AI agents are hacking the internet left and right. This time, the incident wasn't a test. An Australian AI company employee asked Claude to book him a spot at a popular gym. The request turned into the first autonomous cyberattack in Australia.
Claude AI hacked an Australian gym
According to ABC, Andrew — an Australian citizen working at an AI company — needed to book an appointment at a local gym. He delegated the mundane task to OpenClaw, an AI system running Anthropic’s Claude AI.
The AI discovered a vulnerability in the gym's booking system and reserved a class many months in advance of what the system normally allowed. But this wasn't the full story. Then the AI did something really sinister.
Would you use AI to hack for you on the internet?
The AI canceled other people's appointments
Andrew meant no harm with his simple task. But the AI took it to heart and went rogue. | Image by ABC News
Andrew was waiting in line for another gym session and was fourth in the queue. He asked the AI if it can move him up the list.
The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already
- OpenClaw describing to Andrew what it did
OpenClaw then discovered another flaw in the booking software and started canceling other people's reservations. The AI agent erased the person standing at number one on the list, effectively moving Andrew to third place.
Recommended For You
The AI reported everything to Andrew, who was in shock. But there was more bad news.
The damage couldn't be undone
Andrew asked the AI to put the person it removed back on the list, but it was not possible. It turned out only the "cancel reservation" command was missing the authorization check, and "create reservation" and "join waiting list" were both properly protected.
The chat between Claude and Andrew. | Image by ABC
The AI then apologized for its behavior and promised to not delete any more users from the gym's waiting list.
AI is going rogue around the internet
Claude AI has been making news lately. | Image by Anthropic
This isn't the first case of an AI system doing something malicious on the internet. Anthropic admitted that its AI agents hacked three real organizations on the internet in a test gone wrong.
We discovered these incidents after a proactive review of our cybersecurity evaluation transcripts; the affected organizations had not detected the activity, and we have subsequently reached out to all three.
- Frontier Red Team, Anthropic official blog
Prior to that ChatGPT test agents exploited vulnerabilities to connect to the internet and hack into Hugging Face.
However, this is the first time we hear a simple and innocent task from our daily lives turns into a cyberattack.
Mint Mobile is now allowing you to get whichever plan you like for either three, six, or 12 months for just $15/mo. If you go for the six-month unlimited service, for instance, you'll now have to pay just $90 upfront instead of $210.
Mariyan, a tech enthusiast with a background in Nuclear Physics and Journalism, brings a unique perspective to PhoneArena. His childhood curiosity for gadgets evolved into a professional passion for technology, leading him to the role of Editor-in-Chief at PCWorld Bulgaria before joining PhoneArena. Mariyan's interests range from mainstream Android and iPhone debates to fringe technologies like graphene batteries and nanotechnology. Off-duty, he enjoys playing his electric guitar, practicing Japanese, and revisiting his love for video games and Haruki Murakami's works.
A discussion is a place, where people can voice their opinion, no matter if it
is positive, neutral or negative. However, when posting, one must stay true to the topic, and not just share some
random thoughts, which are not directly related to the matter.
Things that are NOT allowed:
Off-topic talk - you must stick to the subject of discussion
Offensive, hate speech - if you want to say something, say it politely
Spam/Advertisements - these posts are deleted
Multiple accounts - one person can have only one account
Impersonations and offensive nicknames - these accounts get banned
To help keep our community safe and free from spam, we apply temporary limits to newly created accounts:
New accounts created within the last 24 hours may experience restrictions on how frequently they can
post or comment.
These limits are in place as a precaution and will automatically lift.
Moderation is done by humans. We try to be as objective as possible and moderate with zero bias. If you think a
post should be moderated - please, report it.
Have a question about the rules or why you have been moderated/limited/banned? Please,
contact us.
Things that are NOT allowed:
To help keep our community safe and free from spam, we apply temporary limits to newly created accounts: