Secure file-transfer vendor Kiteworks is asking customers around the world to temporarily shut down their servers for a six-hour precautionary window after receiving threat intelligence suggesting an attack on its systems could be imminent this weekend.
According to German outlet Heise, Kiteworks CISO Frank Balonis emailed customers stating the company had received “credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend,” and recommended shutting down systems for six hours, even for instances not directly reachable from the internet.
The shutdown window varies by region. Central European customers were told to power down between 4:00 a.m. and 10:00 a.m. on Saturday, September 26, while New York customers were given a window from 10:00 p.m. Friday to 4:00 a.m. Saturday. Kiteworks reportedly advised customers to shut down before the scheduled window begins.
Kiteworks confirmed the advisory to BleepingComputer, saying it received the warning from “federal intelligence authorities” indicating a threat actor may attempt to target customer systems. The company described the move as precautionary.
“We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach,” the company said, adding that all currently known vulnerabilities are patched in the latest release, version 9.5.1, and urging customers to update.
Zero-day concerns unconfirmed
Heise reported that when it contacted Kiteworks support to verify the notice, a representative said the shutdown was meant “to protect against any potential zero-day attacks.” However, neither the customer notification nor the statement given to BleepingComputer explicitly confirms that an unpatched vulnerability has been identified or exploited in the wild.
Kiteworks builds secure file-transfer and communications software used by government agencies, financial institutions, and enterprises, making it a valuable target for data-theft extortion operations. Platforms of this type have repeatedly been hit by such campaigns in recent years, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, several of which were linked to the Clop extortion gang. It is not yet known which threat actor, if any, is connected to the intelligence Kiteworks received.
The U.S. Department of State is currently offering a $10 million reward for information tying Clop’s attacks to a foreign government, underscoring the scale of concern around file-sharing platform compromises.
