NEWS

Kiteworks Urges Customers to Shut Down Servers Over Possible Imminent Zero-Day Attack

Kiteworks told 1,500+ customers to shut down servers for a multi-hour window after credible threat intel warned of a possible imminent zero-day attack.

Dylan H.

News Desk

September 25, 2026
9 min read
Kiteworks Urges Customers to Shut Down Servers Over Possible Imminent Zero-Day Attack

Kiteworks Tells Customers Worldwide to Power Down Over "Credible" Attack Warning

Secure file-transfer and communications vendor Kiteworks (formerly Accellion) urged its entire customer base to shut down their servers for a multi-hour window over the weekend of September 26-27, 2026, after receiving what the company described as "credible threat intelligence from federal intelligence authorities" warning that a threat actor may be preparing an imminent attack against Kiteworks systems. Kiteworks CISO Frank Balonis emailed customers directly with the warning, and CEO Jonathan Yaron signed a follow-up notice asking self-managed customers — those running Kiteworks on-premises or on AWS or Azure — to take their systems offline themselves, while Kiteworks said it would shut down Kiteworks-hosted environments on customers' behalf. The company, which serves more than 1,500 customers and 100 million-plus end users including government agencies, financial institutions, and healthcare organizations, stressed there is no confirmed evidence of a breach — but the unusual scope of the request, which reportedly extends even to servers not exposed to the internet, has drawn comparisons to the file-transfer zero-days previously exploited by the Clop ransomware gang against Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo, and MOVEit Transfer.


Advisory at a Glance

AttributeValue
VendorKiteworks (formerly Accellion)
Advisory issuedSeptember 25, 2026
Shutdown windowSaturday, September 26, 2026, local time zones — e.g. 22:00 ET Friday to 04:00 ET Saturday; 04:00-10:00 CET; 02:00-08:00 UTC
Reported window length6 hours per most outlet reporting (BleepingComputer, Heise); Kiteworks' own press release describes a "nine-hour precautionary shutdown window" — CosmicBytez Labs could not reconcile the discrepancy as of publication
Trigger"Credible threat intelligence from federal intelligence authorities" of a possible imminent attack
Confirmed breachNone disclosed; advisory described by Kiteworks as precautionary
Confirmed CVENone published as of this writing
Who must actSelf-managed customers (on-prem, AWS, Azure) shut down their own systems; Kiteworks-hosted customers require no action
Customer base1,500+ organizations, 100 million-plus end users (government, financial, healthcare, enterprise)
Current patched version9.5.1 — Kiteworks says all currently known vulnerabilities are fixed in this release
Unaffected subsidiaries namedZivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, 123FormBuilder
Recommended offline durationAt least until September 28, 2026, per legal/compliance guidance circulating to customers

How the Warning Unfolded

The Notification

Kiteworks' Balonis wrote to customers that the company had "received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend," and recommended a shutdown of at least six hours. In a follow-up statement to BleepingComputer, Kiteworks framed the same message more formally: "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers." In its own press release, the company described the recommendation as "a precautionary shutdown window this weekend, in [each customer's] local time zone," and quoted Balonis saying: "Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities."

An Unusually Broad Ask

What stood out to researchers was not just that Kiteworks recommended a shutdown, but who it applied to. According to reporting by German outlet Heise, Kiteworks told customers that even servers not reachable from the internet should be powered down during the window. One security expert quoted by Heise drew the implication out directly: "If the company is saying 'shut it down' even if it's not exposed, then you have to assume the zero-day is something already running on the system and has a C2 channel waiting for a command to 'execute.'" Jake Knott, head of threat intelligence at watchTowr, told reporters he was actively tracking an emerging threat to Kiteworks appliances and called the shutdown request itself "highly unusual, and a very bad sign" — while cautioning that no CVE, patch, or additional technical detail was publicly available at the time.

No Confirmed Vulnerability — Yet

Kiteworks has been consistent on one point across every statement: it has not confirmed a zero-day, and has not confirmed a breach. The company's press release states plainly: "We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative." Kiteworks customer support told Heise the goal was narrower and more specific: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks." The company separately noted that all currently known vulnerabilities in its platform are addressed in version 9.5.1 and urged customers to run the latest release — a statement aimed at distinguishing "known, patched issues" from the unknown flaw the threat intelligence apparently concerns.

Echoes of Clop's File-Transfer Campaigns

The comparison security researchers keep reaching for is Clop (also styled Cl0p), the extortion-focused ransomware gang with a long history of exploiting zero-days in secure file-transfer software for mass data-theft campaigns rather than encryption. Clop's prior targets include Accellion FTA — Kiteworks' own predecessor product — as well as GoAnywhere MFT, SolarWinds Serv-U, Cleo, and the MOVEit Transfer campaign that compromised hundreds of organizations in 2023. Kiteworks' file-sharing and governance platform occupies the same product category and serves a similar high-value customer mix of government, financial, and healthcare organizations, making it a logical target for a group specializing in bulk sensitive-data extortion. As of publication, no threat actor has been named in connection with this specific warning.


Impact Assessment

Impact AreaDescription
OperationalCustomers worldwide asked to take Kiteworks systems offline for several hours during a weekend window, disrupting file-transfer and secure-communication workflows
Trust and confidenceAn unprecedented precautionary shutdown request from a major secure-file-sharing vendor, even absent a confirmed exploit, signals a serious threat assessment and may pressure customers to reassess vendor risk
Regulatory and legalOrganizations handling regulated data through Kiteworks may face incident-response and breach-notification analysis obligations if post-restoration log review turns up anomalous access
Industry-wideReinforces file-transfer and managed-file-transfer (MFT) platforms as a persistent high-value target category following Accellion FTA, GoAnywhere, Cleo, and MOVEit
ReputationalKiteworks' handling — direct executive communication, a public press release, and offering to shut down hosted environments on customers' behalf — is being read by some researchers as a rare example of proactive vendor transparency, even though the underlying threat remains unconfirmed

Recommendations

For Kiteworks Administrators and IT Teams

  • Follow Kiteworks' shutdown guidance directly, including for systems that are not internet-facing — the advisory explicitly covers internal deployments, not just externally exposed ones.
  • Preserve system, authentication, network, and security logs before shutting systems down, and ensure logging and monitoring will be available again once systems are restored.
  • Do not restore service simply because the initially announced window has passed; restore only once Kiteworks confirms it is safe to do so, and treat September 28, 2026 as an earliest, not guaranteed, restoration point per circulating legal guidance.
  • Confirm systems are running version 9.5.1 or later before and after the shutdown window, since Kiteworks says all currently known vulnerabilities are addressed there.

For Security and Incident Response Teams

  • Review recent authentication logs, access patterns, and alerts for anomalies predating the shutdown — if a zero-day is already deployed on internal systems, evidence of initial access may exist before the warning was issued.
  • Coordinate cybersecurity, legal, privacy, compliance, and communications stakeholders now rather than waiting for confirmed exploitation, given the sensitivity of data typically routed through Kiteworks deployments.
  • Track watchTowr, CISA, and vendor channels for a forthcoming CVE or technical advisory, and be prepared to move quickly once indicators of compromise are published.
  • Treat this advisory as a reminder to inventory all internet-facing and internal managed-file-transfer software, given the sustained pattern of MFT-focused zero-day campaigns from groups like Clop.

For Organizations That Exchange Sensitive Data via Kiteworks

  • Identify what categories of sensitive data flow through your Kiteworks environment and evaluate potential notification obligations if unauthorized access is later confirmed.
  • Ask your Kiteworks account team directly for confirmation of your deployment model (self-managed vs. hosted) and whether any action is required on your part.
  • Avoid assuming "no news" during the shutdown window means "no risk" — Kiteworks and law enforcement described this as an active, ongoing assessment as of the advisory date.

Key Takeaways

  1. Kiteworks asked its entire customer base — 1,500-plus organizations and 100 million-plus end users — to shut down servers over the weekend of September 26-27, 2026, after receiving credible threat intelligence from federal authorities about a possible imminent attack.
  2. The advisory covers both self-managed deployments (on-premises, AWS, Azure) and Kiteworks-hosted environments, with Kiteworks handling shutdown of the latter on customers' behalf.
  3. Reported shutdown-window length varies by source — six hours per BleepingComputer and Heise, versus a "nine-hour precautionary shutdown window" per Kiteworks' own press release — and Kiteworks has not confirmed any breach or specific zero-day vulnerability as of publication.
  4. The request notably extends to servers with no internet exposure, which researchers say implies concern about malware or a command-and-control channel already present inside customer environments rather than a purely externally exploitable flaw.
  5. Kiteworks says all currently known vulnerabilities are fixed in version 9.5.1 and continues to recommend customers run the latest release independent of this advisory.
  6. The situation echoes past zero-day campaigns against managed-file-transfer platforms — including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo, and MOVEit Transfer — most linked to the Clop extortion group, making MFT software a recurring high-value target category worth monitoring closely for a follow-up CVE disclosure.

Sources