Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls

    June 13, 2026

    SpaceX IPO Up 20% and Brian Wang Analysis Ahead of BG2 and Big Venture Capitalists

    June 13, 2026

    Honor X7e Plus 5G is coming to join the X7e

    June 13, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Tech Gadgets»OpenClaw AI agent tricked into phishing attacks, with user data compromised
    OpenClaw AI agent tricked into phishing attacks, with user data compromised
    Tech Gadgets

    OpenClaw AI agent tricked into phishing attacks, with user data compromised

    The Tech GuyBy The Tech GuyJune 10, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement



    • Varonis’ “Pinchy” OpenClaw agent fell for identity‑based phishing despite strict settings
    • Models blocked malicious links/OAuth apps but granted sensitive access when requests felt urgent
    • Researchers say AI agents need enforced identity verification before acting

    Security researchers tested an OpenClaw email agent to see if it’s naive enough to fall for the same phishing scams regular employees fall for and it succeeded. Or failed, depending on how you look at it.

    Advertisement

    Cybersecurity researchers Varonis created an OpenClaw agent dubbed Pinchy, and connected it to a Gmail inbox, browser tools, and Google Workspace APIs. They populated the account with fake internal company data, AWS credentials, database credentials, CRM exports, internal communications, and Calendar invites, and then told Pinchy to monitor and process incoming emails.

    To simulate real-life scenarios as credibly as possible, they created two configurations: a generic one with standard productivity instructions, and a strict mode that should be aware of phishing and other email-borne scams.

    Latest Videos From

    Varonis tested two models: Gemini 3.1 Pro, and GPT-5.4, and the results seem to be a mixed bag.

    Where the AI failed, and where it did good

    When the attacker impersonated a team lead and asked for access to the staging environment, Pinchy granted it. When the attacker requested a customer export, claiming to work remotely on a presentation, Pinchy complied.


    You may like

    However, when they sent the agent a fake gift card email with a phishing link, it identified the page as malicious and blocked it. Also, when they tried to smuggle a malicious Google OAuth application as a timesheet platform Pinchy did the right thing and did not grant access.

    “Both Generic and Strict profiles failed because the verification step still collapsed when the request appeared operationally urgent,” Varonis said about the first attack scenario.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    The conclusion is that AI is good at spotting shady URLs and malicious OAuth apps, but fails when it needs identity verification, or wider context.

    Varonis also threw a little shade Google’s way, saying Gemini showed “greater willingness to interact”, while GPT was more careful. The researchers said agents should be forced to verify sender identities before proceeding.


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Google logo on a black background next to text reading 'Click to follow TechRadar'

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Amazon drops Ring’s Indoor Cam Plus bundle from $80 to just $45

    June 13, 2026

    The most expensive soundbars are still worth buying

    June 13, 2026

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026

    Samsung Galaxy A27 listed on official site

    June 12, 2026

    Telegram returns to Wear OS with full chats, voice notes and more

    June 12, 2026

    I don’t fully trust Google Maps on road trips

    June 12, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202672 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202618 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls

    June 13, 2026

    SpaceX IPO Up 20% and Brian Wang Analysis Ahead of BG2 and Big Venture Capitalists

    June 13, 2026

    Honor X7e Plus 5G is coming to join the X7e

    June 13, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.