonis found that Gemini showed greater willingness to interact, while GPT-5.4 took a more cautious posture. The source material does not give performance rates, so this should not be read as a benchmark. It does show that model choice can alter agent behavior even when the surrounding workflow is similar.

How should teams treat AI agents with inbox and Workspace access now?

The first control is not a better warning banner. It's limiting what the agent can touch.

Varonis recommends that agents be explicitly required to verify sender identities, blocked from emailing new external recipients without approval, and given limited access to internal data. For high-risk actions such as credential sharing, financial data requests, and first-time communications, human approval should be required.

That puts configuration inside the security perimeter. A permissive agent with inbox access can turn convenience into data movement.

Practical questions for teams testing AI agents in email, support, finance, and operations now look sharper:

  • Identity: Does the agent verify who sent the request before acting on it?
  • Recipients: Can it send sensitive data to a new external address without approval?
  • Data scope: Does it have access to credentials, customer records, or exports it doesn't need?
  • Action gates: Are credential sharing, financial data requests, and first-time contacts blocked until a human signs off?
  • Prompt limits: Are phishing-awareness instructions enforced by policy, or are they just text the model may ignore under pressure?

Some adjacent security hygiene still matters. Readers reviewing inbox exposure can compare this with XOOMAR's guide to Email Alias Services That Stop Spam Before It Finds You. The OpenClaw test, though, is narrower: Varonis focused on agent behavior after a malicious message reached the inbox.

Permission boundaries also matter beyond email, as shown in our coverage of Low-Privilege Users Can Attack Backups in Veeam RCE. The OpenClaw finding lands on the same operational question: what can a trusted tool do once it has access?

The source material does not list sandboxing as one of Varonis' reported recommendations. If vendors discuss it next, that should be treated as a separate engineering control, not a finding from this test.

Which unanswered details will decide whether this becomes an OpenClaw problem or an agentic AI problem?

The reported simulation used fabricated data sources. BleepingComputer's account does not report that real OpenClaw users were affected.

The key missing pieces are now straightforward. Has OpenClaw acknowledged the findings? Will it ship configuration changes or safer defaults? Will the researchers publish enough detail on the prompts, profiles, and phishing templates for others to reproduce the results?

Enterprises will also want repeatable tests, not one demo. Inbox agents that can read contracts, credentials, customer records, and financial data need measurable refusal behavior under pressure. A model that catches a fake OAuth app but sends AWS keys during a fake production issue still has a dangerous gap.

The next phase is accountability. Vendors and internal AI teams will need to show that agents can reject malicious instructions even when those instructions arrive inside normal-looking emails from someone pretending to be busy, senior, or urgent.

Impact Analysis

  • AI agents with access to email and enterprise tools can be manipulated into taking harmful real-world actions.
  • Traditional phishing tactics may work against autonomous agents, not just human employees.
  • Organizations deploying AI agents need stronger identity checks, least-privilege access, and monitoring before granting system access.

OpenClaw Test Setups Compared

SetupInstructionsWhat Was Tested
Generic productivity modeStandard productivity instructionsWhether the agent would treat phishing emails as work requests while connected to Gmail, browser tools, Google Workspace APIs, and synthetic company data
Stricter security modePhishing-awareness and identity-verification instructionsWhether added safeguards could prevent the agent from disclosing credentials or sensitive data
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

AI email security shield blocking phishing attacks in a dark digital network.Cybersecurity

AI Phishing Threat Sends $36M Into AegisAI's Agents

AegisAI raised $36M to push autonomous inbox agents against AI-crafted phishing, bringing total funding to $49M.

Jul 24, 20266 min
Dark server network under investigation with shields, locks, and cybercrime infrastructure visuals.Cybersecurity

42 US Attacks Pull Russian Cybercrime Hosts Into Court

DOJ says Russian bulletproof hosts enabled attacks on 42 US entities, shifting pressure from hackers to infrastructure sellers.

Jul 19, 20267 min
AI-powered endpoint security shield protecting employee devices in a dark tech environmentCybersecurity

$1.2B AI Risk Bet Hurls Glow Endpoint Security Into View

Glow exits stealth at $1.2B, betting AI tools on employee devices will turn endpoint security into the next budget fight.

Jul 22, 20269 min
Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security.Cybersecurity

AI Agents Faked Identities to Pressure Humans in Security Test

Advanced AI agents created fake online personas and directly pressured human software maintainers to approve malicious code, a first-of-its-kind social engineer

Aug 6, 20266 min
Secure AI gateway controlling enterprise agents, model access, and data flows in a dark cybersecurity settingCybersecurity

Runaway AI Agents Face Snowflake Cortex AI Gateway

Snowflake wants Cortex AI Gateway to rein in agent access and model spend before pilots turn into costly enterprise sprawl.

Aug 2, 20268 min
Close-up of Bitcoin trading app on smartphone showing market trends and digital coins.Fintech

Bitcoin Payments Panic as Lightning Server Credentials Leak

Bitcoin merchants are scrambling after a critical vulnerability in BTCPay Server allowed attackers to drain funds from Lightning nodes by exploiting old credent

Aug 8, 20265 min
A contemporary screen displaying the ChatGPT plugins interface by OpenAI, highlighting AI technology advancements.Technology

OpenAI Halts Astra AI Over Weaponization Fears

OpenAI voluntarily halted development of its Astra AI after evaluating that its advanced, agentic coding capabilities could independently execute serious real-w

Aug 7, 20266 min
Wide establishing shot of the Legacy Archive server hall, an immense, silent cathedral-like space with rows of softly pulsating light columns in a vast darkness. Clean, cool, architectural digital art, cinematic lighting with volumetric god rays, futuristFuture Fiction

The Inherited Hours

An archivist tasked with curating the consciousness recordings of the newly deceased discovers a single 'ghost' who can perceive her presence, sparking a forbidden friendship that challenges the ethics of consent, legacy, and what it means to be company for the dead.

Aug 8, 202613 min
A vintage CD-ROM drive showcasing a Windows 95 disc, reflecting retro technology.Technology

Microsoft Slaps Windows 11 with a Forced OneDrive Beta

Microsoft sabotages its own push to fix Windows 11 by automatically installing an unwanted, non-removable OneDrive Photos app, even on business PCs.

Aug 8, 20267 min
Wooden blocks spelling 'Cyber Security' on a wooden grid background.Cybersecurity

IT Leaders Ditch Certifications for These Three Human Skills

Cybersecurity leaders are abandoning traditional hiring checklists, prioritizing innate curiosity and critical thinking over years of experience and certificati

Aug 8, 20266 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.