GLOBAL LIVE DESKS&P 500:7,743.41(+0.51%)FTSE 100:10,695.25(+0.14%)NIKKEI 225:66,364.20(+1.30%)BRENT CRUDE:$97.44(-2.77%)GOLD:$4,321.20(+0.54%)
RDU Global
🌐
Back to Global Desk
2026/09/27Cybersecurity & Cyber Warfare

Kiteworks Urges Customers to Shut Down Servers as Cyber Threat Seen as 'Imminent'

Kiteworks is warning customers to power down systems after receiving credible threat intelligence from law enforcement about a possible cyberattack targeting some of its servers. The precautionary alert, described by the company as preventative rather than a response to a confirmed breach, has already disrupted at least one healthcare customer and raised fresh concerns about zero-day exploitation in widely used file-transfer software.

R

RDU Global Correspondent

Cybersecurity Desk

San Francisco, United States 3h ago•5 min read
🌐 Global Edition • Cybersecurity & Cyber WarfareRDU GLOBAL CORRESPONDENT
VERIFIED WIRE INTELLIGENCE

"Kiteworks Urges Customers to Shut Down Servers as Cyber Threat Seen as 'Imminent'"

Kiteworks is warning customers to power down systems after receiving credible threat intelligence from law enforcement about a possible cyberattack targeting some of its servers. The precautionary alert, described by the company as preventative rather than a response to a confirmed breach, has already disrupted at least one healthcare customer and raised fresh concerns about zero-day exploitation in widely used file-transfer software.

Kiteworks is urging customers to shut down their systems after the company said it received credible intelligence that hackers may soon attempt to target some of its servers, a warning that has triggered concern across sectors that rely on the software to move sensitive data.

The company, formerly known as Accellion, confirmed to TechCrunch that it had notified customers about the potential threat after receiving information from law enforcement. The alert was first reported by German publication Heise, which said it had seen an email from Kiteworks warning of an "imminent" attack that could happen as soon as this weekend.

In a statement to TechCrunch, Kiteworks chief information security officer Frank Balonis said the company had acted out of caution after receiving intelligence indicating that a threat actor might target some customer systems.

"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter," Balonis said. "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach."

Kiteworks did not identify the law enforcement agency that shared the warning, nor did it say which hacking group might be behind the threat. The FBI declined to comment, and Marco DiSandro, a spokesperson for the U.S. cybersecurity agency CISA, would not comment on the record when asked about the alert.

According to a copy of the email sent to customers and shared with TechCrunch, Kiteworks said it was worried about the exploitation of vulnerabilities that are not yet known to the company. Those so-called zero-day flaws are especially dangerous because vendors have no opportunity to patch them before attackers can use them.

In the email, Kiteworks urged customers to shut down their systems before the weekend, if not sooner, to "protect against any potential zero-day attacks," saying it could not confirm whether there were other possible routes for improper access. The company said it has fixed all known vulnerabilities in its latest software release, version 9.5.1, and recommended that customers use that version.

The scope of the potential impact remains unclear, but Kiteworks says on its website that it has thousands of customers across healthcare, technology, education, automotive and government sectors. Security researcher Kevin Beaumont pointed to at least a thousand internet-facing Kiteworks systems visible online, though that figure may overstate the number of affected customer deployments.

For some organizations, the warning has already translated into immediate operational disruption. One Kiteworks customer in healthcare told TechCrunch that the alert prompted the organization to take its server down right away. The customer, who asked not to be identified publicly, said the outage is delaying doctors' ability to contact patients, underscoring the real-world tradeoff between cyber defense and continuity of care.

The episode is particularly sensitive for Kiteworks because the company has lived through a major security crisis before. Prior to its rebrand from Accellion in late 2021, a vulnerability in its file-transfer application was exploited in a mass-hacking campaign that allowed an extortion gang to steal data from hundreds of organizations. Those victims used the product to send customer and internal corporate information over the internet, and attackers later leveraged the stolen data for extortion.

That earlier campaign was part of a broader wave of attacks against file-transfer products, which have long been attractive targets because they often sit at the center of high-value data flows. The current warning does not confirm that a similar compromise is underway, but it shows how quickly anxiety can spread when a vendor handling sensitive files tells customers to power down systems in anticipation of a possible zero-day attack.

For now, Kiteworks is framing the alert as a preventive measure while it works with law enforcement. But the company's unusual advice to shut down servers, combined with the lack of detail about the threat actor or vulnerability, has left customers with an urgent and difficult choice: keep systems online and risk exposure, or take them offline and absorb the operational fallout.

Editorial & Verification Notice

Reported by RDU Global Correspondent. Formatted and verified using real-time institutional and journalistic wire feeds. Independent reporting adhering to the RDU Global Editorial Code of Conduct.

Entity Intelligence & Connected Dossiers

Cross-referenced topic files, verified public records, and institutional tracking

Knowledge Graph
⚖️Laws, Policies & Rulings:

Related Coverage

World Politics & Diplomacy

Hamas Condemns Peace Board Over UNRWA Exclusion in Gaza

Hamas has sharply criticized the proposed Board of Peace for refusing to work with UNRWA in Gaza, framing the decision as a political attempt to sideline the UN agency most closely tied to Palestinian relief operations. The dispute underscores a widening struggle over who will control humanitarian access, postwar administration, and legitimacy in Gaza as international actors weigh competing models for governance.

Just now (07:39 PM IST)
Big Tech, Cloud & Semiconductors

Apple’s iPhone 18 Pro Gets Cooler Under Pressure, Delivering a More Comfortable Upgrade

Apple’s iPhone 18 Pro is not a radical redesign, but it is a meaningful refinement where it matters most: heat management and endurance. In day-to-day use, the device feels easier to live with, even if its gains are more literal than dramatic. For buyers weighing another iterative cycle, the improved thermals and battery life may prove more persuasive than headline features.

Just now (07:39 PM IST)
Clean Energy & Climate Transition

First Adult T. rex Footprints Found in North Dakota Open a New Window on Dinosaur Movement

A high school teacher in North Dakota has helped uncover the first known adult Tyrannosaurus rex footprints, a rare fossil find that is reshaping what scientists know about the predator’s size, gait and speed. The nearly one-meter tracks, preserved in the Hell Creek Formation, offer a new data point in a field long dominated by bones rather than direct evidence of how the animal moved.

Just now (07:39 PM IST)