Kiteworks Urges Customers to Shut Down Systems Amidst Credible Threat Intelligence
Kiteworks has alerted its customers to cease using its platform due to credible threat intelligence from federal agencies indicating a potential targeting by threat actors.

Software company Kiteworks has issued an urgent warning to its customers, advising them to shut down the platform over the weekend due to credible threat intelligence from federal intelligence authorities. The alert, first reported by German news outlet Heise, recommended a six-hour shutdown window on Saturday.
Frank Balonis, CISO at Kiteworks, confirmed the advisory, stating that the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers." He emphasized that the recommendation was made "out of an abundance of caution" while the company and law enforcement partners investigate the matter. Balonis also noted that Kiteworks is not aware of any compromise of its systems and that all known vulnerabilities are addressed in their latest release, version 9.5.1.
Despite the company's assurances that all known vulnerabilities are patched, the unusual nature of the warning has raised concerns. A Kiteworks customer support official reportedly told Heise that the email was sent due to a potential "zero-day" vulnerability, though no specific CVE identifier has been released. The company has not provided further details on the nature of the threat or potential threat actors involved.
The FBI declined to comment on the situation, and the Cybersecurity and Infrastructure Security Agency (CISA) did not respond to requests for comment. This lack of official confirmation from government agencies adds to the uncertainty surrounding the advisory.
Jake Knott, a senior official at cybersecurity firm watchTowr, highlighted the peculiarity of Kiteworks' request for customers to power down their production servers. "There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch," Knott stated. He also drew parallels to past incidents involving Kiteworks, which was formerly known as Accellion.
Kiteworks, previously Accellion, has a history of security incidents. In December 2020, a zero-day vulnerability in its file transfer tool was exploited by the Russian hacking group Clop, leading to data theft from numerous high-profile organizations, including the University of Colorado, the Washington State Auditor Office, and retail chain Kroger.
Knott further commented on the persistent appeal of managed file transfer (MFT) appliances to attackers, stating, "Whilst years have passed and the name has changed, attackers' appetites for targeting managed file transfer appliances has not, and we have no reason to believe this time will be any different. In other words, this is familiar territory, but not the comforting kind."
The current situation underscores the ongoing risks associated with file transfer solutions and the critical importance of timely threat intelligence, even when specific technical details remain undisclosed.