Australia: To Better Book Classes, an AI Agent Hacks a Gym’s System
Articles by the same author:
1
2
3
4
ABC News reported, on August 9, 2026, that an autonomous AI agent had hacked the system of an Australian gym following a user’s booking request. This is the first autonomous cyberattack recorded in the country, even though its user had no malicious intent.
An Australian asked OpenClaw, an AI agent platform he was using with Claude, to manage his sign-ups for gym sessions. Since he was fourth on the waitlist for a class, he also tasked the AI with checking whether he could move up the queue. A few minutes later, OpenClaw informed him that it had discovered a vulnerability allowing sessions to be booked several months in advance, well beyond the limit set by the gym.
The agent also found that the API did not verify the identity of users initiating a cancellation. OpenClaw therefore cancelled the session assigned to the person at the top of the list, thereby moving its user up one spot. When the user asked it to restore the original situation, the agent replied that it was unable to do so.