Skip to content

Security5 publishers2 min readPublished Updated

Kiteworks tells customers to shut down even internal file-sharing servers for six hours

Kiteworks told customers worldwide to power off its file-sharing servers for six hours on September 26 after a federal warning of a possible attack. Servers with no internet exposure are included, so being on release 9.5.1 with every known fix does not by itself clear a customer.

The Watch · Security desk

Illustration accompanying Kiteworks tells customers to shut down even internal file-sharing servers for six hours

What happened

  • Kiteworks asked customers to shut down its servers for six hours on Saturday, September 26, from 4 to 10 a.m. in Central Europe and from 10 p.m. Friday to 4 a.m. Saturday in New York.
  • The company said federal intelligence authorities warned it that a threat actor may try to target some customers' Kiteworks systems.
  • Heise reported that Kiteworks wants servers off before the window starts, including servers that cannot be reached from the internet.
  • Kiteworks did not answer follow-up questions on whether a CVE exists or which group is behind the threat.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction The support desk's zero-day explanation and the CISO's claim that every known flaw is fixed are both true only if the threat is unknown or undisclosed, so a fully patched customer cannot assume it is covered.
  • exposure Because servers behind the firewall are in scope, a customer cannot rule itself out by showing its Kiteworks instance has no public address.
  • constraint The shutdown covers six hours. Restarted servers run the same code as before, so protection after Saturday depends on a fix or indicators Kiteworks has not published.
  • precedent If file-transfer flaws spread the way Knott describes, the first public technical detail will bring indiscriminate exploitation, and customers who restarted without a fix will be in its path.

"We strongly recommend you shut down your Kiteworks system for six hours," the customer notification reportedly states [6]. Heise reported that the email, from chief information security officer Frank Balonis, cited law enforcement intelligence "indicating an attack on Kiteworks systems may be imminent this weekend" [5]. Kiteworks sells file-transfer and communications products to government organizations, financial institutions and enterprises [20].

Kiteworks staff have explained the shutdown in two ways [10][9]. A customer support official told Heise: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks." [10] Balonis told Recorded Future News: "All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version." [9] BleepingComputer noted that neither the company statement nor the customer notification confirms that a zero-day has been discovered or exploited [11]. The FBI declined to comment and CISA did not respond, according to Recorded Future News [13].

Nick DiCola, chief AI security and customer officer at Zero Networks, took the internal-server instruction as a clue to the threat. "If the company is saying 'shut it down' even if it's not exposed, then you have to assume the Zero-Day is something already running on the system and has a C2 channel waiting for a command to 'execute,'" he wrote in an email to SC Media [18]. DiCola was reasoning from the wording of the notice. Balonis said: "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach." [8]

Kiteworks used to be Accellion [14]. In December 2020, Clop used a zero-day in Accellion's file transfer tool to steal data from dozens of companies, among them Kroger, Bombardier and Flagstar Bank [14]. The gang's record of data-theft campaigns against enterprise file platforms also includes GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo and MOVEit Transfer [15]. No actor has been publicly linked to this weekend's warning [15].

Jake Knott of watchTowr said his firm is tracking the threat, and that "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch" [16]. He also told SC Media that suggesting a shutdown "is both unusual and never a good sign, especially when the remediation is the power button" [19]. "Vulnerabilities impacting MFT appliances rarely remain a secret for long, and typically rapidly accelerate from targeted exploitation to indiscriminate, in-the-wild exploitation, with both researchers and attackers likely already throwing the codebase through their favorite LLMs," Knott said [17].

What to watch

  • A Kiteworks advisory with a CVE number or a release after 9.5.1, either of which would confirm a flaw outside the set the company calls known.
  • An FBI or CISA statement naming the actor, or a CISA Known Exploited Vulnerabilities entry for a Kiteworks product.
  • Leak-site claims from Clop or another group naming Kiteworks customers after the September 26 window.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories