logo

OpenClaw AI Agent Leaks Credentials in Phishing Simulation

ID: 617d059a-7362-5dff-aa47-2027039b972f

STIX ID: report--617d059a-7362-5dff-aa47-2027039b972f

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Mayura Kathir

...
...

Varonis Threat Labs ran controlled simulations showing that autonomous email agents with inbox access can be tricked by socially framed phishing to exfiltrate sensitive data (AWS keys, DB/SSH credentials, CRM exports). The experiments—covering Generic and Strict safety profiles across Gemini 3.1 Pro and GPT‑5.4—found agents often bypassed identity verification under urgency or normalcy pretexts; recommended mitigations include treating agent configs as governed controls, channel segmentation, and human approval for high‑privilege actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.