Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

Software company Kiteworks sent a warning to customers this week urging them to shut off the company’s platform over the weekend due to concerns over potential cyberattacks or intrusions.
The email to customers, first reported by German news outlet Heise, recommends customers shut down their systems during a six-hour window on Saturday.
In response to inquiries about the message, Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter,” Balonis said.
“We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach. All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version."
Kiteworks did not respond to follow up questions about whether the bug had a CVE yet or what groups are exploiting the platform. The company makes popular software used for secure or confidential communication.
The FBI declined to comment and the Cybersecurity and Infrastructure Security Agency (CISA) did not respond to requests for comment.
A Kiteworks customer support official told Heise that the email was sent out due to a potential “zero-day” vulnerability but did not elaborate.
Kiteworks was previously known as Accellion and operated a popular file transfer tool until an incident in December 2020 where a Russian hacking group known as Clop used a zero-day vulnerability to steal data from dozens of high-profile companies. The organizations breached included the University of Colorado, the Washington State Auditor Office, Flagstar Bank, airplane maker Bombardier, and U.S. retail store chain Kroger.
Jake Knott, a senior official at cybersecurity firm watchTowr, said they are actively tracking the threat but noted how unusual and concerning it is that Kiteworks suggested customers essentially turn off the power on their servers.
“There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch,” he said, noting the past incidents Kiteworks went through under the Accellion name.
“Whilst years have passed and the name has changed, attackers' appetites for targeting [managed file transfer] appliances has not, and we have no reason to believe this time will be any different. In other words, this is familiar territory, but not the comforting kind.”
References in this story
- Imminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down Servers www.heise.de Manufacturer writes to its customers that they have concrete indications from law enforcement about an attack. Large companies are also affected in this country.
- Faulty emailing tool prevented Accellion from notifying customers of attacks therecord.media Efforts to patch a zero-day vulnerability in Accellion file-sharing servers that was actively exploited by hackers last year were hindered by a faulty emailing tool that delayed crucial customer notifications for days…
- The Accellion Breach Keeps Getting Worse—and More Expensive www.wired.com What started as a few vulnerabilities in firewall equipment has snowballed into a global extortion spree.
- Personal Information Compromised In CU Cyberattack Believed To Be Largest In University History denver.cbslocal.com The University of Colorado is investigating a cyberattack that compromised the personal information of students and employees.
- Frequently asked questions regarding a data breach at SAO’s third-party service provider | Office of the Washington… sao.wa.gov The information on this page was last updated: 03/12/2021 5:05 PM The process is under way to notify people whose unemployment benefits claims information may have been affected by a data security breach of the…
- Accellion Security Incident Impacts Kroger Family of Companies Associates and Limited Number of Customers www.prnewswire.com /PRNewswire/ -- The Kroger Co. (NYSE: KR) Family of Companies today confirmed that it was impacted by the data security incident affecting Accellion, Inc....
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



