Sat 26 Sep 2026 / 12:21 ET
Kernel
Security 3 min read

Kiteworks urges six-hour server shutdown after threat warning

Kiteworks told customers to take systems offline temporarily after an unspecified law-enforcement threat warning, while saying no compromise is known.

Dana Voss

By Dana Voss / Security Correspondent

Kiteworks urges six-hour server shutdown after threat warning
img: The Record

Kiteworks has urged customers to take their systems offline for a six-hour window after receiving what it described as credible threat intelligence from law enforcement. The kiteworks server shutdown notice is a temporary precaution, not an instruction to abandon the platform or evidence of a confirmed breach.

Frank Balonis, Kiteworks' chief information security officer, told Recorded Future News that a threat actor may attempt to target some customers' Kiteworks systems. He said the company notified customers directly and recommended the shutdown while Kiteworks and its law-enforcement partners worked through the matter.

Kiteworks says it is not aware of any compromise and characterizes the advisory as preventative rather than a response to a confirmed breach. The company also says release 9.5.1 addresses all known vulnerabilities and recommends that customers run the current version.

Why did Kiteworks ask customers to shut down servers?

Reporting by Heise, which obtained the customer email, says the recommended outage was scheduled by region. In Central Europe, the stated window was 4 a.m. to 10 a.m. on Saturday, September 26. BleepingComputer reported a New York window running from 10 p.m. Friday to 4 a.m. Saturday. Heise said Kiteworks also recommended taking systems offline even when they were not directly internet-accessible.

The available reporting does not identify the agency that supplied the warning, the suspected attacker, a vulnerability identifier, or an exploit method. The FBI declined to comment in reporting by Recorded Future News and SC Media. CISA did not respond to Recorded Future News, while a CISA spokesperson would not comment on the record to TechCrunch.

A Kiteworks support representative told Heise that the shutdown request was intended to protect against potential zero-day attacks. That is not confirmation that a zero-day flaw was discovered or exploited. BleepingComputer noted that neither Kiteworks' public statement nor the customer notice cited by Heise established that either had happened.

What is confirmed, and what remains unknown?

  • Confirmed by Kiteworks: it issued a customer alert, recommended a time-limited shutdown, and says it is not aware of a compromise.
  • Confirmed by Kiteworks: version 9.5.1 addresses vulnerabilities the company knows about.
  • Not established: the identity of the notifying agency or threat actor, a CVE, a technical attack path, or a confirmed zero-day exploit.

Kiteworks, formerly Accellion, makes software for secure file transfers and confidential communications. Its older Accellion file-transfer product was hit in a separate 2020 incident involving a zero-day used by the Clop group, according to Recorded Future News. That history does not establish any connection to the current warning.

For administrators, the practical distinction is annoyingly plain: an unspecified threat warning prompted a short shutdown recommendation, while the actual vulnerability, if one exists, remains undisclosed.

This story draws on original reporting from The Record.

More Security/

view all ↗