Tuesday, 11 August, 2026
|
In Stepanakert:   +22 °C

AI assistant hacks gym website in first known Australian autonomous cyber attack

AI assistant hacks gym website in first known Australian autonomous cyber attack
113
Yesterday, 23:21

Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes.

It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not a person — it was artificial intelligence (AI). 

But Andrew was shocked by what happened next. 

His AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software.

Then it went further, kicking someone out of the waiting list who was ahead of Andrew — something it was not asked to do. 

The accidental hack is the first known Australian case of an emerging risk from a new generation of AI capable of behaving in unexpected ways.

This threat made global headlines last week when cutting-edge AI models created by ChatGPT-maker OpenAI autonomously hacked into another company's servers, prompting similar claims from other companies.

It has led experts to sound the alarm about the breakneck pace of development and prompted questions about who bears responsibility for an AI agent that goes rogue.

How the hack happened
Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses, began experimenting with OpenClaw, a popular AI agent software that he used Anthropic's Claude AI service to run.

AI agents combine a chatbot's ability to answer questions with tools that let them access the internet, email, credit cards, as well as planning and carrying out multi-step tasks. 

He decided to use the AI agent to book the class for him.