Quick Facts
- Kiteworks directed customers to shut down self-managed servers on Sept. 26 after federal intelligence agencies warned of a credible, imminent cyberattack targeting its platform.
- The threat involved a suspected zero-day vulnerability affecting all deployment models and versions, including systems not exposed to the internet.
- As of Sept. 27, the shutdown recommendation was lifted, no breaches were reported, and Kiteworks released version 9.5.1 with patches for all known vulnerabilities.
Secure file transfer company Kiteworks told its customers to take servers offline Sept. 25, after federal intelligence agencies warned that a threat actor was planning an attack on its platform. The company recommended a precautionary nine-hour shutdown of self-managed systems, with a specific six-hour window on Saturday, Sept. 26, from 3 a.m. to 9 a.m. UK time.
Frank Balonis, Kiteworks' CISO, confirmed the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems." Balonis said the company notified customers directly and recommended the shutdown "while we continue to work through the matter with federal intelligence authorities."
The suspected threat involved zero-day vulnerabilities — flaws unknown to the vendor at the time — affecting all deployment models and versions of the Kiteworks platform. The company said in its customer email that it could not confirm whether other routes for unauthorized access existed, prompting the precautionary guidance.
German publication Heise first reported the story, citing a customer email warning of an attack that could occur as soon as that weekend. Security researcher Kevin Beaumont identified at least a thousand internet-facing Kiteworks systems, though he noted that figure likely overcounts affected customer deployments.
The shutdown directive applied globally, touching organizations in healthcare, government, financial services, technology, and media. One healthcare customer told TechCrunch the advisory forced their organization's server offline immediately, causing delays for doctors trying to reach patients. Subsidiaries including Zivver, DRACOON, ownCloud, and 123FormBuilder were not affected.
By Sept. 27, Kiteworks lifted the shutdown recommendation. No customer breaches were reported. The company brought all systems it hosts on customers' behalf back online and cleared remaining customers to restart their own servers. Those running self-hosted Advanced Forms were directed to contact customer support.
Kiteworks released version 9.5.1 and recommended all customers apply the update for protection against known vulnerabilities. The company said all known vulnerabilities have been addressed in the release.
Broader Stakes for Regulated Industries
Kiteworks serves more than 100 million users globally and holds FedRAMP Moderate Authorization since 2017, with FedRAMP High Ready status granted in 2025. That positioning puts federal agencies handling sensitive unclassified data among its customer base.
Security researchers note that managed file transfer products are high-value targets. A Cybernews expert warned that "vulnerabilities impacting MFT appliances rarely remain a secret for long, and typically rapidly accelerate from targeted exploitation to indiscriminate, in-the-wild exploitation."
The company's history adds weight to that concern. Before rebranding from Accellion in late 2021, a vulnerability in its file-transfer product allowed an extortion gang to breach hundreds of organizations, steal sensitive data, and demand ransom payments threatening public disclosure.
The federal government's decision to warn Kiteworks directly, rather than monitor the threat, is itself notable. A private commercial vendor receiving that level of specificity from intelligence agencies — enough to trigger a global coordinated shutdown — reflects an unusual policy judgment that advance disclosure serves national security interests more than silent observation.
Read more: Kiteworks tells users to shut down servers amid fears of 'imminent' cyberattack
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
