
Kiteworks is telling customers to power down their servers after the company received credible warning that attackers may soon target some systems. The unusual advice reflects what the company described as a preventative response to “imminent” threat intelligence, not a confirmed breach of Kiteworks’ own infrastructure.
Kiteworks warns of a possible attack
Kiteworks, the company formerly known as Accellion, makes software used to transfer large files and sensitive data over the internet. It confirmed to TechCrunch that it had notified customers about a potential threat after receiving information suggesting hackers might attempt to target some Kiteworks systems.
The alert was first reported by German publication Heise, which said an email sent by Kiteworks to customers warned of an “imminent” attack that could happen as soon as the weekend. In a statement to TechCrunch on Friday, Kiteworks chief information security officer Frank Balonis said the company had “received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
Balonis said Kiteworks contacted customers “out of an abundance of caution” and recommended a precautionary shutdown window while the company and law enforcement partners investigate. He also stressed that the company is “not aware of any compromise of Kiteworks systems,” and said the advisory is preventative rather than a response to a confirmed intrusion.
Why the company is telling users to shut systems down
According to a copy of the customer email shared with TechCrunch, Kiteworks said it was worried about the exploitation of vulnerabilities that are currently unknown to the company. These are commonly called zero-day flaws because vendors have no opportunity to patch them before they are used in attacks.
In the email, Kiteworks urged customers to shut down their systems before the weekend, if not sooner, in order to “protect against any potential zero-day attacks.” The company said it could not confirm whether there were other possible paths for improper access, which appears to be part of the reason it recommended a full shutdown rather than a more limited mitigation.
Balonis said Kiteworks has already fixed all known vulnerabilities in its latest software release, version 9.5.1, and recommended that customers use it. But the company’s warning suggests its concern is not only about known issues, but also about the possibility of unknown flaws being exploited before they can be identified and patched.
What Kiteworks has and has not said
Kiteworks did not identify which law enforcement agency shared the intelligence, and it did not say which hacking group may be behind the possible threat. TechCrunch said the FBI and the U.S. cybersecurity agency CISA did not respond to requests for comment about the alert.
The lack of named attribution leaves open key questions about the scope and source of the warning. For now, the company’s public position is that it has acted on credible intelligence and is trying to reduce risk before any attack can be confirmed.
What customers were told
- There may be an imminent threat to some Kiteworks systems.
- Customers should consider shutting down their servers before the weekend.
- The advice is precautionary, not a reaction to a confirmed breach.
- Version 9.5.1 is the latest release and contains fixes for known vulnerabilities.
How many customers could be affected
Kiteworks says on its website that it has thousands of customers across healthcare, technology, education, automotive, and government, among other sectors. The company did not say how many may be affected by this latest warning, and it is not yet clear whether the possible threat applies broadly or only to a subset of customers.
Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems online today. However, that figure is likely an overcount of actual affected customer systems, since it may include multiple endpoints, shared infrastructure, or other internet-facing assets that do not correspond one-to-one with distinct organizations.
Even without a precise number, the warning is notable because Kiteworks products are used to move sensitive data, which means any disruption can have operational consequences well beyond the security team handling the alert.
Customer disruption is already being felt
One Kiteworks customer in healthcare told TechCrunch they received the alert and took their organization’s server down immediately. That person asked not to be publicly named, but said the outage is already causing delays and disrupting doctors’ ability to contact their patients.
The account underscores the difficult tradeoff customers face when a vendor recommends an emergency shutdown: keeping systems online may carry security risk, but taking them offline can interrupt critical workflows and communications. For organizations that rely on file transfer and secure messaging platforms, even a temporary shutdown can ripple into day-to-day operations quickly.
Kiteworks and the history of file-transfer attacks
Kiteworks is no stranger to cyber incidents. Before its rebrand from Accellion in late 2021, a vulnerability in its file-transfer application was exploited by an extortion gang that mass-hacked and stole data from hundreds of organizations using the product to send customer or internal corporate information over the internet.
That earlier campaign was part of a broader wave of attacks against file transfer software. The goal was to steal copies of data that had been transferred previously but not deleted from the affected servers. Attackers then tried to extort victims by threatening to publish stolen information unless ransom demands were met.
The new alert does not say that the current situation is connected to that earlier campaign, and TechCrunch’s reporting does not indicate any confirmed breach this time. Still, the company’s decision to tell customers to shut down systems highlights how sensitive file-transfer products can become high-value targets when attackers are believed to have a route into them.
What happens next
For now, Kiteworks customers are being asked to treat the warning seriously while the company and law enforcement work through the threat information. The most immediate question is whether the feared attack materializes, and if so, whether the recommended shutdowns prevent exposure or simply buy time for further investigation.
More broadly, the episode shows how vendors sometimes have to act on imperfect intelligence before every detail is known. In this case, Kiteworks says the advisory is meant to reduce risk in the face of a possible zero-day event, even though the company has not confirmed a breach of its own systems.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 25, 2026 at 10:32 pm
0 views
