Skip to content
News briefSC-2026-0321

Kiteworks tells customers to switch off for six hours

Kiteworks cites credible intelligence from federal authorities and calls the Saturday shutdown preventive, not a response to a known breach.

2 minEnterprise CyberSecFresh · 25 Sept

Kiteworks, whose software is widely used for secure or confidential communication, has emailed customers recommending that they shut their systems down for a six-hour window on Saturday. The message was first reported by the German outlet Heise; The Record then obtained a statement from the company's chief information security officer, Frank Balonis.

Balonis said Kiteworks had received credible threat intelligence from federal intelligence authorities that a threat actor may attempt to target some Kiteworks systems run for customers. He described the shutdown as a precaution while the company and its law-enforcement partners work through the matter, and said Kiteworks is not aware of any compromise of its systems. According to him, all known vulnerabilities are addressed in the current release, 9.5.1.

What is missing is as telling as what was said. Kiteworks did not answer follow-up questions on whether the issue has a CVE or which groups are involved. A customer support official told Heise the email was prompted by a potential zero-day but gave no detail. The FBI declined to comment and CISA did not respond.

The company's history explains the attention a precautionary email draws. Kiteworks was previously Accellion, whose file transfer tool was breached in December 2020 when the Clop group used a zero-day to steal data from dozens of high-profile companies. Jake Knott of watchTowr told The Record that no vendor asks its entire customer base to unplug production systems over a weekend on a hunch, and that attackers' appetite for managed file transfer appliances has not changed along with the name.

For customers, the instruction is short: take the systems down for the recommended window and run the latest version. Everything beyond that, from a CVE to a patch note to attribution, has not been published.

Retold from The Record. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined