Kiteworks is urging customers to shut down their systems after the company said it received credible intelligence that hackers may soon attempt to target some of its servers, a warning that has triggered concern across sectors that rely on the software to move sensitive data.
The company, formerly known as Accellion, confirmed to TechCrunch that it had notified customers about the potential threat after receiving information from law enforcement. The alert was first reported by German publication Heise, which said it had seen an email from Kiteworks warning of an "imminent" attack that could happen as soon as this weekend.
In a statement to TechCrunch, Kiteworks chief information security officer Frank Balonis said the company had acted out of caution after receiving intelligence indicating that a threat actor might target some customer systems.
"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter," Balonis said. "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach."
Kiteworks did not identify the law enforcement agency that shared the warning, nor did it say which hacking group might be behind the threat. The FBI declined to comment, and Marco DiSandro, a spokesperson for the U.S. cybersecurity agency CISA, would not comment on the record when asked about the alert.
According to a copy of the email sent to customers and shared with TechCrunch, Kiteworks said it was worried about the exploitation of vulnerabilities that are not yet known to the company. Those so-called zero-day flaws are especially dangerous because vendors have no opportunity to patch them before attackers can use them.
In the email, Kiteworks urged customers to shut down their systems before the weekend, if not sooner, to "protect against any potential zero-day attacks," saying it could not confirm whether there were other possible routes for improper access. The company said it has fixed all known vulnerabilities in its latest software release, version 9.5.1, and recommended that customers use that version.
The scope of the potential impact remains unclear, but Kiteworks says on its website that it has thousands of customers across healthcare, technology, education, automotive and government sectors. Security researcher Kevin Beaumont pointed to at least a thousand internet-facing Kiteworks systems visible online, though that figure may overstate the number of affected customer deployments.
For some organizations, the warning has already translated into immediate operational disruption. One Kiteworks customer in healthcare told TechCrunch that the alert prompted the organization to take its server down right away. The customer, who asked not to be identified publicly, said the outage is delaying doctors' ability to contact patients, underscoring the real-world tradeoff between cyber defense and continuity of care.
The episode is particularly sensitive for Kiteworks because the company has lived through a major security crisis before. Prior to its rebrand from Accellion in late 2021, a vulnerability in its file-transfer application was exploited in a mass-hacking campaign that allowed an extortion gang to steal data from hundreds of organizations. Those victims used the product to send customer and internal corporate information over the internet, and attackers later leveraged the stolen data for extortion.
That earlier campaign was part of a broader wave of attacks against file-transfer products, which have long been attractive targets because they often sit at the center of high-value data flows. The current warning does not confirm that a similar compromise is underway, but it shows how quickly anxiety can spread when a vendor handling sensitive files tells customers to power down systems in anticipation of a possible zero-day attack.
For now, Kiteworks is framing the alert as a preventive measure while it works with law enforcement. But the company's unusual advice to shut down servers, combined with the lack of detail about the threat actor or vulnerability, has left customers with an urgent and difficult choice: keep systems online and risk exposure, or take them offline and absorb the operational fallout.
