Kiteworks asked its customers to temporarily shut down their systems for six hours on September 26 after being warned of a potential attack . The company has not confirmed a breach or active exploitation, but describes the move as a precautionary measure .

According to BleepingComputer, Kiteworks informed customers worldwide that it had received credible information from security authorities. The recommendation was for a six-hour window, and the company reportedly requested the outage even before the suggested time.
See also: ShinyHunters hacked the dark web site of the Cl0p gang
Kiteworks' warning of possible attack
Frank Balonis, Kiteworks' chief security officer, said a threat actor may be attempting to target systems used by customers. The company is working with authorities and calls the directive "preemptive," not a reaction to a confirmed breach.
The initial customer advisory referred to potential zero-day attacks because Kiteworks was unable to rule out unknown unauthorized access routes. However, this does not prove that a specific vulnerability exists, that exploit code has been identified, or that attackers have already entered an environment.
The potential attack therefore remains a risk scenario and not a confirmed incident. Organizations need to separate the warning from the documented findings in order to properly inform their management, partners and customers. The absence of a public technical indicator also makes it difficult to check for common signs of a breach.
TechCrunch reported that the recommendation was linked to a message that mentioned a possible attack over the weekend. The report does not name the service that provided the information, the threat group or a specific product, and does not include a CVE number.

What customers know about the six-hour outage
The proposed window was 04:00 to 10:00 in Central Europe, with the corresponding times varying by region. The directive applied to Kiteworks’ systems even when they were not directly accessible from the internet, which increases operational costs for organizations with critical file flows.
Kiteworks provides tools for securely transferring large files and sensitive data to government agencies, businesses, and healthcare organizations. One healthcare customer confirmed to TechCrunch that its server went down immediately, resulting in delays in doctors communicating with patients.
See also: Progress ShareFile: Combination of vulnerabilities allows RCE attacks
The decision to even take down non-publicly accessible systems shows that Kiteworks views the potential attack as a risk that is not necessarily limited to the internet perimeter. At the same time, such an outage could impact automation, file sharing, and processes that rely on continuous availability.
The company was formerly known as Accellion, a name associated with a serious attack on FTA file transfer tool installations in 2020. This historical experience explains why a warning without technical details led to such a strong operational recommendation, but does not confirm that today's incident is the same.
Immediate actions for Kiteworks facilities
Version 9.5.1 is the current version that Kiteworks presents as having fixed all known vulnerabilities. Administrators should confirm the version, follow the company's direct update, and record which systems were taken down and when they were brought back up.
The implementation of version 9.5.1 should not be taken as proof that the risk has been eliminated. Unknown vulnerabilities are not included in the publicly released fixes, so a combination of notification, temporary isolation, and monitoring is required. Any reconnection should be done with a documented fallback plan.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The SecNews technical team recommends, in addition to implementing the directive, checking log files, administrator accounts, and recent changes to network rules to detect a potential attack in a timely manner. Particular attention should be paid to unknown connections, new processes, and unusual data transfers before restoring servers.

See also: Oracle fixes zero-day used by Clop
Recorded Future News notes that there is no publicly known CVE or confirmed breach, so organizations should take the warning seriously and not present as fact something that the available information still indicates is likely.
The choice to discontinue illustrates the difficult balance between availability and prevention. Until more technical details are available, the safest approach for Kiteworks customers is to follow the guidance, use version 9.5.1, and carefully verify before reconnecting.
