Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    If the AI Industry Followed Its Own Research, It Might Have Paused Already

    September 19, 2026

    Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute

    September 19, 2026

    Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute
    • Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery
    • Here’s How an AI Slowdown Could Actually Be Enforced
    • Could AI really kill us all? Your questions, answered.
    • Turning Tech Talent Into Leadership Legacy
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • The Download: AI’s extinction risk and bioweapons threat
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Gadgets»OpenClaw AI agent tricked into phishing attacks, with user data compromised
    Gadgets

    OpenClaw AI agent tricked into phishing attacks, with user data compromised

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 10, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    OpenClaw AI agent tricked into phishing attacks, with user data compromised
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • Varonis’ “Pinchy” OpenClaw agent fell for identity‑based phishing despite strict settings
    • Models blocked malicious links/OAuth apps but granted sensitive access when requests felt urgent
    • Researchers say AI agents need enforced identity verification before acting

    Security researchers tested an OpenClaw email agent to see if it’s naive enough to fall for the same phishing scams regular employees fall for and it succeeded. Or failed, depending on how you look at it.

    Cybersecurity researchers Varonis created an OpenClaw agent dubbed Pinchy, and connected it to a Gmail inbox, browser tools, and Google Workspace APIs. They populated the account with fake internal company data, AWS credentials, database credentials, CRM exports, internal communications, and Calendar invites, and then told Pinchy to monitor and process incoming emails.

    To simulate real-life scenarios as credibly as possible, they created two configurations: a generic one with standard productivity instructions, and a strict mode that should be aware of phishing and other email-borne scams.

    Latest Videos From

    Varonis tested two models: Gemini 3.1 Pro, and GPT-5.4, and the results seem to be a mixed bag.

    Where the AI failed, and where it did good

    When the attacker impersonated a team lead and asked for access to the staging environment, Pinchy granted it. When the attacker requested a customer export, claiming to work remotely on a presentation, Pinchy complied.


    You may like

    However, when they sent the agent a fake gift card email with a phishing link, it identified the page as malicious and blocked it. Also, when they tried to smuggle a malicious Google OAuth application as a timesheet platform Pinchy did the right thing and did not grant access.

    “Both Generic and Strict profiles failed because the verification step still collapsed when the request appeared operationally urgent,” Varonis said about the first attack scenario.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    The conclusion is that AI is good at spotting shady URLs and malicious OAuth apps, but fails when it needs identity verification, or wider context.

    Varonis also threw a little shade Google’s way, saying Gemini showed “greater willingness to interact”, while GPT was more careful. The researchers said agents should be forced to verify sender identities before proceeding.

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

    Agent Attacks compromised data OpenClaw Phishing tricked user
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid

    September 16, 2026

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Meta Sued Over Training Data for Its AI and Face-Recognition Systems

    September 11, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute
    • Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery
    • Here’s How an AI Slowdown Could Actually Be Enforced
    • Could AI really kill us all? Your questions, answered.

    If the AI Industry Followed Its Own Research, It Might Have Paused Already

    September 19, 2026

    Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute

    September 19, 2026

    Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery

    September 18, 2026

    Here’s How an AI Slowdown Could Actually Be Enforced

    September 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.