Kiteworks Tells Customers to Shut Down Their Servers Over Law Enforcement Warning of an 'Imminent' Zero-Day Attack
Kiteworks Tells Customers to Shut Down Their Servers Over Law Enforcement Warning of an 'Imminent' Zero-Day Attack
Kiteworks — the file transfer and sensitive data exchange platform formerly known as Accellion — is urging customers to shut down their systems after receiving what its CISO calls "credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers." The warning, first reported by German publication Heise, cites an email to customers describing an "imminent" attack that could happen as soon as this weekend.
Kiteworks CISO Frank Balonis confirmed the advisory to TechCrunch: "Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter. We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach." The company did not say which law enforcement agency provided the intelligence or which hacking group may be behind the threat. The FBI declined to comment, and CISA did not immediately respond.
The unusual part is the reasoning: the customer email says Kiteworks is concerned about exploitation of vulnerabilities unknown to the company itself — zero-day flaws — and urges customers to shut down before the weekend "to protect against any potential zero-day attacks" because the company "cannot confirm whether there are other potential routes for improper access." All known vulnerabilities are fixed in the latest release, 9.5.1. Kiteworks reports thousands of customers across healthcare, technology, education, automotive and government; security researcher Kevin Beaumont pointed to listings of at least a thousand internet-facing Kiteworks systems (likely an overcount of affected customers). One healthcare customer that received the alert took its server down immediately — causing delays and disruption to doctors' ability to contact patients.
The company knows this scenario from the inside. Before its late-2021 rebrand, a vulnerability in Accellion's FTA file transfer application allowed an extortion gang to mass-hack hundreds of organizations, stealing previously transferred data and holding it for ransom — part of a broader campaign against file transfer products that made the category a standing target.
What Should You Do?
- If you run Kiteworks: follow the advisory — schedule the precautionary shutdown window, and bring systems back only on release 9.5.1 or later with all known fixes applied.
- Before restart: rotate credentials, review logs for signs of improper access, and confirm the appliance is not exposed to the public internet unless there is a business reason that survives this week.
- If you operate any file transfer or MFT appliance: pre-plan the "power-off" playbook now — who approves it, what business processes break, what the fallback is. Kiteworks customers had hours, not weeks.
- Healthcare and regulated users: weigh the real cost of patient-contact outages against a mass data theft scenario — and put that calculus in writing before the next advisory arrives.
The WAF Angle
A vendor telling customers to turn a product off is the loudest possible admission of a hard truth: some appliances should never have been internet-facing in the first place. File transfer platforms are a recurring mass-breach vector — Accellion's own FTA history is the canonical example — because they combine long-lived sensitive data, public exposure and a large parsing attack surface. A WAF in front of an MFT appliance is genuinely useful against known exploit patterns, but a zero-day carrying a law enforcement warning is a containment scenario, not a filtering scenario. The durable fix is architectural: put these systems behind VPN or zero-trust access, keep them off the public internet, and make shutdown-and-patch something you can execute in an afternoon instead of during a crisis.