VMTech
Discuss a project →

Kiteworks Calls for Precautionary Server Shutdowns After Threat Alert

Kiteworks Calls for Precautionary Server Shutdowns After Threat Alert

Kiteworks tells customers to take servers offline

Kiteworks has advised customers to shut down their systems before the weekend, if not sooner, after receiving credible threat intelligence from law enforcement that a threat actor may target some customer deployments. The company, formerly known as Accellion, provides software for transferring large files and sensitive datasets over the internet.

Chief information security officer Frank Balonis told TechCrunch that the notice was precautionary. Kiteworks said it was not aware of any compromise of its systems and described the advisory as a preventative measure rather than a response to a confirmed breach.

The company did not identify the law enforcement agency that provided the intelligence or name a suspected hacking group. The FBI declined to comment, while the U.S. Cybersecurity and Infrastructure Security Agency had not immediately commented on the customer alert.

Concern centres on a potential zero-day route

In an email sent to customers, Kiteworks said it was concerned about the possible exploitation of vulnerabilities unknown to the vendor. Such flaws are generally called zero-days because the supplier has no time to prepare and distribute a fix before exploitation begins.

Kiteworks said it has fixed all known vulnerabilities in its latest release, version 9.5.1, and recommends that customers use it. At the same time, the company said it could not confirm whether other routes for improper access exist, which is why it recommended a shutdown window.

The scale of the potential exposure is unclear. Kiteworks says it serves thousands of customers in sectors including healthcare, technology, education, automotive and government. Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems, while noting that figure may overcount affected customer environments.

Operational consequences can be immediate

One healthcare customer told TechCrunch that it received the alert and immediately took its server offline. The customer said the resulting outage delayed and disrupted doctors' ability to contact patients, illustrating the operational trade-off created by a preventive shutdown.

Kiteworks has faced a major incident before. Before its late-2021 rebrand from Accellion, a flaw in its file-transfer application was used in a mass campaign that stole data from hundreds of organizations. Attackers then sought ransom by threatening to release customer information.

For organizations running Kiteworks, the immediate implication is to establish whether any servers are internet-facing, verify that version 9.5.1 is installed and assess the operational impact of taking systems offline. A controlled response plan should account for the vendor's precautionary guidance while preserving essential business communications and data-transfer processes.

#cybersecurity#zeroday#filetransfer#securityoperations
Open analytics
On the site 3 views
min read 3 25.09.2026
On Instagram 5 views
On Instagram 1 reach
Instagram

Kiteworks Calls for Precautionary Server Shutdowns After Threat Alert

Open the post on Instagram ↗