Skip to content

Kiteworks asks customers to shut down servers this weekend

Kiteworks asked every customer to shut down its servers for six hours on Saturday, September 26, after law enforcement warned of an imminent attack.

By Tech AI Wire Team

3 min read

XLinkedIn
A gloved hand pressing the power button on a rack-mounted server in a dim data center aisle, with one amber status light lit.

Kiteworks has told its customers to shut down their Kiteworks servers this weekend, after law enforcement warned the company that an attack may be imminent. The warning, reported by TechCrunch on September 25, 2026, points to a possible zero-day flaw. That is a security hole the vendor does not know about yet, so no patch exists for it.

Kiteworks sells software for sending large files and sensitive data between organizations. Its customers include banks, insurers and government bodies, so a successful attack could expose exactly the data these systems exist to protect.

What Kiteworks told customers

Kiteworks chief information security officer Frank Balonis said the company had "received credible threat intelligence from law enforcement." The warning indicated "that a threat actor may attempt to target some Kiteworks systems for customers," he told TechCrunch.

"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window," Balonis said. The company and its "law enforcement partners work through the matter" in the meantime.

Kiteworks stresses that nothing has been breached yet. "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach," Balonis said. According to TechCrunch, the company says it has fixed all known vulnerabilities in its latest release, version 9.5.1.

The shutdown window

heise online reports the details of the request:

DetailWhat Kiteworks asked for
Length6 hours
DateSaturday, September 26, 2026
Central European time4 a.m. to 10 a.m.
Which systemsAll customer systems worldwide, any version
Internal serversShut down too, even if not internet-facing

The last point is unusual. Kiteworks told customers that "it cannot be said with certainty what potential access routes there might be," heise reports. A Kiteworks support message explained the reason plainly: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks."

TechCrunch adds that Kiteworks urged customers to shut down "before the weekend, if not sooner."

How many systems are exposed

Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems, TechCrunch reports. The German outlet heise says customers in Germany include several state banks, insurance companies, a media group, consulting firms and well-known automotive suppliers. Google's Mandiant security unit works with Kiteworks, according to heise.

Why file-transfer software is a target

This company has been here before. Kiteworks was called Accellion until a rebrand in late 2021. Before that rebrand, TechCrunch notes, a flaw in its file-transfer application let an extortion gang mass-hack hundreds of organizations that used the product. That attack was part of a broader campaign against file-transfer products.

These tools are attractive to attackers for a simple reason. They sit on the edge of a company's network, face the internet and hold sensitive files by design. One flaw can open many victims at once.

What this means for developers

If your organization runs Kiteworks, confirm today that someone owns the shutdown. Check the exact window for your time zone in the customer notice, and plan it with the teams whose file transfers will stop.

Find the hidden dependencies before the servers go dark. Scheduled jobs, partner integrations and scripts that push files through Kiteworks will fail during the window. Pause them or queue them, so they do not retry against a dead endpoint or lose data.

Upgrade to 9.5.1 before bringing systems back, since that is the release Kiteworks says fixes every known flaw. Then review access logs from the last few weeks for unusual logins or large downloads.

The wider lesson applies to any file-transfer or edge appliance. Keep an inventory of which of these systems you run and which are reachable from the internet. Know who can shut one down quickly. This time the warning came before the attack, which rarely happens.

Sources

  1. Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack - TechCrunch
  2. Imminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down Servers - heise online

Related articles

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.