Then it should stop authorizing Power to do so. Why would it let the credentials work for Power unless those credentials authorized Power access? That's the problem. The simple solution is 2-factor authentication.
This is a solved problem. If you have "open access" of your web services and and access is non-disruptive, I don't know why this should be a criminal violation. It shouldn't be criminal just because it doesn't fit with your business model.