CTIPilot

Kiteworks

product · product:kiteworks

Secure managed file-transfer and confidential-communications platform marketed to government agencies, financial institutions and enterprises; rebranded from Accellion in 2021 after Accellion's FTA product was mass-exploited via a zero-day chain in December 2020. Emailed customers worldwide on 2026-09-25 urging a precautionary six-hour shutdown after receiving unconfirmed law-enforcement threat intelligence of a possible imminent attack (Heise Online / BleepingComputer / TechCrunch / The Record, 2026-09-25).

Also known as: Accellion, Accellion FTA, Accellion File Transfer Appliance, Kiteworks (formerly Accellion)

Coverage timeline
1
first 2026-09-26 → last 2026-09-26
Peak priority
high
1 high
Sources cited
5
5 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
Kiteworks
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-26/kiteworks-precautionary-shutdown-imminent-zero-day-warning · ATT&CK page ↗

Story timeline

  1. 2026-09-26Kiteworks (formerly Accellion) tells customers worldwide to shut down every server for six hours after 'credible' law-enforcement intelligence of an imminent attack, no CVE assigned
    active-threatsA secure-file-transfer vendor with government customers tells its entire customer base to unplug production systems this weekend

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (20%)
  • heise.de1 (20%)
  • security-hub.ncsc.admin.ch1 (20%)
  • techcrunch.com1 (20%)
  • therecord.media1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Kiteworks (1)

2026-09-26 · view entry permalink →

HIGHNATOB2

Kiteworks (formerly Accellion) tells customers worldwide to shut down every server for six hours after 'credible' law-enforcement intelligence of an imminent attack, no CVE assigned

Kiteworks (a secure managed-file-transfer and confidential-communications platform rebranded from Accellion in 2021, marketed to government agencies, financial institutions and enterprises) emailed customers worldwide on 2026-09-25 urging a precautionary six-hour shutdown of every Kiteworks system, staggered by timezone; the Central European window falls 04:00–10:00 CEST on Saturday 2026-09-26, a timezone Switzerland shares (Heise Online, 2026-09-25). CISO Frank Balonis told Heise Online the company "received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend" (Heise Online, 2026-09-25), and recommended shutting systems down even where they are not directly internet-facing, since the possible access route is unconfirmed. No CVE has been assigned, and Kiteworks states plainly it is "not aware of any compromise of Kiteworks systems" and that "all known vulnerabilities are addressed in our current release, 9.5.1" (BleepingComputer, 2026-09-25); the advisory is preventative, not a confirmed-breach response. Researcher Kevin Beaumont's Shodan search found roughly a thousand internet-facing Kiteworks instances, though TechCrunch notes the count is likely an overcount of actually-affected customer systems (TechCrunch, 2026-09-25), and watchTowr's Jake Knott called the request itself unusual: "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch" (The Record, 2026-09-25).

The precedent class is exactly the one that matters for public-sector defenders: BleepingComputer notes that the Clop extortion gang "has a long history of targeting enterprise platforms in data-theft attacks," naming Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer as past victims of that pattern (BleepingComputer, 2026-09-25); no actor has been named or confirmed for this specific warning by Kiteworks, the FBI, or CISA. Kiteworks itself was formerly Accellion, whose FTA product was the subject of exactly this kind of zero-day mass exploitation in December 2020, when a Clop-linked group stole data from dozens of high-profile organizations (The Record, 2026-09-25).

We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend. We strongly recommend you shut down your Kiteworks system for six hours

Kiteworks CISO Frank Balonis, via Heise Online

We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach

All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version.

Kiteworks, statement to BleepingComputer

There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch.

Jake Knott, watchTowr, via The Record (Recorded Future News)
threat26 Sep 04:04Zmulti-sourceOpen finding ↗