· via TechCrunch
Kiteworks tells customers to shut down servers over imminent zero-day attack threat
Kiteworks has told customers to power down servers before the weekend after law enforcement warned of a possible zero-day attack; one healthcare provider is already reporting patient-contact disruption.

Kiteworks urges customers to power down
Kiteworks, the file-transfer and secure-data-exchange vendor formerly known as Accellion, has advised customers to switch off their servers ahead of what it describes as an imminent attack threat. According to TechCrunch, which confirmed the advisory with the company, the move follows credible threat intelligence supplied by law enforcement.
German publication Heise first reported the story, citing an email Kiteworks sent to customers warning that an attack could come as soon as this weekend.
Concerns center on unknown zero-day flaws
In a statement to TechCrunch, Kiteworks chief information security officer Frank Balonis said the company had received credible intelligence from law enforcement indicating that a threat actor might attempt to target certain Kiteworks systems used by customers. He said the company notified customers directly and recommended a precautionary shutdown window while it works through the matter alongside law enforcement partners, and stressed that Kiteworks is not aware of any compromise of its systems — framing the advisory as preventative rather than a response to a confirmed breach.
Per a copy of the customer email shared with TechCrunch, the core worry is exploitation of vulnerabilities Kiteworks does not yet know about — zero-day flaws that leave the vendor no window to patch before attackers use them. The email urged customers to take systems offline before the weekend, if not sooner, to guard against potential zero-day attacks, since the company cannot confirm whether other improper access routes exist.
Kiteworks declined to say which law enforcement agency provided the tip or which hacking group may be behind the threat. TechCrunch reports that the FBI and the U.S. cybersecurity agency CISA did not respond to requests for comment.
The company says all known vulnerabilities are fixed in its latest release, version 9.5.1, which it recommends all customers run. The precaution, however, is aimed at flaws that remain unknown to the vendor.
Customers already feeling the impact
The number of affected customers is unclear. Kiteworks says on its website that it has thousands of customers across sectors including healthcare, technology, education, automotive and government. Security researcher Kevin Beaumont highlighted a listing of at least a thousand internet-facing Kiteworks systems, though TechCrunch notes the figure likely overcounts actual customer installations.
Disruption is already tangible for at least one organization. A Kiteworks customer working in healthcare, who asked not to be named, told TechCrunch their organization pulled its server offline immediately after receiving the alert, and the outage is delaying doctors' ability to reach patients.
The Accellion history
Kiteworks has been through this territory before. Under its previous name, Accellion, a vulnerability in its file-transfer application enabled an extortion gang to hack and steal data from hundreds of organizations that relied on the product to move customer and internal corporate data. As TechCrunch recounts, that campaign was part of a wider wave of attacks on file-transfer products, in which attackers sought copies of data previously sent over the internet and still sitting on affected servers, then demanded ransoms under threat of publishing the stolen information. The company rebranded to Kiteworks in late 2021.
Why it matters
A vendor telling customers to switch off production systems outright is a rare and drastic step, and it signals Kiteworks judged the risk severe enough to prefer customer downtime over potential exposure. For organizations running Kiteworks, the practical guidance is unambiguous: take systems down before the weekend and move to version 9.5.1 before restoring service. The incident also highlights why file-transfer infrastructure keeps landing in attackers' crosshairs — these systems are internet-exposed by design and hold archives of sensitive historical data, making them prime extortion targets. Security teams running comparable products, not just Kiteworks, should treat this as a prompt to inventory their file-transfer estate and rehearse shutdown-and-restore procedures.
- #security
- #file-transfer
- #zero-day
- #cloud
- #cybercrime