Monday, September 28, 2026

Kiteworks lifts shutdown order after incident-free weekend

Managed file transfer (MFT) services provider Kiteworks has rescinded a temporary shutdown recommendation asking its customers to turn off their appliances for six hours on the morning of Saturday 26 September, after no security incidents took place.

In a statement published on Sunday 27 September, the company said its recommendation was lifted for all customers and it was now safe to bring their systems back online.

The firm said that all “known” vulnerabilities were addressed in the current release, and that there remained no indication of any system compromises, either at Kiteworks itself, or across its customer base.

Kiteworks chief information security officer Frank Balonis said: “Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems.

“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities,” said Balonis.

“We have no indication that Kiteworks or our customers’ systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach,” he reiterated.

“Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version.”

The brief shutdown affected customers who self-managed their Kiteworks systems, either on-premise or via their Amazon Web Services (AWS) or Azure environments.

Computer Weekly understands that Kiteworks pulled the plug itself on systems that it hosts on behalf of its customers during the same window – 2am to 8am GMT (3am to 9am BST) – all appliances run as part of such a managed service are now also back online and running normally.

At the time of writing, the threat is not thought to have affected any other Kiteworks subsidiaries, such as Zivver, Dracoon, totemo, ownCloud, Wamnet, Maytech, Bonfy.ai, or 123FormBuilder.

Unusual move

The highly-unusual recommendation to shut down potentially vulnerable appliances came amid speculation that an as-yet undisclosed zero-day was being exploited in the wild, possibly by a ransomware gang.

Since MFT products and services are particularly valuable targets for threat actors, who use them to conduct large-scale supply chain cyber attacks on multiple downstream users, the recommendation was not necessarily without merit.

Indeed, Kiteworks, which was formerly known as Accellion prior to a 2021 rebrand, has been on the receiving end of such cyber attacks before

A 2021 incident saw high-profile customers including aviation specialist Bombardier, cyber firm Qualys, fossil fuel giant Shell, and telco Singtel targeted, among others.

However, according to an email to customers, posted to Reddit, Kiteworks hinted its core MFT product was unaffected by the issue, which appears to have existed only in its Advanced Forms product.

Also known as Secure Data Forms, the Advanced Forms product is a relatively recent introduction to the company’s portfolio and is in use at only a limited subset of customers – many of them organisations required to comply with US government FedRAMP standards.

According to the customer email, those organisations have been receiving direct guidance from Kiteworks through an extended shutdown process.

Related Articles

Latest Articles