Kiteworks urges customers to shut down servers amid threat
Kiteworks alerts thousands of global customers, including healthcare sectors, to shut down servers before the weekend due to an imminent cyber threat.

Stock photo for illustration only, not from the actual event
- Kiteworks alerts customers via email to shut down servers ahead of the weekend.
- The company received credible threat intelligence warning of potential cyberattacks.
- Concerns focus on unknown zero-day vulnerabilities in file-transfer software.
- The alert impacts thousands of users across healthcare, tech, and government.
Technology company Kiteworks is strongly urging its customers to shut down their systems and servers immediately after receiving intelligence that hackers may attempt to target them. The news first emerged from German publication Heise, which cited an email sent by Kiteworks to its customers regarding an imminent attack that could materialize as early as this weekend.
When reached by TechCrunch, Frank Balonis, chief information security officer at Kiteworks, confirmed that the company received credible threat intelligence from law enforcement indicating a threat actor might target specific Kiteworks customer systems. Kiteworks declined to name the specific law enforcement agency or the hacking group behind the alert. Meanwhile, the FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) did not respond to requests for comment regarding the warning.

Stock photo for illustration only, not from the actual event
Balonis noted that while the firm has patched all known vulnerabilities in its latest software release, version 9.5.1, the company remains anxious about potential exploits targeting flaws currently unknown to Kiteworks. These unpatched bugs, commonly known as zero-day vulnerabilities, leave software vendors with zero time to issue fixes before malicious actors exploit them in the wild.
"received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers."
Frank Balonis, Chief Information Security Officer, Kiteworks
In an email shared with TechCrunch, Kiteworks implored clients to power down their systems before the weekend to safeguard against potential zero-day attacks, noting it cannot verify if other unauthorized entry points exist. Although the exact number of impacted customers remains unclear, Kiteworks serves thousands of organizations across healthcare, technology, education, automotive, and government sectors. Security researcher Kevin Beaumont identified at least a thousand internet-facing Kiteworks systems online, though the figure likely overcounts the actual affected deployments.
Forcing a sudden offline shutdown is an extreme yet necessary measure when software vendors confront credible zero-day threats. Because traditional patches do not yet exist for unknown vulnerabilities, severing network access remains the most effective way to prevent threat actors from exfiltrating sensitive data or deploying ransomware, echoing similar past incidents from the company's Accellion era.
Real-world disruptions are already materializing as a healthcare customer told TechCrunch they received the warning and took down their servers instantly, resulting in delays affecting doctors trying to reach patients. Kiteworks, formerly known as Accellion before rebranding in late 2021, is no stranger to security incidents; prior file-transfer application flaws allowed extortion gangs to breach hundreds of organizations, stealing corporate data and threatening public leaks unless ransoms were paid.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment