Kiteworks urges server shutdowns over cyber threat

Kiteworks told customers to power down some systems before the weekend after law enforcement shared intelligence about a possible imminent attack.
Kiteworks is urging customers to shut down some of its systems after receiving information that hackers may try to target them. The warning carries weight because Kiteworks tools are used to move large files and sensitive data online, and even a precautionary shutdown can disrupt day-to-day work for organizations that depend on them.
The company says the alert is preventive, not a response to a confirmed breach. Even so, it drew attention because Kiteworks asked customers to act before the weekend, citing the possibility of an “imminent” attack and the risk of unknown vulnerabilities. According to IT-PUB News, the company framed the move as a defensive step while it assesses the threat with law enforcement.
Kiteworks says the warning is preventive
Kiteworks confirmed to TechCrunch that it had notified customers about a potential threat. Chief information security officer Frank Balonis said the company had received “credible threat intelligence from law enforcement” suggesting that a threat actor may try to target some Kiteworks systems used by customers.
Balonis said the company recommended a precautionary shutdown window while it and law enforcement partners work through the issue. He also said Kiteworks is not aware of any compromise of its own systems.
That distinction matters. Kiteworks is not saying it has been breached. It is warning customers based on outside intelligence and asking them to take defensive action while the situation is assessed.
Customers were told to shut systems down before the weekend
According to a copy of the email shared with TechCrunch, Kiteworks told customers it was concerned about possible exploitation of vulnerabilities that are not yet known to the company. These are known as zero-day flaws, meaning there is no time for the vendor to patch them before they may be used in an attack.
In the email, Kiteworks urged customers to shut down their systems before the weekend, if not sooner, to “protect against any potential zero-day attacks.” The company said it could not confirm whether there were other paths for improper access.
That is an unusual recommendation. For customers, shutting down a server can be a serious step because it may interrupt internal workflows, file transfers, and communication with users or clients. But keeping systems online during a possible attack window could expose organizations to risk.
The alert reaches customers across multiple sectors
Kiteworks says it has thousands of customers across healthcare, technology, education, automotive, government, and other sectors. The company did not say how many may be affected by the warning.
Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems online, though he noted that the number is likely to be an overcount of affected customer systems.
One healthcare customer told TechCrunch that they received the alert and took down their organization’s server immediately. The person said the outage is causing delays and disrupting doctors’ ability to contact patients.
That helps explain why the warning matters beyond security teams. When a file-transfer system goes offline, the effects can quickly spread into ordinary operations, including patient communication, business documents, and internal coordination.
Kiteworks has faced file-transfer attacks before
The company is not new to major security incidents. Before rebranding from Accellion in late 2021, a vulnerability in its file-transfer application was used in a mass-hacking campaign that affected hundreds of organizations.
In that earlier case, attackers stole data from organizations that used the product to send customer or internal corporate information over the internet. The campaign was part of a wider wave of attacks against file-transfer products.
The goal was to steal copies of data that had been sent online but not deleted from affected servers. The hackers then tried to extort victims by threatening to publish the stolen information unless ransom was paid.
That history helps explain why the current warning is being treated seriously. Kiteworks says there is no confirmed breach in this case, but file-transfer systems have long been attractive targets because they can hold sensitive data from many organizations in one place.
U.S. agencies offered no public detail
Kiteworks did not say which law enforcement agency provided the alert or which hacking group might be behind the threat. The FBI declined to comment. Marco DiSandro, a spokesperson for U.S. cybersecurity agency CISA, also would not comment on the record when asked about the alert.
The lack of detail leaves customers with a difficult call — wait for more information or follow the company’s precautionary advice. Kiteworks has clearly chosen the more cautious path.
For organizations that rely on these systems, the immediate issue is not just whether an attack will happen. It is whether they can keep services running safely while the risk remains unresolved.