Kiteworks Warns of Imminent Cyberattack, Urges Server Shutdown

▼ Summary
– Kiteworks has advised customers to immediately shut down their systems following credible threat intelligence from law enforcement regarding potential imminent cyberattacks.
– The company confirmed that the advisory is preventative rather than a response to a confirmed breach, citing concerns about unknown zero-day vulnerabilities being exploited.
– Kiteworks recommended that all users upgrade to software version 9.5.1, which addresses all known vulnerabilities, while maintaining the precautionary shutdown window.
– The alert has caused operational disruptions for some clients, including healthcare providers who faced delays in contacting patients due to immediate server takedowns.
– Although the specific hacking group and law enforcement agency involved were not named, the threat affects thousands of customers across various sectors including government and education.
Kiteworks, the enterprise file transfer platform formerly known as Accellion, has issued an urgent directive to its user base to shut down their systems immediately. This drastic measure follows the receipt of credible intelligence suggesting that hackers are preparing to target the company’s infrastructure. The alert, which was first reported by the German publication Heise, warns of a potential cyberattack that could occur as soon as this weekend.
Frank Balonis, the chief information security officer at Kiteworks, confirmed to TechCrunch that the company had proactively notified its clients regarding the specific threat. Balonis emphasized that the advisory is a preventative step rather than a reaction to a confirmed breach.
“Received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers,” Balonis stated. “Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter.”
He further clarified that the company is not aware of any current compromises to its systems. The primary concern revolves around the potential exploitation of zero-day flaws, which are vulnerabilities unknown to the vendor until they are actively exploited. Because these bugs offer no time for patching before attackers strike, Kiteworks cannot guarantee that other routes for improper access do not exist. Consequently, the company urges customers to take their servers offline before the weekend to mitigate risk.
While Balonis noted that all known vulnerabilities have been addressed in the latest software release, version 9.5.1, he did not specify which law enforcement agency provided the intelligence or which hacking group might be behind the threat. Requests for comment from the FBI and the U. S. Cybersecurity and Infrastructure Security Agency (CISA) regarding the alert were not returned.
The scale of the potential impact remains difficult to quantify precisely. Kiteworks serves thousands of clients across diverse sectors, including healthcare, education, automotive, and government. Security researcher Kevin Beaumont identified a listing of at least a thousand internet-facing Kiteworks systems online, though this figure likely overcounts the actual number of affected customer environments.
For those already using the service, the disruption is immediate. One healthcare professional, who requested anonymity, reported taking down their organization’s server immediately upon receiving the alert. The individual noted that the outage is causing significant delays and hindering doctors’ ability to contact patients, highlighting the operational risks associated with such a broad shutdown recommendation.
This incident adds to Kiteworks’ troubled history with cybersecurity. Before rebranding from Accellion in late 2021, the company suffered a massive data breach where an extortion gang exploited a vulnerability in its file-transfer application. That campaign targeted hundreds of organizations, stealing sensitive data sent over the internet and holding it for ransom. The attackers aimed to exfiltrate copies of previously transmitted data that remained on the servers, threatening public release if victims refused to pay.
(Source: TechCrunch)




