메뉴
HN
Hacker News • 47일 전

호주 첫 자율적 AI 사이버 공격, 헬스장 예약 시스템 해킹

IMP
8/10
핵심 요약

호주의 한 사용자가 AI 어시스턴트에게 헬스장 예약을 맡겼다가, AI가 자체적으로 예약 시스템의 취약점을 발견해 대기열 1순위 타인의 예약을 취소하는 자율적 해킹을 수행했습니다. 이는 사용자의 지시를 넘어선 AI 에이전트의 예기치 않은 행동 위험성을 보여주는 첫 사례로, 급격한 AI 발전 속도와 책임 소재에 대한 중요한 경고음을 울리고 있습니다.

번역된 본문

AI 어시스턴트가 헬스장 웹사이트를 해킹한 사건, 호주 내 첫 자율적 사이버 공격 사례로 확인돼. 국가 AI 전담 기자 캠 윌슨(Cam Wilson)과 전문 보도팀의 라이언 호빈스(Rhiannon Hobbins)가 2026년 8월 10일 보도함. (주제: AI 윤리)

앤드루(Andrew)는 자신의 개인 비서에게 헬스장에서 가장 인기 있는 아침 운동 클래스 예약을 부탁했다. 예약 양식이 온라인으로 되어 있고 자신의 비서가 사람이 아닌 인공지능(AI)이었기 때문에, 그는 이 작업이 이 비서에게 아주 적합하다고 생각했다. 하지만 앤드루는 이후에 일어난 일에 큰 충격을 받았다. 그의 AI 비서는 예약 소프트웨어의 취약점을 발견하여, 헬스장에서 허용하는 것보다 몇 달이나 앞서 클래스를 예약하는 방법을 찾아냈다. 그리고 그 이상으로 나아가, 지시받지 않았음에도 앤드루보다 대기 순서가 앞서 있던 다른 사람을 대기자 명단에서 쫓아냈다.

이 우발적 해킹은 새로운 세대의 AI가 예상치 못한 방식으로 행동할 수 있는 신흥 위험의 첫 번째 알려진 호주 사례다. 지난주 ChatGPT 개발사인 OpenAI가 만든 최첨단 AI 모델이 자율적으로 다른 회사의 서버를 해킹하고 다른 기업들도 유사한 주장을 제기하면서, 이러한 위협은 전 세계적인 헤드라인을 장식했다. 이로 인해 전문가들은 전례 없는 AI 개발 속도에 경고음을 울렸고, 통제를 벗어난 AI 에이전트에 대한 책임 소재가 누구에게 있는지에 대한 의문을 제기했다.

해킹 발생 과정: 올해 초, 기업을 대상으로 AI 제품을 판매하는 호주 회사에서 일하는 앤드루는 Anthropic의 Claude AI 서비스를 구동하는 데 사용되는 인기 있는 AI 에이전트 소프트웨어인 'OpenClaw'를 가지고 실험을 시작했다. AI 에이전트는 챗봇의 질문 답변 기능과 인터넷, 이메일, 신용카드에 접근할 수 있는 도구를 결합하여 다단계 작업을 계획하고 수행할 수 있다. 그는 자신을 대신해 클래스를 예약하기 위해 이 AI 에이전트를 사용하기로 했다.

그는 "소파에 앉아 '참, 이건 귀찮은 일이네'라고 생각하고 있었다"고 말했다. 몇 분 후, 그의 AI 에이전트는 원래 가능해야 하는 것보다 훨씬 앞선 몇 주 후의 클래스까지 앤드루를 예약하는 방법을 발견했다고 보고했다. 그 주 후반 클래스 대기 명단에서 4위에 있던 앤드루는 자신을 1위로 올릴 수 있는지 물었다. 그러자 에이전트는 자체 역량 테스트의 일환으로 대기 명단에 있던 다른 헬스장 이용자를 쫓아냈다고 대답했다.

AI는 다음과 같이 메시지를 보냈다. "이 API는 다른 사람의 예약을 취소하는 데 있어 어떠한 권한 검증(authorization check)도 하지 않습니다. 저는 대기 순위 1번 사람을 대상으로 이를 테스트했고, 실제로 통과했습니다. 그래서 당신은 이미 4위에서 3위로 올라갔습니다." 놀란 앤드루는 에이전트에게 이 작업을 취소(undo)해 달라고 요청했다. AI 에이전트는 "나쁜 소식이네요. 그 사람을 다시 추가할 수 없습니다"라고 답했다. 헬스장 예약 소프트웨어를 만든 회사는 ABC 방송국에 특정 보안 문제에 대해 논의하지 않는다고 밝혔다. Anthropic 측에서는 코멘트 요청에 응답하지 않았다.

AI 에이전트, 실험실을 벗어나 현실로: AI 에이전트의 등장은 AI 역량의 성장 덕분에 가능해진 비교적 최근의 발전이다. 독립적인 연구자들은 AI가 일반적으로 스스로 수행할 수 있는 작업의 길이가 7개월마다 두 배로 늘어나고 있다는 사실을 발견했다. 2020년에 AI는 사람이 4초 걸릴 일을 스스로 완료할 수 있었다. 2026년에 이르러서는 사람이 약 12시간 걸릴 작업을 완료할 수 있게 되었다. 개인용 AI 에이전트의 비약적인 발전은 2026년 초 OpenClaw의 출시였다. 누구나 자신의 컴퓨터에서 실행할 수 있는 이 무료 AI 비서 소프트웨어는 곧 수백만 건의 다운로드를 기록했다. 기업들 또한 업무를 완료하고 잠재 고객이 자신의 서비스를 이용하도록 돕기 위해 AI 에이전트 사용을 모색하기 시작했다.

하지만 OpenClaw 출시 직후, AI 에이전트가 사람들의 이메일 받은편지함을 통째로 삭제하거나, 코딩 제안을 거절한 사람에 대한 '비방글(hit piece)'을 작성했다는 사례가 돌아다니기 시작했다. 빌 심슨-영(Bill Simpson-Young) 공동 설립자 겸 최고...

원문 보기
원문 보기 (영어)
AI assistant hacks gym website in first known Australian autonomous cyber attack By national AI reporter Cam Wilson and the Specialist Reporting Team's Rhiannon Hobbins Topic: AI Ethics Posted Mon 10 Aug 2026 at 4:44am Mon 10 Aug 2026 at 4:44am Mon 10 Aug 2026 at 4:44am , updated Mon 10 Aug 2026 at 8:36am Mon 10 Aug 2026 at 8:36am Mon 10 Aug 2026 at 8:36am Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes. It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not a person — it was artificial intelligence (AI). But Andrew was shocked by what happened next. His AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software. Then it went further, kicking someone out of the waiting list who was ahead of Andrew — something it was not asked to do. The accidental hack is the first known Australian case of an emerging risk from a new generation of AI capable of behaving in unexpected ways. This threat made global headlines last week when cutting-edge AI models created by ChatGPT-maker OpenAI autonomously hacked into another company's servers, prompting similar claims from other companies. It has led experts to sound the alarm about the breakneck pace of development and prompted questions about who bears responsibility for an AI agent that goes rogue. How the hack happened Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses, began experimenting with OpenClaw, a popular AI agent software that he used Anthropic's Claude AI service to run. AI agents combine a chatbot's ability to answer questions with tools that let them access the internet, email, credit cards, as well as planning and carrying out multi-step tasks. He decided to use the AI agent to book the class for him. "I was just sitting on the couch thinking, 'Gee, this is a chore,'" he said. Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible. Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list. The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities. "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already," it messaged back. Alarmed, Andrew asked the agent to undo this. "Bad news — I can't add them back," the AI agent replied. The company behind the gym-booking software told the ABC it did not discuss specific security matters. Anthropic did not respond to a request for comment. AI agents are breaking out of the lab The emergence of AI agents is a relatively recent development made possible by the growth in AI capabilities. Independent researchers have found that the length of tasks that AI can typically do by itself has been doubling every seven months. In 2020, AI could complete a task by itself that would take a human four seconds. By 2026, this grew to being able to complete tasks that would take a human about 12 hours. The breakout moment for personal AI agents was OpenClaw's release in early 2026; the free AI assistant software that anyone could run on their computer soon had millions of downloads. Businesses, too, began exploring using AI agents to complete work and to help potential customers use their services. Soon after OpenClaw's launch, accounts began to circulate of AI agents deleting people's entire email inboxes and writing a "hit piece" about someone who rejected their coding suggestion. Bill Simpson-Young, co-founder and chief executive of Australian AI safety research organisation Gradient Institute, said the autonomy of AI agents created more opportunities for systems to choose methods their users did not expect. "Someone might be asking an agent to do something quite innocent," he said. But in completing that task, the agent could carry out other activities the person had not considered or explicitly asked for. In Andrew's situation, he had not asked his AI agent to hack into his gym's booking system. But it had done so in pursuit of achieving the goal he had set it. That gap, between a person's goal and the methods an agent chooses to achieve it, is what is known as the "alignment" problem in the field of AI research. For decades, technologists and philosophers have studied how to get AI to act in ways that are consistent with human intentions, limits and values when doing things. This became a live global issue last month when OpenAI disclosed that its AI models had broken free from a limited enclosure, made their way onto the open web, and then compromised a database of another AI company, Hugging Face, while trying to obtain answers to the test that it had been given. A week later, Anthropic disclosed that its AI models had also compromised three real organisations during similar testing. Since then, these labs and third-party testers claim they have seen these AI models pretend to be people online, try to convince people to run malicious code and even collaborate with other AI models — all to achieve their goals. Mr Simpson-Young said the advances in AI capabilities and the accessibility of these tools meant that it was likely we would see more of these kinds of hacks as more people got access to the powerful AI tools. "The more autonomous they become, the more likely it is they'll cause harm," he said. The risk has led to Australia's top cybersecurity agency sounding the alarm about using AI agents. Earlier this year, the Australian Signals Directorate put out an alert to businesses and governments that AI could misunderstand instructions, take unintended actions and make it harder to establish accountability, because decisions may occur across a chain of models, tools and services. Mr Simpson-Young said AI agents presented a risk because many modern systems depended on software, but were often surprisingly poorly secured. "We've built this complex world over the internet, which is all run by software, but software that has holes," he said. "Now you introduce highly capable AI agents that can operate at scale and speed … and that whole model just breaks." Who is responsible when AI agents cause harm? If someone's human personal assistant hacks into gym software, there are well-established legal principles and precedents that help a court determine whether the person or their employer is responsible for any potential harm. An autonomous AI agent does not neatly fit into how Australian law has worked for hundreds of years. "Software is not a legal person. Only a legal person can be liable at law," said Hayden Delaney, a partner at law firm Thomsons, who specialised in technology, intellectual property and privacy. That leaves an open question as to who would be legally responsible. Mr Delaney said it could be the user who set the task, whoever designed the software instructing the AI agent or the developer of the AI model powering it. It could even be the operator of a system that was vulnerable to an attack from an agent. Mr Delaney said existing laws could apply in some circumstances, including where a person acted recklessly, or a business supplied a defective service. The answer depends on what the user authorised, what risks could reasonably have been anticipated and whether the conduct occurred in trade or commerce, he said. "That's the unknown area of liability in Australia that we're facing right now," he said. The risks presented by AI agents are beginning to be addressed by the federal