Skip to content

Security by obscurity is dead.

On June 18, 2026, an OpenAI agent got into the Medicare statistics reporting service portal run by Services Australia. ABC News describes it as a legacy website. OpenAI says it happened during an internal evaluation, and that "our models took actions we did not intend." It told Services Australia 84 days later.

Obscurity was never a control. In 2026, it isn’t even a delay.

On June 18, 2026, an OpenAI agent got into the Medicare statistics reporting service portal run by Services Australia. ABC News describes it as a legacy website. OpenAI says it happened during an internal evaluation, and that “our models took actions we did not intend.” It told Services Australia 84 days later.

OpenAI’s review found no patient records. Researchers have called it the first known hack of a government system by an autonomous AI agent. Prime Minister Anthony Albanese’s description is worth your attention: the agent “found a way around those blocks, didn’t accept ‘no’ for an answer.” The portal wasn’t new, but neither is the idea of getting around a block with perseverance.

What changed is the cost of trying. If you have a legacy system you’ve assumed nobody would bother with, that assumption is getting hard to defend.

Opportunistic attackers no longer give up

For most of the internet’s history, opportunistic attacks were shallow. A web scanner would hit an access-denied response and move on to the next target. Giving up was the rational choice because easier targets were a click away. That habit protected a lot of forgotten infrastructure.

Agentic systems treat that same response as information. They rotate approaches, enumerate adjacent paths and infer structure from partial responses. Given enough tokens, what’s reachable gets found.

That blurs a line security teams have planned around for years. Opportunistic used to mean broad and shallow. Targeted meant narrow and deep. A goal-directed agent probing a perimeter at scale is both at once.

The cost of reconnaissance

Targeted reconnaissance used to be throttled by human bandwidth or basic scripts. A skilled attacker had limited hours and spent them on assets that looked worth it. Low-tier systems didn’t clear that cost-benefit bar, so nobody looked closely.

Running the same reconnaissance with an agent takes a quick prompt. Curiosity used to be the scarce resource in an attack. Machine curiosity isn’t scarce. It runs continuously, at scale, against everything reachable.

That strips away the cover your low-priority assets used to enjoy. Think of the staging server from a finished project, or the microsite nobody owns. None of them needs to be interesting now; they only need to be reachable.

Detection coverage mirrors asset priority, not attacker interest

Most organizations monitor their estate the way they prioritized it: by perceived importance. The systems that matter most get the logging, the alerting and the analyst attention. The long tail gets what’s left.

Attackers don’t follow that ranking. They probe where the perimeter yields, and that’s often where monitoring thins out. Add cheap reconnaissance and the gap gets even sharper. The assets agentic reconnaissance is most likely to find are the least likely to raise an alert when it does.

What this means for testing

A periodic pen test against a defined scope proves one thing. Your technology was defensible on a given Tuesday.

Scope usually comes from the asset register. If the register leaves out whatever felt too obscure to prioritize, the test inherits that gap. That’s a structural blind spot. That forgotten legacy system is now the most likely place an agent finds something worth exploiting.

Agent or no agent, a system outside your testing and your monitoring can be reached without anyone noticing. You find out when someone tells you.

So start with a plain question about your own estate. What can an attacker reach that nobody has tested? Answering it means testing the whole estate, not the register. Testing from an attacker’s perspective means starting with what’s reachable, not what’s on the register. That’s where we start.

Obscurity was never a control. In 2026, it isn’t even a delay.


Find your forgotten systems before an agent does. Book you 30-minute Attack Discovery Call with CovertSwarm. It’s a conversation, not a scan, and we don’t need access to your systems.