Kiteworks is telling customers to take their systems offline after the company said it received credible threat intelligence from law enforcement warning that hackers may target some Kiteworks systems used by customers. The file-transfer vendor confirmed the customer notification to TechCrunch, following an initial report by German publication Heise, which cited an email describing an attack that could arrive as soon as this weekend. Kiteworks said the warning is a precaution and that it has no knowledge of any compromise of its own systems.
The company's chief information security officer, Frank Balonis, said Kiteworks received the intelligence from law enforcement and notified customers directly. He described the recommendation as a precautionary shutdown window while the company and its law enforcement partners investigate, and said the advisory was preventative rather than a response to a confirmed breach. Kiteworks declined to identify which law enforcement agency provided the tip or which hacking group might be responsible. The FBI declined to comment, and CISA spokesperson Marco DiSandro would not comment on the record about the alert.
In an email to customers sent Friday and shared with TechCrunch, Kiteworks said it was concerned about exploitation of vulnerabilities currently unknown to the company. Such flaws are called zero-day bugs because the vendor has no time to fix them before attackers use them. The email urged customers to shut down their systems before the weekend, if not sooner, because Kiteworks cannot confirm whether other paths for improper access exist. Balonis said the company has fixed all known vulnerabilities in its latest software release, version 9.5.1, which it recommends all customers use.
The scope of the potential impact is not clear. Kiteworks states on its website that it serves thousands of customers in healthcare, technology, education, automotive and government, among other sectors. Security researcher Kevin Beaumont pointed to a listing showing at least a thousand internet-facing Kiteworks systems online, though that figure is likely an overcount of affected customer systems.
One Kiteworks customer in healthcare told TechCrunch the organization received the alert and took its server down immediately. The person, who asked not to be named publicly, said the outage is delaying and disrupting doctors' ability to reach their patients.
Kiteworks has faced serious cyberattacks before. Prior to rebranding from Accellion in late 2021, a vulnerability in its file-transfer application let an extortion gang mass-hack and steal data from hundreds of organizations that used the product to move customer or internal corporate data over the internet. That campaign targeted file-transfer products broadly, with hackers stealing copies of data previously sent over the internet but not deleted from affected servers, then holding it for ransom and threatening to publish victims' information if they did not pay.
More cybersecurity news from TechManNews.








