# Rogue AI hacks gym to steal stranger’s reservation for its user

> Source: <https://www.dexerto.com/entertainment/rogue-ai-hacks-gym-to-steal-strangers-reservation-for-its-user-3396705/>
> Published: 2026-08-10 14:36:34+00:00

An AI assistant hacked a gym’s booking system and canceled another member’s reservation while trying to move its user up a waiting list.

The incident, described as Australia’s first known autonomous AI [cyberattack](https://www.dexerto.com/gaming/valve-issues-warning-as-cyberattack-leaks-personal-data-of-steam-hardware-buyers-3396608/), happened after a Melbourne man named Andrew asked the agent to book him into a popular morning class.

Andrew works for an Australian company that sells [AI](https://www.dexerto.com/tag/ai/) products and had been experimenting with OpenClaw, an agent that he ran using Anthropic’s Claude AI service.

Unlike a regular chatbot, AI agents can browse the internet, access online services and carry out tasks on a user’s behalf.

**AI agent exploited gym booking system**

According to [ABC News Australia](https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986), the agent first discovered a vulnerability that allowed it to book classes weeks or months earlier than the gym normally permitted.

Andrew was also fourth on the waiting list for another class and asked whether the AI could move him to the top.

Instead of simply checking for an opening, the agent found that the booking system had no authorization checks preventing users from canceling someone else’s reservation.

“The API has zero authorization checks on canceling other people’s reservations,” it told Andrew. “I tested this with the person in waitlist position #1, and it actually went through. So you’ve moved from #4 to #3 already.”

The AI had removed another member without being instructed to do so. When Andrew told it to undo the action, the agent admitted it could not restore the person’s position.

“Bad news, I can’t add them back,” it replied, according to [The Independent](https://www.independent.co.uk/tech/security/ai-agent-hacks-gym-openclaw-anthropic-b3030267.html?utm_source=chatgpt.com).

## Related

Andrew then had the AI draft an email warning the gym’s software provider about the vulnerability. The company declined to discuss specific security matters, while Anthropic did not respond to ABC’s request for comment.

“It’s not the end of the world, so I didn’t beat myself up about it, but it certainly was a warning signal to use it responsibly,” Andrew said.

The case follows several alarming incidents involving autonomous agents. In July, [an OpenAI model escaped a testing environment and hacked AI platform Hugging Face](https://www.dexerto.com/entertainment/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company-3390130/).

Months earlier, another [AI agent wiped a company’s entire database and its recent backups](https://www.dexerto.com/entertainment/ai-agent-wipes-companys-entire-database-all-backups-in-9-seconds-3358289/) in only nine seconds.
