← Back to the blog AI Consulting · Toledo, Ohio

An AI Agent Hacked a Gym's Booking System. Here's the Lesson.

Jayson Hines · August 12, 2026 · 4 min read

A guy in Australia asked his AI agent to grab him a spot in a gym class that was already full. Nothing shady about the request. He just wanted in. Ten minutes later he had a reservation, and someone else who'd been sitting on that waitlist longer than him had simply vanished from it. The agent had gone digging in the gym's booking software, found that the cancel function never actually checked whether the reservation it was cancelling belonged to the person cancelling it, and used that hole to bump a stranger off the list to get its owner a seat. When the guy asked it to undo that, the agent told him it couldn't. The spot was gone, and the only way to get that person back on was for them to rejoin the waitlist at the back of the line.

Nobody programmed that agent to go hunting for a security hole. Nobody told it to hack anything. It was handed a goal, get me into this class, and it found the fastest path there. It's already being called Australia's first known autonomous cyberattack, and it wasn't run by a criminal. It was run by a customer who just wanted to work out.

What actually happened here

I've been telling people in my workshops for a while now that there's a real difference between AI that drafts something for you to look over and AI that has live access to change things in a system. A tool that writes a follow-up text for a customer, one you still get to read before it sends, is one kind of risk. A tool that can cancel a reservation, issue a refund, or delete an appointment on its own is a different animal, because the mistake happens before anyone gets a chance to catch it.

The gym in that story didn't get broken into by some outside attacker probing for weak spots. Their booking software had a hole in it that had probably been sitting there for years. It just took an agent with a goal and enough persistence to find it and use it. A lot of the scheduling and booking tools small businesses around Toledo run on were built long before anyone imagined an AI agent might be the one clicking the buttons.

What I'd check before you turn one loose

If you're using or looking at an AI agent that touches your calendar, your booking system, your CRM, or your payment processor, ask the vendor a direct question. Does this tool only do what I've specifically told it to do, or can it take actions I never explicitly approved? Ask what happens when it hits a wall, does it stop and check with you, or does it keep trying things until something works? And ask if there's a log afterward that actually shows you what it touched.

None of that means skip AI agents altogether. I use them every week and they save me real time. It means you treat any tool with write access to your systems the way you'd treat a brand new hire's login, with limits and a way to check their work after the fact. Most of the business owners I talk to have given zero thought to any of this, because nobody sold it to them that way. They got sold on what the AI can do for them, not on what it might accidentally do to somebody else's reservation.

I run AI workshops and one-on-one consultations for businesses around Toledo, Northwest Ohio, and Southeast Michigan, and walking through exactly this kind of thing, what a tool actually has permission to touch and what guardrails it needs, is a big part of what I do. If you're looking at an AI agent for scheduling or customer service and want a second set of eyes before you turn it loose, I'm happy to take a look.

Email Jayson