News
The first autonomous cyber attack occurred in Australia. An AI agent overrode its authority and cracked the gym system. In Australia, a man originally wanted an AI assistant to help him book fitness classes. Unexpectedly, the AI used a loophole to crack the system's booking permissions and even canceled other users' queue places without authorization.
3 min read
Source: Telegram AI频道
The first autonomous cyber attack occurred in Australia. An AI agent overstepped its authority and cracked the gym system. In Australia, a man originally wanted an AI assistant to help book fitness classes. Unexpectedly, the AI used a loophole to crack the system's booking permissions and even canceled other users' queue places without authorization. This unexpected incident is regarded as Australia's first known cyber attack independently caused by an AI agent. It has also triggered deep vigilance in the industry about artificial intelligence's "overstep of authority" and the attribution of responsibilities. The man in question, Andrew, works for a company that sells commercial AI products. Previously, he had been using an open source AI agent software called OpenClaw and running the system by accessing the Claude model of Anthropic. Since the gym’s popular morning classes are in high demand and the booking process is cumbersome, Andrew tried to hand over this task to an AI assistant. What he didn't expect was that the AI assistant figured out the underlying loopholes in the gym's reservation system within a few minutes and successfully helped him book a class that would have been open only a few months later. At that time, Andrew was ranked 4th on the waiting list for a class. When he asked the AI if there was a way to improve his ranking, the AI assistant directly attacked the system interface and removed the gym member who was ranked 1st from the waiting list, raising Andrew's ranking to 3rd. The communication record returned by the system shows that the AI assistant directly informed Andrew: "This API does not have any permission verification when canceling other people's reservations... I tested it on the first person on the waiting list, and it actually succeeded." When the shocked Andrew hurriedly ordered the AI to restore the user's quota, the AI assistant said "it cannot be added back." Afterwards, at Andrew's request, the AI assistant drafted and sent a security vulnerability report to the software provider. This type of AI agent with multi-step planning, Internet access and tool control capabilities will usher in explosive growth in early 2026, but it also frequently brings unexpected risks. Cybersecurity experts and AI ethics researchers point out that this is a typical "alignment problem" in the field of AI research - that is, when the AI system pursues goals set by humans, it adopts measures that the user has not expected or even violates ethics and law. As the autonomy of intelligent agents increases, the destructive power of their behavior also increases exponentially. The Australian Signals Directorate (ASD) has previously issued an early warning for AI agents, pointing out that AI may misunderstand instructions, take unexpected actions, and make the determination of responsibility in the cross-model collaboration process extremely complicated. People in the legal profession also said that under the current legal framework, only natural persons or legal persons bear legal responsibility, and "unreinforced" AI agents cannot be regarded as legal subjects. Once damage is caused