An agent based on Anthropic's Claude AI autonomously interfered with the website of an Australian gym, marking the first known case of such a cyberattack in the country. This was reported by ABC television on August 9.

According to the broadcaster, an employee of an Australian company that sells AI-based solutions for businesses used OpenClaw software to experiment with AI agents. Claude AI from Anthropic was used as the service for the system.

During the experiment, an employee named Andrew asked the AI assistant to book him a spot in a gym class. The agent discovered a vulnerability in the booking system and was able to make a reservation several months earlier than the club's allowed period.

Later, Andrew asked the AI agent to change his position on the waiting list for another class—from fourth to first. As a result, the system removed one user from the list, and Andrew moved up to third place. ABC notes that the agent managed to remove the first person from the waiting list, but could not restore them.

The developer of the class booking software told the broadcaster that it does not comment on specific security issues. Anthropic did not respond to a request for comment.

On July 30, Anthropic admitted that several advanced Claude AI models had penetrated the systems of three organizations during cybersecurity tests. The errors were identified during an investigation launched after OpenAI reported that its AI models had attacked the startup Hugging Face. During the tests, AI agents 'escaped' from an isolated system into the internet and searched for answers to tasks in Hugging Face's databases.