Kiteworks Urges Customers to Shut Down Systems Amid Imminent Cyberattack Threat
Kiteworks, a technology firm specializing in secure file transfers for sensitive datasets, has advised customers to temporarily shut down their systems following credible threat intelligence from law enforcement. The warning, first reported by German publication Heise, indicates that hackers may target Kiteworks systems as early as this weekend.
In a statement to TechCrunch, Kiteworks CISO Frank Balonis confirmed the company received intelligence suggesting a potential attack but emphasized that no breach has been detected. The advisory is precautionary, with Kiteworks recommending a shutdown to mitigate risks from possible zero-day vulnerabilities flaws unknown to the vendor that could be exploited before patches are available.
The company has released software version 9.5.1, which addresses all known vulnerabilities, but remains concerned about undiscovered exploits. While Kiteworks did not disclose the specific law enforcement agency or threat group involved, the FBI declined to comment, and CISA did not respond to inquiries.
Kiteworks serves thousands of customers across healthcare, government, education, and other sectors. Security researcher Kevin Beaumont identified over a thousand internet-facing Kiteworks systems, though the exact number of affected organizations remains unclear. One healthcare customer reported immediate disruptions after taking their server offline, impacting doctors’ ability to communicate with patients.
This incident follows a 2021 breach under Kiteworks’ former name, Accellion, where a file-transfer vulnerability was exploited to steal and extort data from hundreds of organizations. The current threat appears to be part of a broader trend targeting file-transfer tools for ransomware and data theft.
Kiteworks TPRM report: https://www.rankiteo.com/company/kiteworkscgcp
Accellion TPRM report: https://www.rankiteo.com/company/kiteworkscgcp
"id": "kit1790360656",
"linkid": "kiteworkscgcp",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Healthcare, government, '
'education, and other sectors',
'industry': 'Secure File Transfers',
'name': 'Kiteworks',
'size': 'Thousands of customers',
'type': 'Technology Firm'}],
'attack_vector': 'Zero-day vulnerabilities',
'customer_advisories': 'Temporary shutdown recommended to mitigate risks',
'data_breach': {'sensitivity_of_data': 'Sensitive datasets'},
'description': 'Kiteworks, a technology firm specializing in secure file '
'transfers for sensitive datasets, has advised customers to '
'temporarily shut down their systems following credible threat '
'intelligence from law enforcement. The warning indicates that '
'hackers may target Kiteworks systems as early as this weekend '
'due to possible zero-day vulnerabilities.',
'impact': {'downtime': 'Immediate disruptions reported by customers',
'operational_impact': 'Impacted doctors’ ability to communicate '
'with patients',
'systems_affected': 'Over a thousand internet-facing Kiteworks '
'systems'},
'investigation_status': 'Ongoing',
'motivation': 'Ransomware and data theft',
'post_incident_analysis': {'corrective_actions': 'Release of software patch '
'(version 9.5.1)',
'root_causes': 'Possible zero-day vulnerabilities '
'in Kiteworks systems'},
'recommendations': 'Temporarily shut down systems, apply software patch '
'(version 9.5.1)',
'references': [{'source': 'Heise'}, {'source': 'TechCrunch'}],
'response': {'communication_strategy': 'Advisory to customers via TechCrunch '
'and Heise',
'containment_measures': 'Shut down systems, release software '
'patch (version 9.5.1)',
'incident_response_plan_activated': 'Temporary shutdown advised',
'law_enforcement_notified': 'Yes (unspecified agency)',
'remediation_measures': 'Addressed all known vulnerabilities in '
'version 9.5.1'},
'stakeholder_advisories': 'Customers advised to shut down systems',
'title': 'Kiteworks Urges Customers to Shut Down Systems Amid Imminent '
'Cyberattack Threat',
'type': 'Imminent Cyberattack Threat',
'vulnerability_exploited': 'Undiscovered exploits in Kiteworks systems'}