Kiteworks Urges Customers to Shut Down Servers Over 'Imminent' Cyberattack Threat

File-transfer company says it received credible threat intelligence from law enforcement; no breach confirmed

By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
Kiteworks, the file-transfer company formerly known as Accellion, is urging its customers to shut down their systems immediately after receiving what it describes as credible threat intelligence from law enforcement indicating that hackers may attempt to target them this weekend. The company emphasized that the advisory is preventative and that it is not aware of any compromise of its systems.

In an email sent to customers on Friday, Kiteworks warned of an “imminent” attack that could exploit vulnerabilities currently unknown to the company — so-called zero-day flaws — and recommended a precautionary shutdown window. The company’s chief information security officer, Frank Balonis, told TechCrunch that Kiteworks “received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.”

Kiteworks declined to identify the law enforcement agency or the hacking group believed to be behind the threat. The FBI and the U.S. cybersecurity agency CISA did not respond to requests for comment.

The company said it has fixed all known vulnerabilities in its latest software release, version 9.5.1, which it recommends all customers use. However, the email warned that Kiteworks cannot confirm whether there are other potential routes for improper access, leading to the drastic shutdown recommendation.

One customer in the healthcare sector, who asked not to be publicly named, told TechCrunch that they took down their organization’s server immediately after receiving the alert. The outage is causing delays and disruption to doctors’ ability to contact patients.

Kiteworks has thousands of customers across healthcare, technology, education, automotive, and government. Security researcher Kevin Beaumont noted that at least a thousand internet-facing Kiteworks systems are visible online, though that figure likely overcounts affected customer systems.

The company is no stranger to cyberattacks. Prior to its rebrand from Accellion in late 2021, a vulnerability in its file-transfer application was exploited by an extortion gang, leading to mass data theft from numerous organizations.

§

Analysis

Why This Matters

  • The shutdown advisory affects thousands of organizations across critical sectors including healthcare, where patient communications have already been disrupted.
  • The incident underscores the persistent risk of zero-day vulnerabilities in widely used enterprise software, even after a vendor has released security updates.
  • The level of precaution — urging full system shutdown based on law enforcement intelligence — suggests a credible and serious threat that could have cascading impacts if not contained.

Background

Kiteworks (formerly Accellion) provides secure file-transfer and content collaboration tools used by government agencies, healthcare providers, and large enterprises. The company suffered a major security incident in 2020-2021 when a vulnerability in its legacy Accellion File Transfer Appliance was exploited by the Clop ransomware group, leading to data breaches at hundreds of organizations. The company rebranded as Kiteworks in late 2021. This latest warning is based on threat intelligence from law enforcement rather than a confirmed intrusion.

Key Perspectives

Kiteworks: The company is taking a proactive stance, prioritizing customer security over service continuity. By recommending shutdown, it aims to prevent potential zero-day exploitation before it occurs. It also notes that its latest software version fixes all known vulnerabilities. Customers: One healthcare customer reports that the shutdown is causing real-world disruption, delaying doctor-patient communication. Other customers face similar operational downtime and must balance security risks against business needs. Security Experts: The advisory highlights the difficulty of defending against unknown vulnerabilities. Observers will watch whether any actual exploitation occurs and how quickly law enforcement can neutralize the threat.

What to Watch

  • Whether any customer systems are actually compromised despite the shutdown advisory.
  • When Kiteworks will give the all-clear for customers to resume operations.
  • Further details from law enforcement about the threat actor's identity and motives.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.