2026-09-26 · view entry permalink →
Kiteworks (formerly Accellion) tells customers worldwide to shut down every server for six hours after 'credible' law-enforcement intelligence of an imminent attack, no CVE assigned
Kiteworks (a secure managed-file-transfer and confidential-communications platform rebranded from Accellion in 2021, marketed to government agencies, financial institutions and enterprises) emailed customers worldwide on 2026-09-25 urging a precautionary six-hour shutdown of every Kiteworks system, staggered by timezone; the Central European window falls 04:00–10:00 CEST on Saturday 2026-09-26, a timezone Switzerland shares (Heise Online, 2026-09-25). CISO Frank Balonis told Heise Online the company "received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend" (Heise Online, 2026-09-25), and recommended shutting systems down even where they are not directly internet-facing, since the possible access route is unconfirmed. No CVE has been assigned, and Kiteworks states plainly it is "not aware of any compromise of Kiteworks systems" and that "all known vulnerabilities are addressed in our current release, 9.5.1" (BleepingComputer, 2026-09-25); the advisory is preventative, not a confirmed-breach response. Researcher Kevin Beaumont's Shodan search found roughly a thousand internet-facing Kiteworks instances, though TechCrunch notes the count is likely an overcount of actually-affected customer systems (TechCrunch, 2026-09-25), and watchTowr's Jake Knott called the request itself unusual: "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch" (The Record, 2026-09-25).
The precedent class is exactly the one that matters for public-sector defenders: BleepingComputer notes that the Clop extortion gang "has a long history of targeting enterprise platforms in data-theft attacks," naming Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer as past victims of that pattern (BleepingComputer, 2026-09-25); no actor has been named or confirmed for this specific warning by Kiteworks, the FBI, or CISA. Kiteworks itself was formerly Accellion, whose FTA product was the subject of exactly this kind of zero-day mass exploitation in December 2020, when a Clop-linked group stole data from dozens of high-profile organizations (The Record, 2026-09-25).
We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend. We strongly recommend you shut down your Kiteworks system for six hours
We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach
All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version.
There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch.