Kiteworks advises clients to turn off their servers due to an ‘imminent’ risk of cyberattack

Kiteworks advises clients to turn off their servers due to an ‘imminent’ risk of cyberattack

The technology powerhouse Kiteworks is advising its clients to shut down their systems following alerts that suggest hackers might be looking to target them.

Kiteworks (previously known as Accellion), which provides tools for transmitting large files and sensitive data online, confirmed to TechCrunch that it had alerted its clients regarding a potential security threat. The story was initially reported exclusively by the German outlet Heise, which referenced an email from Kiteworks to its customers regarding an “imminent” attack that might occur as soon as this weekend.

In an email response on Friday, Kiteworks’ chief information security officer Frank Balonis informed TechCrunch that the company “received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.”

“As a precautionary measure, we directly notified customers and advised a preventive shutdown window while we and our law enforcement partners investigate this issue,” stated Balonis. “We have yet to identify any compromise of Kiteworks systems, and this advisory is intended to be preventative rather than a reaction to a confirmed breach.”

When inquired, Kiteworks did not disclose which law enforcement agency informed the company or which hacking group might be responsible for the threat. The FBI and the U.S. Department of Homeland Security’s CISA did not provide comments to TechCrunch regarding the Kiteworks notice to customers.

Balonis noted that the company has resolved all known vulnerabilities in its most recent software version, 9.5.1, which it recommends to all customers.

According to a copy of the email sent to clients on Friday and shared with TechCrunch, the company expressed concerns about the exploitation of currently unknown vulnerabilities to Kiteworks. These issues are referred to as zero-day flaws because they provide the vendor—here, Kiteworks—no opportunity to address the vulnerabilities before they are exploited.

In the email, Kiteworks urged clients to deactivate their systems before the weekend, if possible, to “shield against any prospective zero-day attacks,” given that the company cannot ascertain whether there are additional possible entry points for unauthorized access.

It remains unclear how many clients might be impacted, but Kiteworks states on its website that it serves thousands of customers in healthcare, technology, education, automotive, and government sectors, among others. Security researcher Kevin Beaumont highlighted that at least a thousand Kiteworks systems are presently visible online.

Kiteworks is familiar with cyberattacks. Prior to its rebranding from Accellion in late 2021, a flaw in its file-transfer application allowed a ransomware group to extensively hack and extract data from hundreds of organizations that depended on the product for transmitting customer or internal corporate data over the internet.

This extensive hack formed part of a larger hacking initiative targeting file transfer solutions, aimed at capturing data that had been sent online but not deleted from the compromised servers. The hackers subsequently held the data for ransom, threatening to publicly disclose clients’ information if the affected organizations did not comply with their demands.

Do you have more information regarding the threat facing Kiteworks customers? Are you one of the affected clients of Kiteworks? We’d be eager to hear from you. You can securely contact this reporter via Signal at zackwhittaker.1337, or reach him by email at [email protected].

If you purchase through links in our articles, we may earn a small commission. This does not influence our editorial independence.

Leave a Reply