{"id":3491915,"date":"2026-09-25T15:52:13","date_gmt":"2026-09-25T15:52:13","guid":{"rendered":"https:\/\/techingeek.com\/index.php\/2026\/09\/25\/kiteworks-advises-clients-to-turn-off-their-servers-due-to-an-imminent-risk-of-cyberattack\/"},"modified":"2026-09-25T15:52:13","modified_gmt":"2026-09-25T15:52:13","slug":"kiteworks-advises-clients-to-turn-off-their-servers-due-to-an-imminent-risk-of-cyberattack","status":"publish","type":"post","link":"https:\/\/techingeek.com\/index.php\/2026\/09\/25\/kiteworks-advises-clients-to-turn-off-their-servers-due-to-an-imminent-risk-of-cyberattack\/","title":{"rendered":"Kiteworks advises clients to turn off their servers due to an \u2018imminent\u2019 risk of cyberattack"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/techingeek.com\/wp-content\/uploads\/2026\/09\/kiteworks-advises-clients-to-turn-off-their-servers-due-to-an-imminent-risk-of-cyberattack.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The technology powerhouse Kiteworks is advising its clients to shut down their systems following alerts that suggest hackers might be looking to target them.<\/p>\n<p class=\"wp-block-paragraph\">Kiteworks (previously known as Accellion), which provides tools for transmitting large files and sensitive data online, confirmed to TechCrunch that it had alerted its clients regarding a potential security threat. The story was initially reported exclusively by the German outlet Heise, which referenced an email from Kiteworks to its customers regarding an \u201cimminent\u201d attack that might occur as soon as this weekend.<\/p>\n<p class=\"wp-block-paragraph\">In an email response on Friday, Kiteworks&#8217; chief information security officer Frank Balonis informed TechCrunch that the company \u201creceived credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cAs a precautionary measure, we directly notified customers and advised a preventive shutdown window while we and our law enforcement partners investigate this issue,\u201d stated Balonis. \u201cWe have yet to identify any compromise of Kiteworks systems, and this advisory is intended to be preventative rather than a reaction to a confirmed breach.\u201d<\/p>\n<p class=\"wp-block-paragraph\">When inquired, Kiteworks did not disclose which law enforcement agency informed the company or which hacking group might be responsible for the threat. The FBI and the U.S. Department of Homeland Security&#8217;s CISA did not provide comments to TechCrunch regarding the Kiteworks notice to customers.<\/p>\n<p class=\"wp-block-paragraph\">Balonis noted that the company has resolved all known vulnerabilities in its most recent software version, 9.5.1, which it recommends to all customers.<\/p>\n<p class=\"wp-block-paragraph\">According to a copy of the email sent to clients on Friday and shared with TechCrunch, the company expressed concerns about the exploitation of currently unknown vulnerabilities to Kiteworks. These issues are referred to as zero-day flaws because they provide the vendor\u2014here, Kiteworks\u2014no opportunity to address the vulnerabilities before they are exploited.<\/p>\n<p class=\"wp-block-paragraph\">In the email, Kiteworks urged clients to deactivate their systems before the weekend, if possible, to \u201cshield against any prospective zero-day attacks,\u201d given that the company cannot ascertain whether there are additional possible entry points for unauthorized access.<\/p>\n<p class=\"wp-block-paragraph\">It remains unclear how many clients might be impacted, but Kiteworks states on its website that it serves thousands of customers in healthcare, technology, education, automotive, and government sectors, among others. Security researcher Kevin Beaumont highlighted that at least a thousand Kiteworks systems are presently visible online.<\/p>\n<p class=\"wp-block-paragraph\">Kiteworks is familiar with cyberattacks. Prior to its rebranding from Accellion in late 2021, a flaw in its file-transfer application allowed a ransomware group to extensively hack and extract data from hundreds of organizations that depended on the product for transmitting customer or internal corporate data over the internet.<\/p>\n<p class=\"wp-block-paragraph\">This extensive hack formed part of a larger hacking initiative targeting file transfer solutions, aimed at capturing data that had been sent online but not deleted from the compromised servers. The hackers subsequently held the data for ransom, threatening to publicly disclose clients&#8217; information if the affected organizations did not comply with their demands.<\/p>\n<p class=\"wp-block-paragraph\"><strong><em>Do you have more information regarding the threat facing Kiteworks customers? Are you one of the affected clients of Kiteworks? We\u2019d be eager to hear from you. You can securely contact this reporter via Signal at zackwhittaker.1337, or reach him by email at zack.whittaker@techcrunch.com.<\/em><\/strong><\/p>\n<\/div>\n<p><em>If you purchase through links in our articles, we may earn a small commission. This does not influence our editorial independence.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/techingeek.com\/wp-content\/uploads\/2026\/09\/kiteworks-advises-clients-to-turn-off-their-servers-due-to-an-imminent-risk-of-cyberattack.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The technology powerhouse Kiteworks is advising its clients to shut down their systems following alerts that suggest hackers might be looking to target them.<\/p>\n<p class=\"wp-block-paragraph\">Kiteworks (previously known as Accellion), which provides tools for transmitting large files and sensitive data online, confirmed to TechCrunch that it had alerted its clients regarding a potential security threat. The story was initially reported exclusively by the German outlet Heise, which referenced an email from Kiteworks to its customers regarding an \u201cimminent\u201d attack that might occur as soon as this weekend.<\/p>\n<p class=\"wp-block-paragraph\">In an email response on Friday, Kiteworks&#8217; chief information security officer Frank Balonis informed TechCrunch that the company \u201creceived credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cAs a precautionary measure, we directly notified customers and advised a preventive shutdown window while we and our law enforcement partners investigate this issue,\u201d stated Balonis. \u201cWe have yet to identify any compromise of Kiteworks systems, and this advisory is intended to be preventative rather than a reaction to a confirmed breach.\u201d<\/p>\n<p class=\"wp-block-paragraph\">When inquired, Kiteworks did not disclose which law enforcement agency informed the company or which hacking group might be responsible for the threat. The FBI and the U.S. Department of Homeland Security&#8217;s CISA did not provide comments to TechCrunch regarding the Kiteworks notice to customers.<\/p>\n<p class=\"wp-block-paragraph\">Balonis noted that the company has resolved all known vulnerabilities in its most recent software version, 9.5.1, which it recommends to all customers.<\/p>\n<p class=\"wp-block-paragraph\">According to a copy of the email sent to clients on Friday and shared with TechCrunch, the company expressed concerns about the exploitation of currently unknown vulnerabilities to Kiteworks. These issues are referred to as zero-day flaws because they provide the vendor\u2014here, Kiteworks\u2014no opportunity to address the vulnerabilities before they are exploited.<\/p>\n<p class=\"wp-block-paragraph\">In the email, Kiteworks urged clients to deactivate their systems before the weekend, if possible, to \u201cshield against any prospective zero-day attacks,\u201d given that the company cannot ascertain whether there are additional possible entry points for unauthorized access.<\/p>\n<p class=\"wp-block-paragraph\">It remains unclear how many clients might be impacted, but Kiteworks states on its website that it serves thousands of customers in healthcare, technology, education, automotive, and government sectors, among others. Security researcher Kevin Beaumont highlighted that at least a thousand Kiteworks systems are presently visible online.<\/p>\n<p class=\"wp-block-paragraph\">Kiteworks is familiar with cyberattacks. Prior to its rebranding from Accellion in late 2021, a flaw in its file-transfer application allowed a ransomware group to extensively hack and extract data from hundreds of organizations that depended on the product for transmitting customer or internal corporate data over the internet.<\/p>\n<p class=\"wp-block-paragraph\">This extensive hack formed part of a larger hacking initiative targeting file transfer solutions, aimed at capturing data that had been sent online but not deleted from the compromised servers. The hackers subsequently held the data for ransom, threatening to publicly disclose clients&#8217; information if the affected organizations did not comply with their demands.<\/p>\n<p class=\"wp-block-paragraph\"><strong><em>Do you have more information regarding the threat facing Kiteworks customers? Are you one of the affected clients of Kiteworks? We\u2019d be eager to hear from you. You can securely contact this reporter via Signal at zackwhittaker.1337, or reach him by email at zack.whittaker@techcrunch.com.<\/em><\/strong><\/p>\n<\/div>\n<p><em>If you purchase through links in our articles, we may earn a small commission. This does not influence our editorial independence.<\/em><\/p>\n","protected":false},"author":2,"featured_media":3491916,"comment_status":"open","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3491915","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/posts\/3491915"}],"collection":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/comments?post=3491915"}],"version-history":[{"count":0,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/posts\/3491915\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/media\/3491916"}],"wp:attachment":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/media?parent=3491915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/categories?post=3491915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/tags?post=3491915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}