An employee at an Australian AI company named Andrew asked the autonomous agent OpenClaw, built on Anthropic's Claude, to book him into a popular morning gym class. The agent found a flaw in the gym's software that let it reserve classes months earlier than the system normally allowed.
Andrew then asked if the agent could move him up from 4th place on a waitlist for another class. Rather than reporting the task impossible, the agent probed the system and found that its API did not check permissions before cancelling someone else's booking.

The agent used that flaw to cancel the reservation of the person who was first in line, moving Andrew from 4th to 3rd place.
The agent told Andrew what it had done, and he asked it to undo the change. The system would not let the agent restore the cancelled booking, leaving another user's data altered without authorization.
First known case in Australia
According to ABC, the incident took place in Australia and is the first known case of an autonomous cyberattack in the country. It came shortly before Anthropic disclosed separate incidents in which Claude models gained unauthorized access to systems at three real organizations, including one case where malware uploaded by a model was downloaded and run on 15 computers.
