I Need IT Support Now
Managed Service Provider Houston Cybersecurity
Shane

SixMap Study Reveals Critical Cybersecurity Gaps in US Energy Sector: Houston Businesses Must Act Now

Your Local Cybersecurity Experts for Energy Sector Protection

Threat Alert
A Study of 21 Energy Firms Found 377 Actively Exploited Flaws. Houston Sits at Ground Zero.

What the SixMap external attack-surface study means for Houston's oil, gas, power, and pipeline businesses, and the smaller firms in their supply chain.

TL;DR
A SixMap study of 21 major US energy companies found 58,862 internet-exposed services and 5,756 vulnerabilities, 377 of them already being exploited by nation-state and criminal groups. Many hid on non-standard ports and IPv6 assets that ordinary scans never check. For Houston, the energy capital, this is a direct warning, and it reaches every SMB in the sector's supply chain.

A SixMap assessment of 21 leading US energy providers found systemic, exploitable weaknesses across the sector's internet-facing systems, and many of them sat in the blind spots that traditional security tools never scan.

Houston is the center of America's energy industry, which makes these findings local news. The study looked at the external attack surface, the systems any attacker can reach from the internet, and found thousands of exposed services and known-exploited flaws hiding on unusual ports and IPv6 addresses. You do not have to be a Fortune 500 refiner for this to matter; the same gaps show up in the smaller engineering firms, contractors, and service providers that make up the supply chain.

The short version: The dangerous vulnerabilities were not exotic. They were known, exploitable flaws sitting in places standard scans skip. The fix is visibility across your whole attack surface, and fast patching of anything already being exploited.

What the SixMap Study Found

SixMap scanned all 65,535 ports across roughly 40,000 IP addresses. The picture was not reassuring.

Across 21 energy organizations, SixMap identified 58,862 internet-exposed services and 5,756 vulnerabilities, including 377 actively exploited in the wild and 43 systemic flaws present in at least 45% of the companies.

SIXMAP ENERGY SECTOR STUDY 21 Firms, One Exposed Surface 58,862 internet-exposed services found 5,756 total vulnerabilities across all firms 377 actively exploited in the wild 43 systemic flaws in 45%+ of companies 107 IPv6 assets per firm, often unmonitored 16 of 21 firms exposed to one NK-linked SSH flaw Source: SixMap · Visualized by CinchOps

About 7% of those exposed services, nearly 4,000 of them, were running on non-standard ports that fall outside the scope of a typical scan, which usually checks only the top 1,000 to 5,000 ports. That is the core problem: the flaws were not always hidden by sophistication, they were hidden by location. The spread between firms was wide too. One organization had zero external vulnerabilities, while an outlier carried 2,875, many from outdated Apache web servers running across multiple hosts.

Chart of vulnerabilities found by company in the SixMap energy sector study
Vulnerabilities by company. Source: SixMap.

How attackers exploit these gaps. The unmonitored surface gives intruders room to work, and they use it in predictable ways:

  • Hunting obscure ports. Services on unusual ports like 21098 and 41094 sit outside routine scans and go unnoticed.
  • Reusing known flaws. Attackers lean on well-documented vulnerabilities in SSH, HTTP, SMTP, and DNS services.
  • Targeting IPv6. IPv6 assets stay invisible to tools that only watch IPv4, and every firm in the study had them.
  • Finding shadow IT. Systems the security team does not know about are the ones nobody is patching.
  • Automating the search. Bots continuously scan the internet for the unpatched systems these gaps expose.

A standout example was CVE-2023-38408, a critical SSH vulnerability tied to the North Korea-linked group Silent Chollima, found in 16 of the 21 companies assessed.

The eight services most commonly found to be vulnerable to attack in the SixMap study
The eight most commonly vulnerable services. Source: SixMap.
Breakdown of vulnerabilities by severity in the SixMap energy sector study
Vulnerabilities by severity. Source: SixMap.

The Threat Actors Behind the Attacks

The study tied the exposed flaws to named state-sponsored and criminal groups, not hypothetical risk.

SixMap linked the vulnerabilities to active threat groups from North Korea, Russia, and China, a mix of state-sponsored spies seeking intelligence and financially motivated criminals seeking disruption and ransom.

  • Silent Chollima (North Korea). A state-sponsored group active since 2007, originally focused on espionage and increasingly running financially motivated extortion against government, defense, energy, and aerospace targets.
  • ExCobalt (Russia). A financially motivated crew known for hitting financial institutions and ATM networks through social engineering and custom malware.
  • Ethereal Panda (China). A state-sponsored APT focused on cyber-espionage against defense, technology, and government organizations through large-scale intelligence gathering.
  • Ryuk Ransomware Group (Russia). A notorious ransomware operation that has disrupted hospitals, municipalities, and major companies worldwide for extortion.
Threat actor activity mapped against energy sector vulnerabilities in the SixMap study
Threat actor activity. Source: SixMap.

The energy sector's interconnected nature is what makes this dangerous. A successful attack on one provider can cascade through the supply chain, and the 43 vulnerabilities shared across at least 45% of the firms mean a single exploit could hit many operators at once.

What Houston Energy Businesses Must Do Now

The remediation list is not exotic. It is visibility plus disciplined patching.

The fix is to see your entire external attack surface, including non-standard ports and IPv6, then patch the known-exploited flaws first, because those are the ones already under attack.

The findings hit every part of Houston's energy economy: oil and gas producers and refiners, power generation facilities, pipeline operators, energy service providers, and the small and mid-sized businesses that support them and often lack a large security team. Here is the priority list the study points to:

  • Scan all 65,535 ports. Not just the common few thousand. Complete port visibility is the only way to find the services hiding where attackers look.
  • Discover your IPv6 assets. Every firm in the study had IPv6 in use, many without realizing it. If you are not monitoring it, you cannot defend it.
  • Patch known-exploited CVEs first. The 377 actively exploited flaws are the highest risk. A vulnerability with known exploitation should never sit on your external surface.
  • Hunt for shadow IT. Find the forgotten systems running outdated software before an automated scanner does.
  • Assess the surface regularly. External exposure changes constantly, so a one-time scan is not enough. Reassess on a schedule.
  • Feed in threat intelligence. Track which flaws active groups are exploiting so you prioritize the ones that matter this week.
The scary part of this study is not that the flaws were advanced. It is that they were known, exploitable, and sitting in the ports and IPv6 addresses nobody was watching. You cannot patch what you cannot see, and most tools were not looking in the right places.
Shane Stevens, CEO, CinchOps - LinkedIn

See Your Whole Attack Surface Before Attackers Do

CinchOps monitors every port and protocol, discovers the IPv6 and shadow-IT assets ordinary tools miss, and prioritizes the known-exploited flaws, as part of your cybersecurity program for Houston energy businesses.

Explore CinchOps cybersecurity services →

How CinchOps Helps Secure Houston Energy Businesses

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

  • Through cybersecurity services, we monitor across all ports and protocols, including the IPv6 and shadow-IT assets that traditional scans miss, and prioritize vulnerabilities known to be exploited.
  • With managed IT support and 24/7 monitoring, we watch your infrastructure for threats and respond before they cause damage.
  • Backed by Houston IT support, we bring local expertise that understands the operational realities of energy-sector businesses.
  • Through business continuity and disaster recovery, we make sure an incident does not become an extended outage.

You do not have to be a major refiner to be a target; automated attacks do not check your size first. If you cannot say for certain what your external attack surface looks like, that is the place to start. Talk to CinchOps about an external attack-surface assessment for your Houston business.

100% Free

Free Cybersecurity Assessment

Find out what your business looks like from the outside. Get a FREE external attack-surface review that finds exposed services, IPv6 assets, and known-exploited flaws before attackers do.

Get Your Free Assessment

Frequently Asked Questions

What did the SixMap energy sector study find?

SixMap assessed the external attack surfaces of 21 major US energy companies and found 58,862 internet-exposed services and 5,756 vulnerabilities. Of those, 377 were actively exploited in the wild and 43 were systemic flaws present in at least 45% of the organizations, many hidden on non-standard ports and IPv6 assets.

Why do traditional security scans miss these vulnerabilities?

Most attack-surface tools scan only the top 1,000 to 5,000 ports and focus on IPv4. The SixMap study scanned all 65,535 ports and found roughly 4,000 services on non-standard ports, plus an average of 107 IPv6 assets per company, that fall into the blind spots ordinary scans never check.

Which threat actors are targeting the energy sector?

The study tied exposed flaws to Silent Chollima (North Korea), ExCobalt (Russia), Ethereal Panda (China), and the Ryuk ransomware group (Russia). The mix spans state-sponsored espionage and financially motivated extortion, and one North Korea-linked SSH flaw, CVE-2023-38408, appeared in 16 of the 21 firms.

Does this affect small energy businesses in Houston?

Yes. Automated attacks do not check a company's size, and smaller engineering firms, contractors, and service providers often have fewer security resources than large operators. Because the energy sector is interconnected, a breach at a small supplier can cascade into the larger supply chain.

What should a Houston energy business do first?

Get full visibility into your external attack surface, scan all ports, discover IPv6 assets, and find shadow IT, then patch the known-exploited vulnerabilities first. A vulnerability with active exploitation should never remain on your internet-facing systems.

Discover More

Sources

Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including senior roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506