FR
live

Kiteworks orders customers to power down servers for six hours over a possible zero-day

On September 25, 2026, Kiteworks CISO Frank Balonis asked every customer to power down their servers for six hours on Saturday after federal intelligence authorities warned of an imminent attack. If you run a managed file transfer appliance, read this as a signal: MFT appliances remain the top target of extortion gangs.

A row of server racks in a dark data center aisle, every status light dark except one amber power LED still glowing.

September 25, 2026. Kiteworks CISO Frank Balonis emails every customer asking them to power down their servers for six hours. Saturday, September 26, 2026. The shutdown window runs from 4:00 a.m. to 10:00 a.m. in Central Europe, and from 10:00 p.m. Friday to 4:00 a.m. Saturday in New York. September 25, 2026. The company confirms it received credible intelligence from U.S. federal authorities. Why it matters: when a vendor asks its entire customer base to take production offline, it is never a hunch. It means the threat is real, quantified, and the vendor prefers a planned outage to a suffered breach.

An unprecedented instruction for a file transfer appliance

Kiteworks is a secure file transfer platform used by government agencies, financial institutions, and enterprises to exchange sensitive documents. Asking customers to shut down such an appliance is not a routine suggestion: it is a service interruption the vendor is willing to defend in front of its customers, which tells you how much it trusts the intelligence it received.

The instruction is precise. According to German outlet Heise, which first reported the email, the window applies worldwide, from Australian Eastern Standard Time to Pacific Daylight Time. In Central Europe, servers must be down between 4:00 a.m. and 10:00 a.m. on Saturday, September 26. The company reportedly recommends powering systems off before the window begins, including systems that are not directly reachable from the internet.

Researcher Jake Knott of watchTowr captures the anomaly: “There is no known CVE, patch, or additional technical details available — but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch.” The tone is credible alert, not routine maintenance.

What Kiteworks knows, and what it will not say

The official wording is deliberately narrow. Asked by BleepingComputer, the company confirmed it received “credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.” Frank Balonis added: “Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter.”

Two sentences bound the disclosure. First, the vendor says it is aware of no compromise: “We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach.” Second, it states that all known vulnerabilities are addressed in the current release, 9.5.1.

The word zero-day appears only on the support side. Contacted by Heise to verify the alert, Kiteworks customer support reportedly justified the instruction this way: “The reason we’re asking you to shut down the servers is to protect against any potential zero-day attacks.” Neither the official statement nor the customer email quoted by Heise confirms that an unknown vulnerability has been found or exploited. The FBI declined to comment, and CISA did not respond to press inquiries.

Accellion, Clop, and the genealogy of a target

To understand why this alert resonates, go back to the company’s former name: Kiteworks was once Accellion. In December 2020, the Clop gang exploited a zero-day in Accellion FTA, the company’s former file transfer product, to steal data from dozens of high-profile organizations, including the University of Colorado, the Washington State Auditor, Flagstar Bank, aircraft maker Bombardier, and retail chain Kroger.

Clop never stopped targeting this product family. The group has chained together compromises of file transfer platforms: Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo, and MOVEit Transfer. Each time the playbook is identical: a flaw in a transfer appliance, a massive document exfiltration, then a threat to publish. The U.S. Department of State now offers a $10 million reward for information linking the gang’s attacks to a foreign government.

“Whilst years have passed and the name has changed, attackers’ appetites for targeting managed file transfer appliances has not, and we have no reason to believe this time will be any different,” Jake Knott warned. Familiar territory, but not the comforting kind.

Why MFT appliances remain the favorite prey

A managed file transfer appliance concentrates everything an extortion gang wants: sensitive documents, centralized, reachable from a single internet-exposed point. Unlike a workstation, it does not sit behind a consumer EDR and is rarely monitored as closely day to day. It is often deployed and then forgotten, with patches applied late.

The value is visible in the economics of the attack. Clop and its imitators do not always encrypt the files: they steal them and threaten to publish. Data-theft extortion requires no ransomware on every machine, only reading a well-stocked filesystem. That is exactly what a transfer appliance offers: a single entry point into an organization’s most confidential exchanges.

The corollary is that trust in the vendor becomes a security asset in its own right. Kiteworks chose transparency over silence: warning customers, even without a CVE, even without a patch, rather than leaving them exposed. That posture is rare, and it deserves to be both praised and followed.

What to do in practice

If you are a Kiteworks customer, follow the instruction to the letter: power the appliance down before the window starts, even if it is not directly reachable from the internet, and keep it off for the full recommended duration. If you are unsure of your version, confirm you are on 9.5.1 or newer, and schedule the upgrade.

bash
# From an admin workstation, verify the appliance is no longer reachable
# after the network cut — both commands should fail.
ping -c 4 <appliance-ip>
curl -m 5 -I https://<appliance-fqdn>

If you cannot power down physically, isolate the appliance from the network: remove the rule that exposes it, close inbound and outbound flows, and keep an out-of-band console path to bring it back. If you run a larger estate, use the alert to inventory your transfer appliances — including any legacy Accellion instances still in service — and confirm they are patched, segmented, and monitored. A transfer appliance should never be the only link protecting sensitive documents.

A new kind of alert

The Kiteworks advisory opens a category that security teams will have to learn to handle: the intelligence-led precautionary shutdown, distinct from the CVE-patch cycle. In the classic cycle, a flaw is found, scored, patched, then shipped. Here the order is inverted: the intelligence precedes any public flaw, and the response is an outage, not a patch.

For a CISO, that changes the decision rule. A vendor notification is no longer just an item to triage in a threat feed: it can become an operational order to execute the same day. The metric to track is no longer only time-to-remediate, but time-to-react to a credible alert — and the ability to stop a sensitive service without improvising, leaning on a runbook written in cold blood. Teams that have one will react in minutes; everyone else will discover, on a Saturday, that powering down an appliance is not obvious.

Verdict

If you are a Kiteworks customer, shut it down. Six hours of downtime on a Saturday costs far less than exfiltrated customer documents, and the credibility of the intelligence justifies the interruption. If you run any managed file transfer appliance, treat this alert as a signal for the whole segment: extortion gangs keep targeting these products because the return on effort is unbeatable, and Kiteworks will not be the last vendor to ask for a precautionary shutdown. The lesson is not “distrust Kiteworks” — it is “distrust whatever you leave behind a file transfer appliance.”

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

CVE-2026-65660 turns Microsoft’s SharePoint ‘spoofing’ flaw into remote code execution

Microsoft described CVE-2026-65660 as a CVSS 6.5 spoofing issue; researcher Dinh Ho Anh Khoa showed it is actually a code-injection flaw (CWE-94) enabling authenticated remote code execution, and CISA added it to the KEV catalog on September 25, 2026 after observed attacks. Apply the August 11 patch and audit your SharePoint 2016, 2019 and Subscription Edition servers.

CISA adds actively exploited WSO2 and Adobe Commerce flaws to its KEV catalog

On September 24, 2026, CISA added the path traversal flaw CVE-2026-5430 in WSO2 and the broken authorization flaw CVE-2026-71362 in Adobe Commerce and Magento to its Known Exploited Vulnerabilities catalog, both of them already exploited in the wild. U.S. federal agencies must patch by September 27, and any organization exposing these products should do the same without waiting.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss