Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
Kiteworks advised customers to shut down servers after receiving law enforcement intelligence about an imminent cyberattack. The company cited potential zero-day vulnerabilities in its file transfer platform and recommended immediate precautionary measures. No confirmed breach occurred, but the advisory highlights urgent risks for organizations relying on Kiteworks for sensitive data transfers.

Kiteworks received credible threat intelligence from law enforcement regarding a potential imminent attack on customer systems. The company expressed concern about unknown bugs that could allow improper access before fixes are available. Frank Balonis, the chief information security officer, stated these unknowns are referred to as zero-day flaws because vendors lack time to patch them before exploitation occurs. No confirmed compromise of systems has been reported by the organization. Alerts were sent to customers who use the platform for transferring large files and sensitive datasets. While the exact number of impacted entities remains unclear, the firm claims thousands of clients exist across sectors including healthcare, government, and automotive. Security researcher Kevin Beaumont identified a listing of at least a thousand internet-facing systems, though he noted this figure likely overcounts actual affected customer infrastructure. The company recommended a precautionary shutdown of servers before the weekend to protect against potential attacks. All users were advised to install the latest software release, identified as version 9.5.1, which contains fixes for known vulnerabilities. This guidance came as a preventative measure rather than a response to an active breach. One healthcare client reported that complying with the shutdown caused operational disruptions for patient communication.