Kiteworks Advises Nine-Hour Precautionary Customer Shutdown

Kiteworks issues precautionary shutdown advice
Kiteworks has advised customers to shut down their systems for a nine-hour window over the weekend after receiving what it described as credible threat intelligence that an actor may attempt to target some Kiteworks systems. The U.S. software company said the recommendation is precautionary and that it has not identified evidence that customer environments have been compromised.
Frank Balonis, Kiteworks’ chief information security officer, said federal intelligence authorities provided the warning. The company notified customers directly and said it is continuing to work through the matter with those authorities. It has also emailed customers with the specific hours and the recommended nine-hour shutdown timeframe.
No confirmed compromise, but patching remains central
Kiteworks did not identify the law-enforcement or intelligence body that provided the alert, nor did it name a suspected threat actor. The lack of attribution means customers have limited public detail about the anticipated method or scope of a potential attack.
The company stressed that all known vulnerabilities have been addressed in its latest release, version 9.5.1. Customers are being urged to apply the available patches for optimal protection. The advice combines an immediate operational measure—a temporary shutdown—with a longer-lived requirement to ensure deployments are running the remediated software.
The advisory affects some Kiteworks systems, rather than every business associated with the company. Kiteworks said its subsidiaries Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder are not affected.
History raises the stakes for file-transfer customers
Kiteworks was formerly known as Accellion. In late 2020 and early 2021, the Clop group, also tracked as UNC2546, exploited multiple zero-day vulnerabilities in the company’s file-transfer software in a campaign involving data theft and extortion against high-profile organizations.
That history does not establish a link to the current intelligence warning, and Kiteworks has not reported a confirmed incident. It does, however, underscore why the company is asking customers to act before a compromise is detected rather than after one has been verified.
Business implication
Organizations using affected Kiteworks systems should verify whether they have received the company’s customer notice, apply version 9.5.1 where required, and plan operational coverage for the specified shutdown period. The practical priority is to follow the vendor’s preventive guidance while preserving business continuity during the advised window.

