Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Software company Kiteworks sent a warning to customers this week urging them to shut off the company’s platform over the weekend due to concerns over potential cyberattacks or intrusions.
The email to customers, first reported by German news outlet Heise, recommends customers shut down their systems during a six-hour window on Saturday.
In response to inquiries about the message, Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter,” Balonis said.
“We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach. All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version."
Kiteworks did not respond to follow up questions about whether the bug had a CVE yet or what groups are exploiting the platform. The company makes popular software used for secure or confidential communication.
The FBI declined to comment and the Cybersecurity and Infrastructure Security Agency (CISA) did not respond to requests for comment.
A Kiteworks customer support official told Heise that the email was sent out due to a potential “zero-day” vulnerability but did not elaborate.
Kiteworks was previously known as Accellion and operated a popular file transfer tool until an incident in December 2020 where a Russian hacking group known as Clop used a zero-day vulnerability to steal data from dozens of high-profile companies. The organizations breached included the University of Colorado, the Washington State Auditor Office, Flagstar Bank, airplane maker Bombardier, and U.S. retail store chain Kroger.
Jake Knott, a senior official at cybersecurity firm watchTowr, said they are actively tracking the threat but noted how unusual and concerning it is that Kiteworks suggested customers essentially turn off the power on their servers.
“There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch,” he said, noting the past incidents Kiteworks went through under the Accellion name.
“Whilst years have passed and the name has changed, attackers' appetites for targeting [managed file transfer] appliances has not, and we have no reason to believe this time will be any different. In other words, this is familiar territory, but not the comforting kind.”
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



