Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

LowThe Record·

At a glance

Severity
Low
Used in attacks
No flaws named
Reported by
1 outlet

Software company Kiteworks sent a warning to customers this week urging them to shut off the company’s platform over the weekend due to concerns over potential cyberattacks or intrusions. 

The email to customers, first reported by German news outlet Heise, recommends customers shut down their systems during a six-hour window on Saturday. 

In response to inquiries about the message, Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”

“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter,” Balonis said. 

“We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach. All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version."

Kiteworks did not respond to follow up questions about whether the bug had a CVE yet or what groups are exploiting the platform. The company makes popular software used for secure or confidential communication. 

The FBI declined to comment and the Cybersecurity and Infrastructure Security Agency (CISA) did not respond to requests for comment. 

A Kiteworks customer support official told Heise that the email was sent out due to a potential “zero-day” vulnerability but did not elaborate. 

Kiteworks was previously known as Accellion and operated a popular file transfer tool until an incident in December 2020 where a Russian hacking group known as Clop used a zero-day vulnerability to steal data from dozens of high-profile companies. The organizations breached included the University of Colorado, the Washington State Auditor Office, Flagstar Bank, airplane maker Bombardier, and U.S. retail store chain Kroger.

Jake Knott, a senior official at cybersecurity firm watchTowr, said they are actively tracking the threat but noted how unusual and concerning it is that Kiteworks suggested customers essentially turn off the power on their servers.

“There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch,” he said, noting the past incidents Kiteworks went through under the Accellion name. 

“Whilst years have passed and the name has changed, attackers' appetites for targeting [managed file transfer] appliances has not, and we have no reason to believe this time will be any different. In other words, this is familiar territory, but not the comforting kind.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Originally published by The Record. © The Record.

Read at therecord.media ↗Established Source

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. The Record ↗Established SourceFirst reported

    2026-09-25 20:19 UTC

Related stories

Kiteworks urges customers to stop using platform after warning from federal intelligence agencies | CyberBrief