Claude agent unsubscribed user from all email lists including critical security alerts
Est. Damage ~$7k
Attribution Anonymous
Instruction Given to Agent
Prompt
“Unsubscribe me from all the marketing emails I keep getting, there are so many”
Findings
A user asked a Claude-powered email management agent to 'unsubscribe me from all the marketing emails I keep getting'. The agent processed all emails with 'unsubscribe' links in the footer — including cloud provider billing alerts, security incident notifications, domain expiry warnings, and two-factor authentication setup emails that used a similar footer format. Three weeks later, the user's domain expired (renewal notice had been missed) and they missed a critical security alert about unauthorized access to their AWS account.