Security1 publisher2 min readPublished
Kiteworks asked customers to go offline for nine hours over a federal threat tip
Kiteworks told customers to take systems offline for nine hours over a federal tip of possible targeting, then lifted the advisory on September 27. Operators running their own copies on-premises or in AWS and Azure had to carry out the shutdown themselves.
The Watch · Security desk

What happened
- Kiteworks calls the shutdown precautionary and says it has no indication that its own systems or customer environments were compromised.
- The shutdown window fell on a weekend, and each customer was told to follow it in its own local time zone.
- Kiteworks says every system it hosts on behalf of customers has been restored and is operating normally.
- The company says the threat does not affect its subsidiaries, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Teams that self-host Kiteworks in AWS or Azure need a tested runbook for stopping and restarting every instance on the vendor's schedule, because the vendor only acts on the systems it hosts.
- cost Customers that complied gave up nine hours of weekend service as a precaution, and the vendor reports no indication that anyone was compromised.
- constraint With no actor or technique disclosed, defenders have no indicators to search their logs for, so upgrading to 9.5.1 is the only step the company has published.
Kiteworks says its 9.5.1 release addresses all known vulnerabilities, and it continues to recommend that customers run the latest version [7]. Version status is the one control the company has published [7]. A self-hosted instance on an older build is behind it [7].
The tip is known only through Kiteworks. According to the company, federal intelligence authorities passed it information that a threat actor may attempt to target some Kiteworks systems [2]. Frank Balonis, Kiteworks' chief information security officer, said the company notified customers directly after receiving the intelligence and recommended the precaution while it continued to work with those authorities [14]. That account is a paraphrase in the reporting, not a direct quote. Kiteworks has not named the suspected actor or described how the targeting could have occurred [8]. On that record, there is no way to tell a one-off attempt from a sustained campaign [8].
The work split along hosting lines [4]. Kiteworks said it would carry out the shutdown itself for systems it hosts [4]. The specific hours reached customers in an email advisory [13]. For a team with Kiteworks in its own AWS or Azure accounts, compliance depended on someone reading that email and stopping every instance inside the window, on the local clock [3][4].
Coming back was also partly on the customer. Customers that had not already restarted were cleared to bring their systems back online once the advisory was lifted [15]. Those running self-hosted Advanced Forms were asked to contact Customer Support for help [12].
What to watch
- Any federal agency statement, or further Kiteworks disclosure, that names the suspected actor or the targeted component.
- A CVE or security bulletin tied to the 9.5.1 release that shows which flaws it closed.
- A second shutdown advisory, or any customer report of compromise linked to this tip.