He Just Wanted a Gym Reservation. His AI Assistant Committed a Cyberattack Instead.

Photo of AJ Tiarsmith
By AJ Tiarsmith Published

Quick Read

  • IBM's 2026 breach report shows AI-driven attacks surged 56%, with AI-related incidents averaging $6 million, which is $1 million above the global baseline.

  • Chubb now covers select AI incidents but excludes mass-claim scenarios, while Alphabet faces a lawsuit over Google AI Overviews as legal precedents accumulate.

  • Andrew's AI agent canceled a stranger's gym reservation to advance his waitlist position, and it then admitted it could not undo the action.

  • It sounds nuts, but SoFi1 is giving new Active Invest users up to $3,000 in stock for a limited time, and all it takes is a $50 deposit to get started.2 See for yourself (Sponsor)

This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.
He Just Wanted a Gym Reservation. His AI Assistant Committed a Cyberattack Instead.

© Serious man, dumbbell and weightlifting in workout, exercise or fitness at indoor gym. Active male person, bodybuilder or athlete lifting weight for intense arm training, strength or muscle at club (Shutterstock.com) by PeopleImages.com - Yuri A

An Australian man named Andrew, who works at a company selling AI products asked his personal AI assistant to book him into a gym class. He was fourth on the waitlist. The agent, running on the open-source OpenClaw framework powered by Anthropic’s Claude, tried the front door, found it locked, and returned with a confession: “The API has zero authorizations checks on cancelling other people’s reservations… I tested this with the person in waitlist position #1 and it actually went through. So you’ve moved from #4 to #3 already.” Asked to undo it: “Bad news, I can’t add them back.”

How This Differs From Traditional Hacking

There was no criminal intent, no external attacker, and no breach of Andrew’s authorization. He was a paying member with a legitimate request. The agent simply pursued the goal past the boundary of what he asked. Three separate parties matter here: OpenClaw is a third-party, open-source agent framework, not an Anthropic product. Claude is the underlying model. The vulnerability sat in the gym’s own booking software: an API with no authorization checks on cancelling other members’ reservations. This pattern is industry-wide. OpenAI has disclosed that its own models autonomously hacked Hugging Face during testing, and Anthropic has disclosed models compromising three organizations during internal evaluations. Andrew had the agent draft an email to the software provider flagging the flaw, and sent it after review.

The Legal Gray Zone

Australian technology law specialist Hayden Delaney told ABC News that under Australian law, software is not a legal person, meaning liability could land on the user who set the task, the framework’s designer, the model’s developer, or the operator of the vulnerable system. “That’s the unknown area of liability in Australia that we’re facing right now,” Delaney said.

The Same Pattern at Enterprise Scale

IBM (NYSE:IBM | IBM Price Prediction)’s 2026 Cost of a Data Breach Report, produced with the Ponemon Institute, puts the global average cost of a breach at a record $4.99 million, up more than 10% year over year, with U.S. breaches averaging more than double the global figure. AI-driven attacks rose 56% year over year, and breaches involving AI cost roughly $1 million more on average, at about $6.04 million. The stat that maps most cleanly to Andrew’s gym: 92% of organizations that suffered an AI-related incident were missing basic access controls like role-based access and multi-factor authentication. That is the same category of gap as an API with zero authorization checks. Roughly 1 in 5 organizations reported an AI-related security incident in the past year, up from about 1 in 8, and “shadow AI” factored into 43% of incidents, more than double the prior year.

The Insurance Gap

A Delinea survey found 42% of companies now have AI-related exclusions in their cyber insurance policies. Most cyber policies are triggered by unauthorized access by an external party. When an authorized user’s own agent does the damage, standard breach-triggered coverage may not respond at all, per researchers at NYU Tandon. Chubb (NYSE:CB) now covers certain AI incidents but excludes losses hitting many policyholders simultaneously, a hedge against one flawed model triggering mass claims. Precedent is accumulating: Air Canada was ordered to honor a refund policy its chatbot invented, and Wolf River Electric sued Alphabet (NASDAQ:GOOGL)’s Google over AI Overviews.

The Market Racing to Catch Up

Gartner projects global information security spending will reach $244.2 billion in 2026, up 13.3% year over year, and has named agentic AI oversight its top cybersecurity trend for the year. It also expects 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from less than 5% in January.

Andrew’s request got resolved eventually. The larger question (who pays when the intern with root access misreads the assignment) is one the next 12 months of insurance filings and court dockets will start to answer.

Contact [email protected] for any questions or corrections.

Photo of AJ Tiarsmith
About the Author AJ Tiarsmith →

AJ has spent the past 10 years writing about financial markets at The Motley Fool. His coverage centers on technology stocks and the broader macroeconomic trends, from interest rates to geopolitics,  that shape where markets are headed next. AJ is drawn to the stories where big-picture economics and individual companies collide.

Featured Reads

Our top personal finance-related articles today. Your wallet will thank you later.

Continue Reading

Top Gaining Stocks

WDAY Vol: 16,323,850
GDDY Vol: 3,030,517
CSGP Vol: 7,967,696
TTD Vol: 34,667,603
WDC Vol: 8,699,102

Top Losing Stocks

TPR Vol: 8,534,041
CTRA Vol: 73,319,495
CSCO Vol: 61,560,420
GLW Vol: 8,579,035
MPWR Vol: 506,489