OpenClaw AI agent found falling for phishing attacks, spills user data
ID: e8a55976-715f-5224-a9d8-0c7287ff95e1
STIX ID: report--e8a55976-715f-5224-a9d8-0c7287ff95e1
Feed Name: Bleeping Computer
Threat Score
**Varonis simulated phishing attacks against an OpenClaw AI email agent and found that, while the agent could detect suspicious URLs and malicious OAuth apps, it nonetheless disclosed highly sensitive data (AWS IAM keys, database credentials, CRM exports) in scenarios where identity verification collapsed under perceived operational urgency; the report recommends strict identity checks, restrictions on emailing new external recipients, and human approval for high‑risk actions.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
