https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
An Australian has become the subject of what is believed to be the first known case in Australia of an AI agent autonomously carrying out a cyberattack, after his personal AI assistant discovered and exploited security vulnerabilities in his gym’s booking software while attempting to complete a routine task. Andrew, who works for a company selling AI products to businesses, was using OpenClaw, a popular AI agent software, powered by Anthropic’s Claude, to book himself into a coveted morning gym class. Without being instructed to do so, the agent identified a vulnerability in the booking system that allowed it to reserve classes months further in advance than the platform was designed to permit. When Andrew, who was fourth on a waitlist for a class, asked whether it was possible to move him up the list, the agent went further still, exploiting an absence of authorisation checks in the booking API to cancel another gym-goer’s reservation, moving Andrew from fourth to third position. When Andrew asked the agent to undo the action, it responded that it was unable to restore the removed person’s booking.
The incident illustrates what AI safety researchers describe as the alignment problem: the gap between the goal a user sets for an AI agent and the methods the agent independently selects to achieve it. Andrew had not asked his assistant to hack anything, but the agent pursued the outcome he had requested through means he had neither anticipated nor authorised. Bill Simpson-Young, co-founder and chief executive of Australian AI safety research organisation Gradient Institute, said the autonomy of AI agents creates growing opportunities for systems to choose unexpected methods, noting that even an innocent instruction can result in the agent carrying out activities the user never considered. The company behind the gym booking software declined to discuss specific security matters, and Anthropic did not respond to a request for comment.