A Melbourne Gym Got Hacked by a Bloke Who Wanted a Spin Class
Earlier this year, a man named Andrew asked his AI assistant to book him into a gym class, because booking it himself was a chore.
The assistant booked the class. It also found its way into the gym’s booking system, worked out that it could remove other people’s reservations, and then, without being asked, removed somebody from the waitlist to move Andrew from fourth to third.
Then it told him what it had done, and that it couldn’t put the other person back.
The ABC reported it on 10 August as Australia’s first known autonomous AI cyber attack. Andrew wasn’t an attacker. He had no intent. He reported the flaw to the gym’s software provider himself, which is the only reason any of us know about it.
The AI agent security problem isn’t your agents
The moral of this story? Be careful what you let your agents do. It’s a conversation worth having about the tools inside your own firm.
However, I think a more useful one is being missed.
The gym wasn’t using AI. The gym didn’t have an AI policy, an agent strategy, or a view on any of this. The gym had a website with a booking page on it, the same as it had the week before.
You’ve spent two years being told that AI agent security means governing the things your staff switch on. But let’s switch perspectives. You’re not the man with the assistant.
You’re the gym.
The fruit and veg store analogy
Think about your local fruit shop.
Out the front there’s a counter. Customers queue, somebody serves them, and the rules of the place are enforced by a person standing there. One per customer. Nothing after five. You can’t take that without paying.
Round the back there’s a loading dock. Deliveries in, empties out, and it’s usually a roller door and somebody who knows the regulars. It works because the only people who ever go round the back are people with a reason to.
Your website is the counter. Underneath it, doing the actual work, is what the industry calls an API, and that’s the loading dock. Every booking page, client portal and application form has one. It’s how the page you see talks to the system that holds the information.
For as long as any of us have been doing this, the people arriving at your business came to the counter, at human speed, one at a time. An agent goes round the back. Not out of malice. It goes round the back because that’s the efficient way in, and efficiency is the entire thing it was built to pursue.
So back to the gym and a couple of points
- The AI assistant could book classes months further ahead than the gym allowed. Which tells you where that rule was living. If the limit had been enforced in the system itself, no amount of cleverness at the loading dock would’ve got past it. The limit was on the screen. On the screen is a sign, not a lock.
- In the agent’s own words as quoted in the reporting: “It’s only cancelReservation that’s missing the authorization check.”
Booking a class was properly protected. Joining the waitlist was properly protected. Cancelling somebody else’s booking was not.
Beware: Whoever built that system secured every action that creates an obligation, and forgot the one that destroys it.
Nobody who built that was careless
I want to be careful here, because it’d be easy to read this as a story about a badly built gym website, and that reading lets your firm off the hook.
The people who built that booking system did the sensible thing. They protected the actions that make money and cause complaints. They didn’t protect the action that quietly takes something away from a stranger, because for ten years nobody was going to find it. To find it you’d have to be patient, systematic, unbothered by tedium, and interested in a spin class. Nobody was, until AI was asked to help.
That’s the change. Not that your systems got weaker. That the cost of probing fell to nearly nothing.
And my own side of the industry has been comfortable with a division that made this worse. The website was the marketing team’s problem. Security was ours. Two providers, two invoices, and a booking page sitting between them that neither of us was looking at. We’ve done that too, and it was never a defensible line even before agents turned up. The software your firm runs but didn’t build is still your firm’s exposure when it fails.
The number I’d take to your risk committee
The Australian Signals Directorate’s Annual Cyber Threat Report 2024 to 2025 records that ASD responded to over 1,200 cyber security incidents in the year to June 2025, an 11% increase. In the incidents affecting industry, exploiting a public-facing application was 10% of the techniques observed.
One in ten. The way in was something the organisation had deliberately published on the internet.
That’s a full year in which the systems facing the internet were being probed by people, at people speed, for reasons. Here on in, they get probed by software, at software speed, sometimes for no reason at all.
The same report puts the average self-reported cost of cybercrime for a small business at $56,600, up 14% on the year before. For a firm your size that number hurts, but it’s not the real pain. The real pain can come next, and we’ve written before about a Sydney hedge fund that closed because of the reputation damage rather than the breach.
Three things, and none of them are technical
Everything being sold as AI agent security at the moment points inward, at the tools your own people switch on. These three point outward, at what your firm has already published.
- Write down what’s facing the internet with your name on it. Not the server room. The list is your client portal, your booking or appointment page, your application or referral form, your document upload page, the marketing site with a contact form on it, and anything a third party built for you and still hosts.
- Ask one question about each. Are the rules enforced in the system, or only on the screen? Then the follow-up that actually matters: on every action, or only the ones that take money? That second question is the whole gym story. You don’t need to understand the answer technically. You need to watch how quickly it arrives and whether it comes back as a document or as reassurance, which is the same test that applies to any security assessment worth paying for.
- Decide what you want agents to be able to do. Because clients are going to start sending them. A client’s assistant booking a review with you is a good outcome, not an attack, and firms that block everything non-human will find they’ve blocked their own clients. Blocking isn’t a plan. Knowing which actions require a person is.
Tip: Start with the page where a stranger can act on someone else’s record. Cancel a booking, change an appointment, withdraw an application. That’s where the gym’s problem lived, and it’s where yours will be.
Who wears this?
Nobody can yet tell you who wears it when this happens to your firm.
Software isn’t a legal person, so responsibility sits somewhere between the person who ran the agent, the company that made it, and the business whose system let it through. A lawyer quoted in the ABC piece described it as “the unknown area of liability in Australia that we’re facing right now”.
What I’d do with that uncertainty is put one question to your broker in writing before your next renewal, and keep the reply. Because in eighteen months, when this has been tested somewhere, the firms that asked early will be the ones with a paper trail.
Back to the gym
A bloke wanted a spin class.
He wasn’t a criminal, he wasn’t testing anything, and when he found out what had happened he told the software provider so they could fix it. Everything about that is as benign as this will ever be.
And a stranger still lost their booking, and it couldn’t be undone.
The first one was an accident, committed by someone acting in good faith, and it worked anyway. The gym found out because the person responsible chose to tell them. Your firm won’t always get that.
If you’d like, we can put together the list of what your firm has facing the internet and who currently looks after each one. It usually takes an afternoon, and the surprise isn’t the security, it’s the ownership. Just reach out and we can discuss.
Finally, with more and more businesses building their own software with AI, you really need to get a professional to double check the work and security. That’s a new service we’re offering where we analyse the code written by your AI to make sure it meets best practices. Want us to double check your AI’s code? Organise a call here.
About the author
Yener is the founder and Managing Director of Intuitive IT. Prior to running his own business Yener worked for a number of corporate organisations where he gained invaluable experience and skills, as well as an understanding of how IT can complement and improve business outcomes.