Skip to main content
Threat IntelligenceEmerging Threats

Kiteworks Alerts Customers to Possible Cyber Attack, Urges 9-Hour System Shutdown

Rows of computer servers and networking equipment in a data center.

"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief Information Security Officer at Kiteworks.

Frank Balonis and Kiteworks' advisory

The statement from Frank Balonis is the central fact in a precautionary move by Kiteworks (formerly Accellion). The company said it received what it described as "credible threat intelligence" from federal intelligence authorities and, "out of an abundance of caution," notified customers directly. Kiteworks emphasized the advisory is preventative: it reported no evidence that customer systems have been compromised.

The nine-hour shutdown window

Kiteworks recommended a specific, temporary action — a nine-hour shutdown of affected systems over the weekend. The company said it has communicated the recommended timeframe and the exact hours to customers by email. Kiteworks framed the shutdown as a mitigation measure while it "continue[s] to work through the matter with federal intelligence authorities," rather than as a response to a detected intrusion.

Software release 9.5.1 and patch guidance

In the same advisory, Kiteworks said "all known vulnerabilities have been addressed in its latest software release, 9.5.1," and it recommended customers apply those patches "for optimal protection." The company pointed customers toward that release as a risk-reduction step concurrent with the temporary shutdown guidance.

Unaffected subsidiaries: Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, 123FormBuilder

Kiteworks explicitly identified a group of subsidiaries that it said are not affected by this advisory: Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder. The company’s statement separated those entities from the systems it warned could be targeted, limiting the scope of the precaution to Kiteworks systems themselves.

Clop (aka UNC2546): historical context cited by Kiteworks

Kiteworks' advisory included a reminder of an earlier, related episode: in late 2020–early 2021, the Clop threat actor (also referenced as UNC2546) was found exploiting multiple zero-day vulnerabilities in a file transfer program to conduct a data-theft and extortion campaign targeting high-profile entities. Kiteworks did not link the current intelligence to any specific actor, but it invoked that past activity as a relevant precedent for why a preventive shutdown and patching would be prudent.

How technologists, affected enterprises, and federal intelligence authorities are positioned

  • Technologists and security teams: Kiteworks has sent an email to all customers detailing the specific hours and the recommended nine-hour timeframe. From the company’s instructions, technology teams are positioned to implement the scheduled shutdown and to apply release 9.5.1 as the immediate defensive steps Kiteworks has recommended.
  • Affected enterprises and procurement leaders: Organizations that use Kiteworks systems received a direct customer notice and were given a short, concrete mitigation plan — a temporary shutdown plus a patch. The advisory puts operational and scheduling questions on those customers to reconcile the nine-hour window with business continuity needs.
  • Federal intelligence authorities: Kiteworks credited "federal intelligence authorities" with providing the credible threat intelligence and said it is working with those authorities while the company monitors the situation. Kiteworks did not disclose which agencies provided the intelligence or identify the potential threat actor.

First public reporting on the advisory was carried by the German publication Heise, and Kiteworks' direct customer communications and the company statement remain the source of the technical and operational details.

The immediate facts are narrow: Kiteworks has advised a precautionary nine-hour shutdown, has sent customers the specific hours, reports no evidence of compromise, and urges installation of release 9.5.1 to address known vulnerabilities. Missing from the company’s public statement are the identity of the federal agency that provided the intelligence and any attribution for who might be behind the possible attack — facts Kiteworks said it did not disclose. Kiteworks also noted its other named subsidiaries are not affected.

The next, concrete signals will be whether customers follow the instructed shutdown and apply 9.5.1, and whether Kiteworks or federal authorities disclose any further details about the origin or nature of the intelligence. For now, the company’s precautionary steps and its reference to the 2020–2021 Clop activity provide the full public record Kiteworks has put on the table.

Source: https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html