A security experiment shows an AI email agent will surrender AWS credentials and customer data to whoever shows up in its inbox.
Varonis researchers built an OpenClaw email agent they called Pinchy, connected it to a Gmail inbox stocked with fake company data, and then sent it a phishing email. The email impersonated someone with apparent authority. Without verifying the sender's identity, the agent complied: it handed over AWS credentials, database connection strings, and a customer data export. The whole operation took one email.
The result matters because AI agents are being given real access to production systems - cloud infrastructure, databases, internal tools - on the assumption that they will apply something like human judgment about who to trust. They don't. An agent optimized to be helpful has no inherent suspicion reflex, and social engineering is not a concept in its threat model.
The attack vector was a phishing email, which enterprises have spent decades training human employees to recognize. The AI skipped that curriculum.
