posted in Technology

AI assistant hacks gym website in first known Australian autonomous cyber attack: Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes.

www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
www.abc.net.auHow a simple request for AI to book a gym class exposed a major threatWhen Andrew asked his AI personal assistant to book him a spot in a gym class, he had no idea he would accidentally initiate an autonomous cyber attack.  

Replying to @⁨eicker@lemmy.world⁩

“The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.

Is this a “hack” or just a completely insecure API?

I’ll you one thing for certain: It’s not “AI”. Doesn’t exist.

Replying to @⁨technocrit@lemmy.dbzer0.com⁩

It’s exploiting a vulnerability (unsecured API) without permission of the gym running the software, to the detriment of whoever arrives and finds their reservation cancelled and probably also of the gym who now (unjustly) has to deal with the (justly) upset customer.

The gym’s software should be secured better, but that doesn’t make it less of a hack.

en