In an email sent to customers on Friday, Kiteworks warned of an “imminent” attack that could exploit vulnerabilities currently unknown to the company — so-called zero-day flaws — and recommended a precautionary shutdown window. The company’s chief information security officer, Frank Balonis, told TechCrunch that Kiteworks “received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
Kiteworks declined to identify the law enforcement agency or the hacking group believed to be behind the threat. The FBI and the U.S. cybersecurity agency CISA did not respond to requests for comment.
The company said it has fixed all known vulnerabilities in its latest software release, version 9.5.1, which it recommends all customers use. However, the email warned that Kiteworks cannot confirm whether there are other potential routes for improper access, leading to the drastic shutdown recommendation.
One customer in the healthcare sector, who asked not to be publicly named, told TechCrunch that they took down their organization’s server immediately after receiving the alert. The outage is causing delays and disruption to doctors’ ability to contact patients.
Kiteworks has thousands of customers across healthcare, technology, education, automotive, and government. Security researcher Kevin Beaumont noted that at least a thousand internet-facing Kiteworks systems are visible online, though that figure likely overcounts affected customer systems.
The company is no stranger to cyberattacks. Prior to its rebrand from Accellion in late 2021, a vulnerability in its file-transfer application was exploited by an extortion gang, leading to mass data theft from numerous organizations.