US Edition
Your source for latest news
TechnologyCybersecurity

Kiteworks tells customers to shut down servers after federal cyberattack warning

The secure file-transfer vendor, formerly known as Accellion, ordered a nine-hour precautionary shutdown after law enforcement warned of a possible zero-day attack, reviving memories of the company's damaging 2021 breach.

PT
By PressTemps Technology DeskPublished Today, 09:33 ET · 5 min read
Kiteworks tells customers to shut down servers after federal cyberattack warning
Photo: Kevin Ache / Unsplash. Illustrative image of a server room; not a Kiteworks facility.
What to know
Kiteworks urged customers to shut down systems for roughly nine hours on Sept 25-26 after federal authorities warned of a possible imminent attack.
Kiteworks later said the flaw was isolated to its Advanced Forms product and affected fewer than 50 of its customers, or under 1 percent.
Kiteworks, formerly Accellion, was the center of a 2021 zero-day breach that a joint advisory from CISA and four allied nations' agencies linked to the Clop ransomware group.
The shutdown advisory was lifted Sept 27 after Kiteworks released software version 9.5.1 and began sharing threat intelligence with Mandiant.

Kiteworks, a San Mateo, California-based provider of secure file-transfer and data-governance software used by government agencies, hospitals, banks and defense contractors, told customers late on September 25 to shut down their systems for nine hours after receiving what it described as credible threat intelligence from federal authorities warning of an imminent attack. The advisory, one of the more unusual moves by a major enterprise software vendor in recent memory, asked thousands of organizations running Kiteworks' platform to power down self-managed deployments over the weekend while the company investigated.

In a precautionary shutdown advisory posted to its newsroom, Kiteworks said law enforcement had informed it that a threat actor might attempt to exploit a previously unknown vulnerability in its systems. The company said it had no evidence that any customer environment had actually been breached, and framed the shutdown as a preventive measure rather than a response to a confirmed intrusion. By September 27, Kiteworks lifted the recommendation, saying its own hosted systems were back online and that all known vulnerabilities had been addressed in software release 9.5.1.

The numbers

The shutdown window itself ran roughly nine hours over the weekend, timed to overnight hours on the East Coast of the United States, according to Kiteworks and a client alert from the law firm Morgan Lewis, which advised affected clients to preserve logs and review access records before complying. Kiteworks' platform is used by thousands of organizations, and TechCrunch reported that security researchers had identified more than 1,000 internet-facing Kiteworks systems exposed online at the time of the advisory, spanning healthcare, technology, education, automotive and government sectors. By September 28, Kiteworks and outlets covering the incident narrowed the scope considerably: SecurityWeek reported that the underlying flaw was isolated to Kiteworks' Advanced Forms product, a secure data-collection tool, and affected fewer than 1 percent of customers, or under 50 organizations. Core products, including managed file transfer, email encryption, file collaboration and the company's APIs, were not implicated.

How Kiteworks got here

The episode carries particular weight because of the company's history. Kiteworks was formerly known as Accellion, whose legacy File Transfer Appliance was at the center of one of the most damaging software supply-chain incidents of the early 2020s. Starting in December 2020, attackers linked to the Clop ransomware group exploited a chain of zero-day vulnerabilities in the aging appliance to steal data from dozens of organizations and extort them with threats of public release. The scale of that breach was significant enough that cybersecurity authorities in five countries took the rare step of issuing a coordinated warning: a joint advisory from the US Cybersecurity and Infrastructure Security Agency and counterparts in Australia, New Zealand, Singapore and the United Kingdom detailed the vulnerabilities and listed victims that ultimately included the Reserve Bank of New Zealand, Australia's securities regulator, the law firm Jones Day, and universities and hospital systems across several continents. Accellion later rebranded as Kiteworks and rebuilt its file-transfer business around a newer platform, positioning itself as a hardened alternative for regulated industries. This week's advisory was the company's most visible security event since that rebrand, and it suggests the scrutiny attached to its name has not faded.

Who is affected

Kiteworks said the advisory applied to customers running self-managed deployments, whether on-premises or hosted on Amazon Web Services or Microsoft Azure, who were asked to shut systems down themselves. Customers on Kiteworks' own hosted infrastructure had their instances taken offline by the company directly. Several of Kiteworks' subsidiary brands and acquired products, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder, were explicitly excluded from the shutdown, the company said. Because Kiteworks markets itself heavily to compliance-sensitive sectors, the customer base skews toward organizations handling regulated data: healthcare providers bound by HIPAA, financial institutions, defense contractors and federal, state and local government agencies. Law firms including Morgan Lewis moved quickly to advise clients that even a precautionary shutdown could trigger review obligations under data-breach notification laws if any evidence of unauthorized access later surfaced.

What people are saying

Kiteworks' chief information security officer, Frank Balonis, has been the company's primary public voice on the incident. In the company's own advisory and in comments to reporters, he emphasized that the shutdown was precautionary rather than reactive.

"We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach," Balonis said.

Neither the FBI nor the Cybersecurity and Infrastructure Security Agency would confirm their roles in the tip that prompted the shutdown; TechCrunch reported that the FBI declined to comment and a CISA spokesperson would not speak on the record. That reticence has left open questions about the specificity and source of the original warning, and about why a private company received it directly rather than through a public advisory. Coverage from The Hacker News noted that the lack of detail on the threat actor's identity left security teams largely reliant on Kiteworks' own account of events.

What happens next

Kiteworks says it is now working with the incident-response firm Mandiant to share threat intelligence gathered during the episode, and it has urged all customers, not only those running Advanced Forms, to update to software release 9.5.1, listed on Kiteworks' own security updates archive, which the company says addresses every vulnerability currently known to it. Self-hosted customers running the affected forms product were directed to contact Kiteworks support directly for remediation guidance rather than patching independently. For customers in regulated industries, the more consequential work may only be beginning: compliance teams are now expected to document what systems relied on Kiteworks infrastructure, whether any regulated data was reachable during the exposure window, and whether notification obligations apply even absent confirmed compromise. Given the company's history with the Accellion breach, security researchers are likely to scrutinize Kiteworks' subsequent disclosures closely, watching in particular whether a CVE identifier and technical details of the Advanced Forms flaw are eventually published, and whether the "federal authorities" behind the original tip are ever publicly named.

More on this story

All Technology