Kiteworks Urges Server Shutdown Over Imminent Zero Day Threat
Kiteworks urges customers to shut servers before the weekend after law enforcement warned of a possible zero-day attack, though no breach is confirmed.
Summary
On Friday, September 25, 2026, Kiteworks, formerly Accellion, told customers to shut down systems before the weekend, if not sooner, after credible law enforcement intelligence indicated a threat actor may target some customer deployments. CISO Frank Balonis called the shutdown precautionary: Kiteworks knows of no compromise but cannot rule out unknown access routes or zero-day flaws. The company did not identify the agency or attacker; the FBI and CISA did not respond to requests for comment.
Balonis said release 9.5.1 fixes all known vulnerabilities and should be installed by every customer. Exposure is unclear: Kiteworks says thousands of healthcare, technology, education, automotive and government customers use its sensitive-data transfer tools, while researcher Kevin Beaumont found at least 1,000 internet-facing systems. Before rebranding in late 2021, an Accellion file-transfer flaw let an extortion gang steal retained data from hundreds of organizations in a wider campaign and threaten publication unless ransoms were paid.
Positives
- Kiteworks says no system compromise is known, making the shutdown advisory preventative rather than a response to a confirmed breach.
- Release 9.5.1 fixes every vulnerability currently known to Kiteworks, and the company recommends all customers upgrade.
- Credible law enforcement intelligence prompted direct customer warnings before the threatened weekend attack window.
Risks & concerns
- Unknown zero-day flaws or other access routes may remain despite Kiteworks fixing all known vulnerabilities.
- At least 1,000 internet-facing Kiteworks systems could present a substantial attack surface.
- Thousands of customers across healthcare, technology, education, automotive and government may face exposure or precautionary shutdowns.
- Kiteworks has not identified the threat actor or law enforcement agency behind the warning.
- An Accellion flaw previously enabled an extortion gang to steal retained data from hundreds of organizations before the late 2021 rebrand.