Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks urged a nine-hour customer shutdown after a federal warning of a possible attack.
Kiteworks told customers to shut down systems for nine hours after federal intelligence authorities said a threat actor might target some Kiteworks systems. CISO Frank Balonis said there is no evidence customer systems were compromised and called the shutdown preventative. The company said known vulnerabilities are fixed in release 9.5.1 and that subsidiaries including Zivver, DRACOON, and ownCloud are unaffected. Formerly Accellion, Kiteworks was targeted by Clop in 2020-2021 through zero-days in its file-transfer software.
- Federal intelligence warned of a possible imminent attack on some Kiteworks systems.
- Kiteworks found no customer compromise and called the nine-hour shutdown preventative.
- Known vulnerabilities are addressed in software release 9.5.1.
- Subsidiaries including ownCloud, Zivver, and DRACOON are not affected.
- Clop previously exploited Accellion zero-days in 2020-2021 for data theft.
Full article275 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 26, 2026Threat Intelligence / Vulnerability
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief Information Security Officer (CISO) at Kiteworks.
"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities."
The company said it has not found any evidence that its customers' systems have been compromised, emphasizing the advisory is preventative rather than a response to a confirmed hack. The development was first reported by German news publication Heise.
Kiteworks did not disclose which law enforcement agency alerted the company, or who may be behind it. The American software firm said all known vulnerabilities have been addressed in its latest software release, 9.5.1, recommending that customers apply the patches for optimal protection.
Other subsidiaries of Kiteworks, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder, are not affected.
Kiteworks also revealed that it has sent an email to all customers detailing the specific hours as well as the recommended nine-hour timeframe.
In late 2020-early 2021, the Clop threat actor (aka UNC2546) was found exploiting multiple zero-day vulnerabilities in its file transfer program to conduct a data theft and extortion campaign targeting high-profile entities.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: