Kiteworks and Kiteworks Customers: Expecting cyber attack, Kiteworks tells users to turn off servers

Kiteworks and Kiteworks Customers: Expecting cyber attack, Kiteworks tells users to turn off servers

Kiteworks Urges Immediate Shutdown of MFT Servers Over Zero-Day Threat

Kiteworks, a provider of secure managed file transfer (MFT) solutions, has instructed users to power down their servers worldwide following warnings of an imminent cyberattack exploiting an undisclosed zero-day vulnerability. The directive, first reported by German outlet Heise, applies for a six-hour window on Saturday, September 26, from 3 AM to 9 AM UK time, though the company recommends shutting systems down beforehand.

In an email to customers, Kiteworks CISO Frank Balonis cited "credible threat intelligence from law enforcement" indicating a potential attack this weekend. While no compromise of Kiteworks services has been confirmed, the move was described as a precautionary measure. The vulnerability has yet to receive a CVE designation, and no technical details such as attack vectors or affected components have been disclosed.

Security experts have raised concerns over the unusual request. Jake Knott, Head of Threat Intelligence at Watchtowr, noted that demanding a full shutdown of production systems without a patch or public CVE is highly irregular. Managed file transfer appliances remain prime targets for threat actors, offering both initial access and direct exposure to sensitive data for extortion or lateral movement. Knott warned that such vulnerabilities often transition from targeted to widespread exploitation rapidly, with attackers and researchers likely already analyzing the codebase.

The advisory’s lack of specificity including why even non-internet-facing systems must be powered off has sparked further questions. While Kiteworks’ customers are advised to comply, the public disclosure of the zero-day may temporarily deter attackers, though the long-term risk remains unclear. The incident underscores the persistent targeting of MFT solutions in software supply chain attacks.

Source: https://www.computerweekly.com/news/366651301/Expecting-cyber-attack-Kiteworks-tells-users-to-turn-off-servers

Kiteworks TPRM report: https://www.rankiteo.com/company/kiteworksuk

Kiteworks Customers TPRM report: https://www.rankiteo.com/company/kiteworksuk

"id": "kit1790368239",
"linkid": "kiteworksuk",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'All Kiteworks MFT server users',
                        'industry': 'Cybersecurity / Managed File Transfer '
                                    '(MFT)',
                        'location': 'Global',
                        'name': 'Kiteworks',
                        'type': 'Company'}],
 'customer_advisories': 'Power down MFT servers for 6 hours on September 26 (3 '
                        'AM to 9 AM UK time).',
 'data_breach': {'sensitivity_of_data': 'Potentially sensitive (MFT solutions '
                                        'handle sensitive data)'},
 'date_publicly_disclosed': '2023-09-26',
 'description': 'Kiteworks, a provider of secure managed file transfer (MFT) '
                'solutions, has instructed users to power down their servers '
                'worldwide following warnings of an imminent cyberattack '
                'exploiting an undisclosed zero-day vulnerability. The '
                'directive applies for a six-hour window on Saturday, '
                'September 26, from 3 AM to 9 AM UK time, though the company '
                'recommends shutting systems down beforehand. The '
                'vulnerability has yet to receive a CVE designation, and no '
                'technical details such as attack vectors or affected '
                'components have been disclosed.',
 'impact': {'downtime': '6 hours (recommended longer)',
            'operational_impact': 'Global shutdown of MFT servers',
            'systems_affected': 'Managed File Transfer (MFT) servers'},
 'investigation_status': 'Ongoing',
 'recommendations': 'Shut down MFT servers immediately as a precautionary '
                    'measure; await further updates from Kiteworks.',
 'references': [{'source': 'Heise (German outlet)'},
                {'source': 'Watchtowr (Jake Knott, Head of Threat '
                           'Intelligence)'}],
 'response': {'communication_strategy': 'Email advisory to customers',
              'containment_measures': 'Immediate shutdown of MFT servers for 6 '
                                      'hours (recommended longer)',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes (credible threat intelligence '
                                          'from law enforcement cited)'},
 'stakeholder_advisories': 'Email advisory from Kiteworks CISO Frank Balonis '
                           'to customers.',
 'title': 'Kiteworks Urges Immediate Shutdown of MFT Servers Over Zero-Day '
          'Threat',
 'type': 'Zero-Day Exploitation',
 'vulnerability_exploited': 'Undisclosed zero-day vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.