Security5 publishers2 min readPublished Updated
Kiteworks tells customers to shut down even internal file-sharing servers for six hours
Kiteworks told customers worldwide to power off its file-sharing servers for six hours on September 26 after a federal warning of a possible attack. Servers with no internet exposure are included, so being on release 9.5.1 with every known fix does not by itself clear a customer.
The Watch · Security desk

What happened
- Kiteworks asked customers to shut down its servers for six hours on Saturday, September 26, from 4 to 10 a.m. in Central Europe and from 10 p.m. Friday to 4 a.m. Saturday in New York.
- The company said federal intelligence authorities warned it that a threat actor may try to target some customers' Kiteworks systems.
- Heise reported that Kiteworks wants servers off before the window starts, including servers that cannot be reached from the internet.
- Kiteworks did not answer follow-up questions on whether a CVE exists or which group is behind the threat.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction The support desk's zero-day explanation and the CISO's claim that every known flaw is fixed are both true only if the threat is unknown or undisclosed, so a fully patched customer cannot assume it is covered.
- exposure Because servers behind the firewall are in scope, a customer cannot rule itself out by showing its Kiteworks instance has no public address.
- constraint The shutdown covers six hours. Restarted servers run the same code as before, so protection after Saturday depends on a fix or indicators Kiteworks has not published.
- precedent If file-transfer flaws spread the way Knott describes, the first public technical detail will bring indiscriminate exploitation, and customers who restarted without a fix will be in its path.
"We strongly recommend you shut down your Kiteworks system for six hours," the customer notification reportedly states [6]. Heise reported that the email, from chief information security officer Frank Balonis, cited law enforcement intelligence "indicating an attack on Kiteworks systems may be imminent this weekend" [5]. Kiteworks sells file-transfer and communications products to government organizations, financial institutions and enterprises [20].
Kiteworks staff have explained the shutdown in two ways [10][9]. A customer support official told Heise: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks." [10] Balonis told Recorded Future News: "All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version." [9] BleepingComputer noted that neither the company statement nor the customer notification confirms that a zero-day has been discovered or exploited [11]. The FBI declined to comment and CISA did not respond, according to Recorded Future News [13].
Nick DiCola, chief AI security and customer officer at Zero Networks, took the internal-server instruction as a clue to the threat. "If the company is saying 'shut it down' even if it's not exposed, then you have to assume the Zero-Day is something already running on the system and has a C2 channel waiting for a command to 'execute,'" he wrote in an email to SC Media [18]. DiCola was reasoning from the wording of the notice. Balonis said: "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach." [8]
Kiteworks used to be Accellion [14]. In December 2020, Clop used a zero-day in Accellion's file transfer tool to steal data from dozens of companies, among them Kroger, Bombardier and Flagstar Bank [14]. The gang's record of data-theft campaigns against enterprise file platforms also includes GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo and MOVEit Transfer [15]. No actor has been publicly linked to this weekend's warning [15].
Jake Knott of watchTowr said his firm is tracking the threat, and that "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch" [16]. He also told SC Media that suggesting a shutdown "is both unusual and never a good sign, especially when the remediation is the power button" [19]. "Vulnerabilities impacting MFT appliances rarely remain a secret for long, and typically rapidly accelerate from targeted exploitation to indiscriminate, in-the-wild exploitation, with both researchers and attackers likely already throwing the codebase through their favorite LLMs," Knott said [17].
What to watch
- A Kiteworks advisory with a CVE number or a release after 9.5.1, either of which would confirm a flaw outside the set the company calls known.
- An FBI or CISA statement naming the actor, or a CISA Known Exploited Vulnerabilities entry for a Kiteworks product.
- Leak-site claims from Clop or another group naming Kiteworks customers after the September 26 window.