Kiteworks this week urged customers to shut off its platform for a six-hour window on Saturday after receiving what it described as credible threat intelligence from federal agencies warning of possible attacks on some Kiteworks systems.
Frank Balonis, CISO at Kiteworks, told Recorded Future News the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.” The customer email recommended a precautionary shutdown while Kiteworks and law enforcement partners investigate the matter.
Kiteworks advisory and response
Balonis said the advisory was “out of an abundance of caution” and described the notice as preventative rather than a response to a confirmed breach. “We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach. All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version,” he said.
Kiteworks did not answer follow-up questions about whether the issue has been assigned a CVE or which groups might be exploiting the platform. A Kiteworks customer support official told the German outlet that the email was sent out because of a potential “zero-day” vulnerability.
The FBI declined to comment and the Cybersecurity and Infrastructure Security Agency (CISA) did not respond to requests for comment.
Context and industry reaction
Kiteworks, which makes software used for secure or confidential communication, was previously known as Accellion. In December 2020 a Russian group known as Clop exploited a zero-day in an Accellion file transfer tool to steal data from dozens of organisations, including the University of Colorado, the Washington State Auditor Office, Flagstar Bank, Bombardier and Kroger.
Jake Knott, a senior official at cybersecurity firm watchTowr, said his team is actively tracking the current threat but called it unusual and concerning that Kiteworks advised customers to effectively power down production systems. “There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch,” he said, noting the company’s past incidents under the Accellion name.
Kiteworks’ direct customer advisory, the company statements to Recorded Future News and the remarks from security professionals were the primary sources of the information released about the warning and the recommended shutdown window.

