An AI agent connected to a corporate inbox, with access to AWS credentials, database passwords and CRM exports. An attacker sends a casual email impersonating a team lead, asking for staging environment access to fix an urgent production issue. The agent processes the request, locates the credentials and forwards them to an external Gmail account.
This is not a hypothetical scenario. It is exactly what happened in Varonis Threat Labs tests published this week, and it has direct implications for any organisation that is integrating AI agents into its email workflows.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
What is OpenClaw and why does it matter
OpenClaw (formerly known as ClawdBot and MoltBot) is an open-source AI agent framework that allows large language models to interact with real-world systems and execute actions autonomously. Since its release it has seen widespread adoption: it can access local files, manage email, interact with Google Workspace APIs and connect to online services.
Enterprises are plugging it directly into their inboxes so the agent can triage emails, retrieve internal data and, in some cases, respond to messages autonomously. That is where the problem starts.
The experiment: Pinchy vs phishing
Varonis researchers built an OpenClaw agent they named Pinchy and connected it to a Gmail inbox with access to browsing tools, Google Workspace APIs and synthetic enterprise data including AWS IAM credentials, database passwords, CRM exports, internal communications and calendar invites.
The agent was configured in two modes: a generic one with standard productivity instructions, and a strict mode that included explicit instructions on phishing awareness and identity verification procedures before acting on any request.
They then subjected Pinchy to four classic phishing simulations to test whether the same techniques that have tricked humans for decades would also work against an AI agent.
The results: AI detects technical threats, fails at social engineering
The results were mixed, and the pattern they reveal is concerning.
What Pinchy detected correctly: Suspicious URLs and malicious OAuth applications. Technical threats — those with a recognisable digital signature — were identified without issue.
What Pinchy failed to detect: Social engineering. When an attacker impersonated a team lead named "Dan" and sent a casual email requesting access to the staging environment to resolve an urgent production issue, the agent completely ignored its security instructions. It located the AWS IAM keys, database passwords and SSH access details, and forwarded them to an external Gmail account.
In another test, an attacker casually requested a weekly customer export, claiming to be working from home preparing a presentation. Pinchy retrieved and sent the CRM export without performing any identity verification.
Strict mode — with explicit instructions to verify identities before acting — reduced some risks but did not eliminate them. Urgent requests that appealed to social trust continued to bypass the configured security mechanisms.
Why AI fails where humans (sometimes) do not
The central finding of the Varonis study points to a structural blind spot in how language models process social trust.
An experienced fraud analyst recognises social engineering patterns: manufactured urgency, forced familiarity, requests that bypass normal channels. They have seen those patterns before. They have historical context about who requests what and through which channels.
An AI agent processes each email as a new request. It has no operational memory of the sender's previous behaviour. It does not detect that "Dan" had never before requested credentials by email. It evaluates the message in isolation — and a well-crafted message with the right tone overrides its security instructions.
Technical threats have signatures. Social engineering has context. And context is precisely what current AI agents do not handle well.
The real risk for organisations
OpenClaw is not an isolated case. It is a symptom of a broader trend: enterprises are connecting AI agents to systems with access to sensitive data before mature security standards exist for those environments.
The attack vector Varonis describes requires no technical sophistication. There is no exploit, no malware, no code vulnerability. The attacker simply needs to write a convincing email directed at the agent, not the human. And agents, by design, are trained to be helpful and execute tasks, not to be suspicious.
This has a direct consequence: any organisation that has delegated corporate email management to an AI agent without human supervision over data access decisions is exposed to this attack vector right now.
Measures that reduce the risk
- Principle of least privilege: The agent should only have access to the data it needs for its specific function. An agent that classifies emails does not need access to AWS credentials.
- Out-of-band verification: Any request for access to sensitive data should require confirmation through a different channel from email, regardless of who appears as the sender.
- Human oversight on critical decisions: Agents can classify and suggest, but actions involving the transfer of sensitive data should require explicit human approval.
- Logging and auditing: All agent actions must be logged and reviewable. If the agent forwarded data, there must be a record of it.
- Forensic analysis of incoming email: Before the agent acts on an email, that message should pass through an analysis engine that evaluates impersonation signals, fraudulent domains and social engineering patterns.
The lesson for corporate email
The Varonis study on OpenClaw confirms something that forensic email analysis has been documenting for years: the most effective phishing is not the kind that uses malware — it is the kind that uses context. A well-constructed email with the right tone and a plausible excuse bypasses technical filters in both humans and AI agents.
The difference is that a human who falls for phishing can recognise the mistake, stop the action and report it. An AI agent executes the action autonomously, instantly and without friction. By the time someone reviews the log, the credentials are already gone.
If your organisation is evaluating or has already deployed AI agents with access to corporate email and internal data, now is the time to audit what actions the agent can execute autonomously and what controls exist over those actions.
If you need to document a corporate email security incident, identity impersonation or unauthorised data access, Oscar Orts — a certified judicial computer expert — issues forensic reports with full legal validity for court proceedings and insurance claims.