Kiteworks Issues Precautionary Server Shutdown Advisory
Kiteworks, the secure file-sharing software provider, is urging customers worldwide to temporarily shut down their systems for a six-hour window on Saturday, September 26, 2026, following receipt of credible threat intelligence from law enforcement agencies. The recommendation comes after the company received information indicating that a threat actor may attempt to target some customer systems in the near future.
According to a report by German technology publication Heise, Kiteworks CISO Frank Balonis communicated the warning to customers via email, stating that the company had obtained "credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend." The message reportedly advised recipients to "strongly recommend you shut down your Kiteworks system for six hours" as a preventive measure.
Global Shutdown Window Specified by Time Zone
The shutdown advisory applies to customers across all regions, with specific time windows provided based on local time zones. In Central Europe, including Germany, customers were instructed to power down systems between 4:00 a.m. and 10:00 a.m. on Saturday, September 26. For users in New York and the Eastern Time Zone, the recommended window runs from 10:00 p.m. on Friday, September 25, to 4:00 a.m. on Saturday, September 26. In Australia, the timeframe corresponds to Australian Eastern Standard Time (AEST), while Pacific Daylight Time (PDT) governs the West Coast of the United States.
Kiteworks emphasized that customers should initiate the shutdown before the scheduled window begins and should take systems offline regardless of whether they are directly accessible from the public internet. This broad application is intended to mitigate any potential exposure during the period of heightened risk.
Company Confirms Advisory, Stresses Preventative Nature
Kiteworks confirmed the legitimacy of the warning to BleepingComputer, stating that it had received intelligence from federal authorities suggesting a possible targeting attempt by threat actors. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers," the company said in its statement.
The firm clarified that the advisory is strictly precautionary and not a response to any confirmed breach or active exploitation. "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach," Kiteworks stated. The company added that all known vulnerabilities are addressed in its current software release, version 9.5.1, and continues to recommend that customers maintain up-to-date installations.
No Confirmation of Zero-Day Exploitation
While Heise reported that Kiteworks customer support indicated the shutdown was intended to protect against potential zero-day attacks, the company has not confirmed the discovery or exploitation of any previously unknown vulnerability. In its statement to BleepingComputer, Kiteworks did not assert that a zero-day flaw had been identified, instead reiterating that the action is based solely on intelligence received from authorities and is designed as a precautionary step.
The company maintains that its current release, 9.5.1, includes patches for all known security issues and that the shutdown recommendation is not tied to any specific unpatched flaw. Kiteworks advises customers to remain vigilant and follow standard security practices while the situation is monitored in coordination with law enforcement partners.
Context: Secure File-Sharing Platforms as High-Value Targets
Kiteworks provides secure file-transfer and communications solutions used by government agencies, financial institutions, and large enterprises. These platforms are frequent targets for cybercriminals due to the sensitive nature of the data they store, including intellectual property, personal information, and confidential business documents. Attackers often seek to exfiltrate this data for use in extortion campaigns.
Although no specific threat actor has been linked to the current advisory, the Clop ransomware gang has historically targeted similar managed file transfer (MFT) and secure file-sharing systems, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. The U.S. Department of State has offered a reward of up to $10 million for information connecting Clop’s activities to foreign government sponsorship.
Source: BleepingComputer