A technician monitors server racks in a data center, with a world map and clocks displayed behind her.
Kiteworks, which makes secure file-transfer software, has asked customers around the world to switch their servers off for six hours this weekend. The company says it has no confirmed breach, no public CVE and no named attacker. What it does have is a warning from law enforcement. Nobody asks every customer to take production systems offline over a weekend without a serious reason, so administrators should act on this rather than wait and see.

What Kiteworks told customers​

According to Heise, the German outlet that first reported the story, Kiteworks CISO Frank Balonis wrote to customers that the company had received "credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend." BleepingComputer reported that the notice tells customers the company is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window.

Kiteworks confirmed the warning to several outlets. In its statement to BleepingComputer, the company said it had "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers," and added: "Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter."

Balonis gave TechCrunch the same message. He stressed: "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach."

The shutdown window, by time zone​

The reported window is 4:00 a.m. to 10:00 a.m. on Saturday, September 26 in Central Europe, which is 10:00 p.m. Friday to 4:00 a.m. Saturday on the US East Coast (according to Heise's reporting as relayed by SC Media). Heise says the notice covers time zones from Australian Eastern Standard Time to Pacific Daylight Time.

Those two anchor times are the same moment: 02:00 to 08:00 UTC on Saturday, September 26. Our own conversions, which you should check against the notice you actually received, are below.

RegionApproximate local window
UTCSat 02:00 – 08:00
Central Europe (CEST)Sat 04:00 – 10:00
US Eastern (EDT)Fri 22:00 – Sat 04:00
US Pacific (PDT)Fri 19:00 – Sat 01:00
Australia East (AEST)Sat 12:00 – 18:00

Two more details from the reporting matter here:

  • Shut down before the window opens. Kiteworks reportedly recommends taking servers down ahead of the start time. TechCrunch saw the customer email and says Kiteworks urged customers to shut down their systems before the weekend, if not sooner.
  • Internal servers are included. Heise reports that Kiteworks said even servers that are not accessible from the internet should be shut down.

Is this a zero-day or not?​

Probably, but nobody has confirmed it.

When Heise phoned Kiteworks support to confirm the email was genuine, it was told: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks." TechCrunch says the customer email itself raised concern about vulnerabilities Kiteworks does not yet know about, and said the company cannot confirm whether there are other potential routes for improper access.

BleepingComputer points out that neither the statement provided to BleepingComputer nor the customer notification quoted by Heise confirms that a zero-day vulnerability has been discovered or exploited. The company's official line is that all currently known vulnerabilities are fixed in version 9.5.1.

That leaves version 9.5.1 as necessary but not sufficient. If the worry is a flaw Kiteworks hasn't found yet, being fully patched won't protect you from it. That explains why the advice is to power off rather than to install an update.

Security researchers have noticed the odd wording too. Jake Knott, head of threat intelligence at watchTowr, told SC Media that asking customers to shut down is "both unusual and never a good sign, especially when the remediation is the power button." He added that there is no known CVE, patch, or additional technical detail available.

Nick DiCola of Zero Networks went further. He argued that if non-exposed systems must also go down, "then you have to assume the Zero-Day is something already running on the system and has a C2 channel waiting for a command to 'execute.'" That is one expert's reading, and Kiteworks has not confirmed it. Still, it is a reasonable explanation for why being unreachable from the internet apparently isn't enough.

What we don't know​

  • Which agency sent the warning, or who the attacker is. Kiteworks did not say, when asked, which law enforcement agency alerted the company or which hacking group may be behind the threat. The FBI declined to comment, and a CISA spokesperson would not comment on the record. Heise notes that Germany's BSI and BKA hadn't responded either, although it said the authenticity of the warning message is beyond doubt anyway.
  • How many customers are affected. Kiteworks says on its website that it has thousands of customers across healthcare, technology, education, automotive, and government. Researcher Kevin Beaumont pointed to at least a thousand internet-facing Kiteworks systems online today; though the number is likely an overcount of affected customer systems.
  • When it's safe to restart, and how. None of the reporting includes a restart time, an alternative mitigation, indicators of compromise, or whether hosted and self-hosted deployments get different instructions.

Why file-transfer platforms keep getting hit​

The pattern is familiar. Because secure file-sharing platforms commonly store sensitive documents, they are a valuable target for cybercriminals who conduct data-theft extortion attacks.

Kiteworks has been through this before. TechCrunch notes that before it rebranded from Accellion in late 2021, a vulnerability in its file-transfer application allowed an extortion gang to mass-hack and steal data from hundreds of organizations. The attackers went after copies of the data that had been previously sent over the internet but not deleted from the affected servers.

BleepingComputer adds that although it is not known which threat actor is linked to these potential attacks, the Clop extortion gang has a long history of targeting enterprise platforms in data-theft attacks, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. That history is context only. No evidence links Clop, or anyone else, to this warning.

What Kiteworks admins should do tonight​

This checklist is our editorial guidance based on the reporting. It is not an official Kiteworks procedure.

  1. Find the vendor notice. Look for Kiteworks' direct email to your organisation and use the time zone it gives. Don't rely on conversions like ours.
  2. Plan to be offline before the window starts. For the US East Coast that means before 10 p.m. Friday. Include internal-only instances too.
  3. Check you're on 9.5.1. Kiteworks recommends the latest release. That covers known bugs only, not whatever prompted this warning.
  4. Tell the business. Partners and staff who depend on secure file transfer need to know it will be unavailable, and need an approved alternative so nobody starts emailing sensitive files as attachments.
  5. Don't restart blindly. Wait for Kiteworks to give restart guidance rather than guessing when the six hours are "probably fine."
  6. Look back as well as forward. Review logs for anything unusual on your Kiteworks systems. Clean up old stored files you no longer need, since stale data on file-transfer servers is exactly what past extortion campaigns stole.

Bottom line​

Kiteworks is essentially saying: we can't tell you what the threat is, but switch everything off anyway. That is frustrating for admins, and some will question how much the vendor is holding back. The company does deserve some credit for warning customers in advance, when the alternative might have been a breach notice next week. Six hours of downtime costs far less than a mass data-theft campaign. For self-hosted Kiteworks shops, especially in regulated industries, doing what Kiteworks asks is the cautious choice, and there isn't much time left to do it.