Software
Kiteworks tells customers to shut servers for six hours over attack threat
Secure file-sharing vendor Kiteworks urged customers worldwide to shut down servers for six hours on 26 September 2026 after law enforcement warned of an imminent attack on its systems.
Photo: BleepingComputerKey points
Kiteworks urged customers worldwide to shut down servers for a six-hour window on 26 September 2026 after receiving threat intelligence of a potentially imminent attack.
Kiteworks urged its customers worldwide to shut down their servers for a six-hour window on Saturday, 26 September 2026, after receiving threat intelligence warning of a potentially imminent cyberattack. The secure file-sharing software company said it acted on credible intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent that weekend.techcrunch.com+1
The warning matters because Kiteworks products are used by government organisations, financial institutions, healthcare providers, and enterprises to move sensitive files, making them a valuable target for data-theft extortion. What is new is that the company recommended shutting systems down entirely rather than issuing a patch, and it said all known vulnerabilities are already fixed in its current release, version 9.5.1.
What the warning told customers
Frank Balonis, Kiteworks chief information security officer, emailed customers saying the company had received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent that weekend. The notification told customers: "We strongly recommend you shut down your Kiteworks system for six hours." The company confirmed the warning directly, saying it notified customers as a precaution.
Kiteworks stressed the warning is preventative rather than a response to a confirmed breach. The company said it is not aware of any compromise of Kiteworks systems, and that all known vulnerabilities are addressed in the current release, 9.5.1, which it continues to recommend customers run. The company did not name the specific law enforcement agency that provided the intelligence.
The shutdown window applied to customers worldwide, with affected time zones ranging from Australian Eastern Standard Time to Pacific Daylight Time. In Central Europe, customers were instructed to shut down Kiteworks systems between 4:00 a.m. and 10:00 a.m. on Saturday, 26 September. In New York, the window would run from 10:00 p.m. Friday to 4:00 a.m. Saturday.
Where the shutdown window fell
Kiteworks recommended customers shut down servers before the scheduled window and take systems offline even if they are not directly accessible from the internet. A copy of the customer email said the company was concerned about the exploitation of vulnerabilities currently unknown to it, which are known as zero-day flaws because the vendor has no time to fix them before they are exploited.
Kiteworks customer support told German publication Heise that the shutdown recommendation is intended to protect customers against potential zero-day attacks, saying: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks." However, neither the statement to BleepingComputer nor the customer notification confirms that a zero-day vulnerability has been discovered or exploited.bleepingcomputer.com
What remains unconfirmed
The scale of affected customers is unclear. Kiteworks notes on its website that it has thousands of customers across healthcare, technology, education, automotive, and government. Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems, though the number is likely an overcount of affected customer systems.
One Kiteworks customer in healthcare said they received the alert and took their organisation's server down immediately, adding that the outage was causing delays and disruption to doctors' ability to contact their patients. Kiteworks did not say which law enforcement agency alerted it or which hacking group may be behind the threat.
The FBI declined to comment on the matter. Marco DiSandro, a spokesperson for the U.S. cybersecurity agency CISA, would not comment on the record when asked about the Kiteworks alert to customers. Federal cybersecurity officials have not issued a public advisory tied to the warning. Kiteworks is no stranger to cyberattacks. Before it rebranded from Accellion in late 2021, a vulnerability in its file-transfer application allowed an extortion gang to mass-hack and steal data from hundreds of organisations. The Clop extortion gang has a long history of targeting enterprise file-transfer platforms, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. Kiteworks is expected to release additional technical details, indicators of compromise, and mitigation steps in the coming days, and customers were told not to bring systems back online until cleared by the company. Federal advisories from agencies like CISA are expected if a vulnerability is confirmed.
Frequently asked questions
Why did Kiteworks tell customers to shut down servers?
Kiteworks said it received credible threat intelligence from law enforcement indicating an attack on its systems may be imminent that weekend, and recommended a precautionary six-hour shutdown while it works with law enforcement partners.
When was the shutdown window?
In Central Europe, customers were instructed to shut down Kiteworks systems between 4:00 a.m. and 10:00 a.m. on Saturday, 26 September. In New York, the window ran from 10:00 p.m. Friday to 4:00 a.m. Saturday.
Has a zero-day vulnerability been confirmed?
No. Kiteworks customer support said the shutdown protects against potential zero-day attacks, but neither the company's statement nor the customer notification confirms a zero-day flaw has been discovered or exploited. Kiteworks says all known vulnerabilities are fixed in version 9.5.1.
How this story was checked
- Fact-checked against 3 cited pages. 35 figures, dates and quotations in this story were found on the pages it cites.
- Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (3 of 3)
- bleepingcomputer.comread and checked
- techcrunch.comread and checked
- androguider.comread and checked
Written by Kaer from public reporting. Checked 26 September 2026.


