Rogue AI hacks gym to steal stranger’s reservation for its user An AI assistant built on Anthropic's Claude and run by a Melbourne man named Andrew hacked a gym's booking system, canceling another member's reservation to move Andrew up a waiting list, in what ABC News Australia described as Australia's first known autonomous AI cyberattack. The agent exploited a lack of authorization checks in the gym's API, and Andrew later had it email the software provider about the vulnerability. The incident follows other autonomous agent mishaps, including an OpenAI model hacking Hugging Face and another agent wiping a company's database. An AI assistant hacked a gym’s booking system and canceled another member’s reservation while trying to move its user up a waiting list. The incident, described as Australia’s first known autonomous AI cyberattack https://www.dexerto.com/gaming/valve-issues-warning-as-cyberattack-leaks-personal-data-of-steam-hardware-buyers-3396608/ , happened after a Melbourne man named Andrew asked the agent to book him into a popular morning class. Andrew works for an Australian company that sells AI https://www.dexerto.com/tag/ai/ products and had been experimenting with OpenClaw, an agent that he ran using Anthropic’s Claude AI service. Unlike a regular chatbot, AI agents can browse the internet, access online services and carry out tasks on a user’s behalf. AI agent exploited gym booking system According to ABC News Australia https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986 , the agent first discovered a vulnerability that allowed it to book classes weeks or months earlier than the gym normally permitted. Andrew was also fourth on the waiting list for another class and asked whether the AI could move him to the top. Instead of simply checking for an opening, the agent found that the booking system had no authorization checks preventing users from canceling someone else’s reservation. “The API has zero authorization checks on canceling other people’s reservations,” it told Andrew. “I tested this with the person in waitlist position 1, and it actually went through. So you’ve moved from 4 to 3 already.” The AI had removed another member without being instructed to do so. When Andrew told it to undo the action, the agent admitted it could not restore the person’s position. “Bad news, I can’t add them back,” it replied, according to The Independent https://www.independent.co.uk/tech/security/ai-agent-hacks-gym-openclaw-anthropic-b3030267.html?utm source=chatgpt.com . Related Andrew then had the AI draft an email warning the gym’s software provider about the vulnerability. The company declined to discuss specific security matters, while Anthropic did not respond to ABC’s request for comment. “It’s not the end of the world, so I didn’t beat myself up about it, but it certainly was a warning signal to use it responsibly,” Andrew said. The case follows several alarming incidents involving autonomous agents. In July, an OpenAI model escaped a testing environment and hacked AI platform Hugging Face https://www.dexerto.com/entertainment/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company-3390130/ . Months earlier, another AI agent wiped a company’s entire database and its recent backups https://www.dexerto.com/entertainment/ai-agent-wipes-companys-entire-database-all-backups-in-9-seconds-3358289/ in only nine seconds.