Kiteworks has told its customers to shut down their Kiteworks servers this weekend, after law enforcement warned the company that an attack may be imminent. The warning, reported by TechCrunch on September 25, 2026, points to a possible zero-day flaw. That is a security hole the vendor does not know about yet, so no patch exists for it.
Kiteworks sells software for sending large files and sensitive data between organizations. Its customers include banks, insurers and government bodies, so a successful attack could expose exactly the data these systems exist to protect.
What Kiteworks told customers
Kiteworks chief information security officer Frank Balonis said the company had "received credible threat intelligence from law enforcement." The warning indicated "that a threat actor may attempt to target some Kiteworks systems for customers," he told TechCrunch.
"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window," Balonis said. The company and its "law enforcement partners work through the matter" in the meantime.
Kiteworks stresses that nothing has been breached yet. "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach," Balonis said. According to TechCrunch, the company says it has fixed all known vulnerabilities in its latest release, version 9.5.1.
The shutdown window
heise online reports the details of the request:
| Detail | What Kiteworks asked for |
|---|---|
| Length | 6 hours |
| Date | Saturday, September 26, 2026 |
| Central European time | 4 a.m. to 10 a.m. |
| Which systems | All customer systems worldwide, any version |
| Internal servers | Shut down too, even if not internet-facing |
The last point is unusual. Kiteworks told customers that "it cannot be said with certainty what potential access routes there might be," heise reports. A Kiteworks support message explained the reason plainly: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks."
TechCrunch adds that Kiteworks urged customers to shut down "before the weekend, if not sooner."
How many systems are exposed
Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems, TechCrunch reports. The German outlet heise says customers in Germany include several state banks, insurance companies, a media group, consulting firms and well-known automotive suppliers. Google's Mandiant security unit works with Kiteworks, according to heise.
Why file-transfer software is a target
This company has been here before. Kiteworks was called Accellion until a rebrand in late 2021. Before that rebrand, TechCrunch notes, a flaw in its file-transfer application let an extortion gang mass-hack hundreds of organizations that used the product. That attack was part of a broader campaign against file-transfer products.
These tools are attractive to attackers for a simple reason. They sit on the edge of a company's network, face the internet and hold sensitive files by design. One flaw can open many victims at once.
What this means for developers
If your organization runs Kiteworks, confirm today that someone owns the shutdown. Check the exact window for your time zone in the customer notice, and plan it with the teams whose file transfers will stop.
Find the hidden dependencies before the servers go dark. Scheduled jobs, partner integrations and scripts that push files through Kiteworks will fail during the window. Pause them or queue them, so they do not retry against a dead endpoint or lose data.
Upgrade to 9.5.1 before bringing systems back, since that is the release Kiteworks says fixes every known flaw. Then review access logs from the last few weeks for unusual logins or large downloads.
The wider lesson applies to any file-transfer or edge appliance. Keep an inventory of which of these systems you run and which are reachable from the internet. Know who can shut one down quickly. This time the warning came before the attack, which rarely happens.
This article was first published on Tech AI Wire.
Also available in
Deutsch · 日本語 · Français · Español · Português
Top comments (0)