Kiteworks issues global server shutdown
Kiteworks advised customers worldwide to shut down servers for a six-hour window on Saturday, September 26, based on credible threat intelligence from

Kiteworks has urged its global customer base to temporarily shut down their servers for a six-hour window on Saturday, September 26. The advisory is based on credible threat intelligence from federal authorities indicating a threat actor may attempt to target some customer systems.
Kiteworks received the intelligence from law enforcement, warning of a possible attack this weekend. The recommended shutdown window is scheduled from 4 a.m. To 10 a.m. Central European Time. This applies worldwide, covering time zones from Australian Eastern Standard Time (AEST) to Pacific Daylight Time (PDT). The company advises customers to power down servers before the scheduled window and to take systems offline even if they are not directly accessible from the internet.
Company stresses precautionary nature of warning
Kiteworks emphasized the shutdown is a preventive measure, not a response to a confirmed incident. The company stated it is not aware of any compromise of its systems. Neither the company's public statement nor its customer notification confirms that a zero-day vulnerability has been discovered or exploited.
Frank Balonis, Chief Information Security Officer of Kiteworks, showed the advisory's intent. "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach," Balonis said.
Context of risk to secure file-sharing platforms
Kiteworks develops secure file-transfer and communications products used by government organizations, financial institutions, and large enterprises. Such platforms are high-value targets for cybercriminals because they commonly store sensitive documents for data-theft extortion attacks.
Extortion groups like Clop have a long history of targeting similar enterprise file-transfer platforms. Their past campaigns have exploited vulnerabilities in Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, and MOVEit Transfer. The U.S. Department of State offers a $10 million reward for information linking Clop's attacks to a foreign government.
In Germany alone, Kiteworks customers include several state banks, insurance companies, a media group, consulting firms, and automotive suppliers. This widespread enterprise use shows the potential impact of a successful attack.
Technical guidance and version recommendations
Kiteworks provided specific technical guidance alongside the shutdown order. The company confirmed that all known vulnerabilities are addressed in its latest software release, version 9.5.1. It continues to strongly recommend that all customers run this latest version.
Kiteworks continues to recommend customers run the latest version of its software, 9.5.1, to address all known vulnerabilities.





