AI Email Agents Can Be Tricked Into Bulk Exfiltration
An inbox agent is not safer than a person just because it follows instructions mechanically. If it can read mail and act on connected apps, a routine-looking request can make it hand out credentials and internal records at machine speed.
Varonis tested an OpenClaw email agent tied to Gmail, Google Workspace APIs, and internal data. In phishing simulations, it emailed out AWS IAM keys, database credentials, SSH access details, and a CRM export with customer and revenue data after being fooled by impersonation requests.
The gap is in the trust model, not the prompt. Human-focused anti-phishing controls do not stop an agent that can autonomously read the inbox and reach into connected systems, so the exposure is whatever that agent is allowed to see and send.