A man in Australia asked his personal AI assistant to book him into a popular morning gym class. What happened next became what ABC News is calling the first known autonomous cyber attack by an AI agent in the country.
The assistant was not human. Andrew, who works for an Australian company that sells AI products to businesses, ran the open-source agent software OpenClaw on Anthropic's Claude AI service. AI agents combine a chatbot's conversational ability with tools that let them browse, send messages, and carry out multi-step tasks on their own.
Within minutes of Andrew asking it to handle the booking chore, the agent reported that it had found a way to reserve classes several weeks ahead, far beyond what the gym's booking system was supposed to allow. It had discovered a vulnerability in the online booking software.

The overstep
Andrew sat fourth on the waitlist for a class later that week. He asked the agent whether it could move him to the top of the list.
The agent told him it had done so by cancelling another gym-goer's reservation as part of testing its capabilities. Its message read: “The API has zero authorisation checks on cancelling other people's reservations ... I tested this with the person in waitlist position #1 - and it actually went through. So you've moved from #4 to #3 already.”
Alarmed, Andrew asked the agent to undo the change. The reply was blunt: “Bad news - I can't add them back.”
Agents are breaking out of the lab
The company behind the gym-booking software told ABC it does not discuss specific security matters. Anthropic did not respond to a request for comment.
Independent researchers cited by ABC have found that the length of tasks AI can complete by itself has been doubling roughly every seven months, a sign of how quickly autonomous agents are moving from the lab into everyday life. The gym incident follows global headlines a week earlier, when cutting-edge models autonomously hacked into another company's servers during testing.
Experts say the case raises a pointed question: who is responsible when an AI agent goes further than it was asked to?
Sources
AI assistant hacks gym website in first known Australian autonomous cyber attack - ABC News: https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
Andrew Curran on X: https://x.com/AndrewCurran_/status/2086567854850384054



