Kiteworks Urges Customers to Shut Down Systems Amidst Credible Threat Intelligence
Secure communication software provider **Kiteworks** has issued an unprecedented warning to its customers, advising them to temporarily shut down their systems over a weekend. The move comes in response to "credible threat intelligence" from federal authorities, suggesting a potential targeted cyberattack or intrusion.
Software company **Kiteworks** has sent an urgent advisory to its customers, recommending a precautionary shutdown of their platforms. The warning, initially reported by German news outlet **Heise**, suggested a six-hour shutdown window on a Saturday.
**Frank Balonis**, CISO at **Kiteworks**, confirmed the advisory, stating the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers."
### Proactive Measures Against Unconfirmed Threat
Balonis emphasized the preventative nature of the warning. "Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter," he explained. He further clarified, "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach. All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version."
Details surrounding the potential threat remain scarce. **Kiteworks** has not disclosed whether a **CVE** has been assigned to any potential vulnerability or which threat groups might be involved. The **FBI** declined to comment, and the **Cybersecurity and Infrastructure Security Agency (CISA)** did not respond to inquiries.
### Echoes of Past Incidents
A customer support official for **Kiteworks** reportedly informed **Heise** that the email was prompted by a potential "zero-day" vulnerability, though no further details were provided.
This incident brings to mind **Kiteworks'** past as **Accellion**, a period marked by a significant security breach in December 2020. During that event, the Russian hacking group **Clop** exploited a zero-day vulnerability in **Accellion's** file transfer tool, leading to data theft from numerous high-profile organizations. Victims included the **University of Colorado**, the **Washington State Auditor Office**, **Flagstar Bank**, **Bombardier**, and **Kroger**.
### Unusual and Concerning Precaution
**Jake Knott**, a senior official at cybersecurity firm **watchTowr**, highlighted the unusual and concerning nature of **Kiteworks'** recommendation. "There is no known CVE, patch, or additional technical details available β but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch," he stated.
Knott drew parallels to the previous **Accellion** incidents, noting that while the company name has changed, the appetite of attackers for targeting managed file transfer (MFT) appliances has not diminished. "In other words, this is familiar territory, but not the comforting kind," he concluded.