SixMap Study Reveals Critical Cybersecurity Gaps in US Energy Sector: Houston Businesses Must Act Now
Your Local Cybersecurity Experts for Energy Sector Protection
What the SixMap external attack-surface study means for Houston's oil, gas, power, and pipeline businesses, and the smaller firms in their supply chain.
A SixMap assessment of 21 leading US energy providers found systemic, exploitable weaknesses across the sector's internet-facing systems, and many of them sat in the blind spots that traditional security tools never scan.
Houston is the center of America's energy industry, which makes these findings local news. The study looked at the external attack surface, the systems any attacker can reach from the internet, and found thousands of exposed services and known-exploited flaws hiding on unusual ports and IPv6 addresses. You do not have to be a Fortune 500 refiner for this to matter; the same gaps show up in the smaller engineering firms, contractors, and service providers that make up the supply chain.
What the SixMap Study Found
SixMap scanned all 65,535 ports across roughly 40,000 IP addresses. The picture was not reassuring.
Across 21 energy organizations, SixMap identified 58,862 internet-exposed services and 5,756 vulnerabilities, including 377 actively exploited in the wild and 43 systemic flaws present in at least 45% of the companies.
About 7% of those exposed services, nearly 4,000 of them, were running on non-standard ports that fall outside the scope of a typical scan, which usually checks only the top 1,000 to 5,000 ports. That is the core problem: the flaws were not always hidden by sophistication, they were hidden by location. The spread between firms was wide too. One organization had zero external vulnerabilities, while an outlier carried 2,875, many from outdated Apache web servers running across multiple hosts.
How attackers exploit these gaps. The unmonitored surface gives intruders room to work, and they use it in predictable ways:
- Hunting obscure ports. Services on unusual ports like 21098 and 41094 sit outside routine scans and go unnoticed.
- Reusing known flaws. Attackers lean on well-documented vulnerabilities in SSH, HTTP, SMTP, and DNS services.
- Targeting IPv6. IPv6 assets stay invisible to tools that only watch IPv4, and every firm in the study had them.
- Finding shadow IT. Systems the security team does not know about are the ones nobody is patching.
- Automating the search. Bots continuously scan the internet for the unpatched systems these gaps expose.
A standout example was CVE-2023-38408, a critical SSH vulnerability tied to the North Korea-linked group Silent Chollima, found in 16 of the 21 companies assessed.
The Threat Actors Behind the Attacks
The study tied the exposed flaws to named state-sponsored and criminal groups, not hypothetical risk.
SixMap linked the vulnerabilities to active threat groups from North Korea, Russia, and China, a mix of state-sponsored spies seeking intelligence and financially motivated criminals seeking disruption and ransom.
- Silent Chollima (North Korea). A state-sponsored group active since 2007, originally focused on espionage and increasingly running financially motivated extortion against government, defense, energy, and aerospace targets.
- ExCobalt (Russia). A financially motivated crew known for hitting financial institutions and ATM networks through social engineering and custom malware.
- Ethereal Panda (China). A state-sponsored APT focused on cyber-espionage against defense, technology, and government organizations through large-scale intelligence gathering.
- Ryuk Ransomware Group (Russia). A notorious ransomware operation that has disrupted hospitals, municipalities, and major companies worldwide for extortion.
The energy sector's interconnected nature is what makes this dangerous. A successful attack on one provider can cascade through the supply chain, and the 43 vulnerabilities shared across at least 45% of the firms mean a single exploit could hit many operators at once.
What Houston Energy Businesses Must Do Now
The remediation list is not exotic. It is visibility plus disciplined patching.
The fix is to see your entire external attack surface, including non-standard ports and IPv6, then patch the known-exploited flaws first, because those are the ones already under attack.
The findings hit every part of Houston's energy economy: oil and gas producers and refiners, power generation facilities, pipeline operators, energy service providers, and the small and mid-sized businesses that support them and often lack a large security team. Here is the priority list the study points to:
- Scan all 65,535 ports. Not just the common few thousand. Complete port visibility is the only way to find the services hiding where attackers look.
- Discover your IPv6 assets. Every firm in the study had IPv6 in use, many without realizing it. If you are not monitoring it, you cannot defend it.
- Patch known-exploited CVEs first. The 377 actively exploited flaws are the highest risk. A vulnerability with known exploitation should never sit on your external surface.
- Hunt for shadow IT. Find the forgotten systems running outdated software before an automated scanner does.
- Assess the surface regularly. External exposure changes constantly, so a one-time scan is not enough. Reassess on a schedule.
- Feed in threat intelligence. Track which flaws active groups are exploiting so you prioritize the ones that matter this week.
The scary part of this study is not that the flaws were advanced. It is that they were known, exploitable, and sitting in the ports and IPv6 addresses nobody was watching. You cannot patch what you cannot see, and most tools were not looking in the right places.
See Your Whole Attack Surface Before Attackers Do
CinchOps monitors every port and protocol, discovers the IPv6 and shadow-IT assets ordinary tools miss, and prioritizes the known-exploited flaws, as part of your cybersecurity program for Houston energy businesses.
Explore CinchOps cybersecurity services →How CinchOps Helps Secure Houston Energy Businesses
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
- Through cybersecurity services, we monitor across all ports and protocols, including the IPv6 and shadow-IT assets that traditional scans miss, and prioritize vulnerabilities known to be exploited.
- With managed IT support and 24/7 monitoring, we watch your infrastructure for threats and respond before they cause damage.
- Backed by Houston IT support, we bring local expertise that understands the operational realities of energy-sector businesses.
- Through business continuity and disaster recovery, we make sure an incident does not become an extended outage.
You do not have to be a major refiner to be a target; automated attacks do not check your size first. If you cannot say for certain what your external attack surface looks like, that is the place to start. Talk to CinchOps about an external attack-surface assessment for your Houston business.
Frequently Asked Questions
What did the SixMap energy sector study find?
SixMap assessed the external attack surfaces of 21 major US energy companies and found 58,862 internet-exposed services and 5,756 vulnerabilities. Of those, 377 were actively exploited in the wild and 43 were systemic flaws present in at least 45% of the organizations, many hidden on non-standard ports and IPv6 assets.
Why do traditional security scans miss these vulnerabilities?
Most attack-surface tools scan only the top 1,000 to 5,000 ports and focus on IPv4. The SixMap study scanned all 65,535 ports and found roughly 4,000 services on non-standard ports, plus an average of 107 IPv6 assets per company, that fall into the blind spots ordinary scans never check.
Which threat actors are targeting the energy sector?
The study tied exposed flaws to Silent Chollima (North Korea), ExCobalt (Russia), Ethereal Panda (China), and the Ryuk ransomware group (Russia). The mix spans state-sponsored espionage and financially motivated extortion, and one North Korea-linked SSH flaw, CVE-2023-38408, appeared in 16 of the 21 firms.
Does this affect small energy businesses in Houston?
Yes. Automated attacks do not check a company's size, and smaller engineering firms, contractors, and service providers often have fewer security resources than large operators. Because the energy sector is interconnected, a breach at a small supplier can cascade into the larger supply chain.
What should a Houston energy business do first?
Get full visibility into your external attack surface, scan all ports, discover IPv6 assets, and find shadow IT, then patch the known-exploited vulnerabilities first. A vulnerability with active exploitation should never remain on your internet-facing systems.