Skip to main content
CybersecurityIncident Response

Kiteworks Resumes Operations After Heeding Federal Threat Intel

Secure server room with rows of equipment racks and muted lighting.

“Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them,” Chief Information Security Officer Frank Balonis wrote in Kiteworks’ statement, explaining why the company ordered a weekend shutdown for customers in response to what it called “credible threat intelligence” from federal authorities.

Kiteworks ordered a precautionary shutdown over a federal warning

Kiteworks told customers on Monday they could resume normal operations after a weekend-long precautionary shutdown that the company said was prompted by “credible threat intelligence” from federal authorities. The recommendation — issued last week — asked customers to take production systems offline ahead of a potential imminent attack. Kiteworks also shut down the environments it hosts on customers’ behalf. By Sunday, the company said continuous monitoring showed no abnormal activity and lifted the advisory.

What Kiteworks found: a critical Advanced Forms vulnerability and a rapid patch

During the shutdown, Kiteworks said it discovered a previously unknown critical vulnerability in Advanced Forms, its secure data collection tool. Advanced Forms is used by fewer than 1% of Kiteworks’ customers — a group the company estimated at approximately 50 organizations. Kiteworks said its other products, including file collaboration, file transfer, email encryption and managed file transfer, were unaffected.

The company reported that it developed and deployed a fix during the shutdown window and that it has no indication the Advanced Forms vulnerability was ever exploited. Kiteworks said all known vulnerabilities are addressed in release 9.5.1 and recommended that customers run that version.

Federal intelligence and industry coordination during the weekend

Kiteworks attributed its precaution to intelligence provided by federal authorities, saying the intelligence met a threshold it considered “credible.” The company said it worked with federal intelligence authorities throughout the weekend and shared threat intelligence with industry partners, including Mandiant. Kiteworks declined to identify which federal authorities supplied the intelligence or which hacking group prompted the warning.

CEO Jonathan Yaron framed the action as a deliberate, customer-focused choice: “Our customers gave up their weekend on our recommendation, at short notice and at difficult hours, and many of their teams worked through the night alongside ours,” Yaron said. “The industry standard is to wait for proof of an attack. We would rather be proactive on credible warning than wait for certainty and be too late. That is the standard we intend to keep.”

How customers, security teams, and vendors are responding

  • Customers using Kiteworks’ hosted environments: The majority of customers resumed normal operations after Kiteworks lifted the advisory Monday; organizations using Advanced Forms (about 50) were specifically identified as those who should ensure they are running release 9.5.1.
  • Security teams at affected organizations: They carried out the offline windows called for by Kiteworks, worked alongside Kiteworks security staff through the night, monitored for abnormal activity, and applied the vendor’s updates during the outage window.
  • Other vendors and industry partners: Kiteworks’ choice to act on intelligence and to share findings with partners such as Mandiant shows a coordinated posture that industry partners accepted during the weekend response, even as Kiteworks declined to name the authorities or the adversary that triggered the warning.

Context from Kiteworks’ corporate history and final observations

Kiteworks is a California-based company that rebranded in October 2021 from its former name, Accellion. The company’s statement recalls that rebranding followed a vulnerability in its legacy file transfer appliance that allowed an extortion gang to breach hundreds of organizations; that campaign was part of a broader wave of attacks on file transfer products. The weekend shutdown and the prompt patch for Advanced Forms underline Kiteworks’ stated posture: prioritizing proactive action on credible warnings even when that imposes short-term costs on customers.

Two concrete details remain part of the record: Kiteworks says it found and fixed a critical vulnerability in Advanced Forms and that continuous monitoring turned up no evidence of exploitation; it also says it will press customers to run release 9.5.1. The company’s decision not to name the federal authorities or the hacking group that prompted the warning leaves open which intelligence sources and adversary indicators produced the “credible threat intelligence” that generated the shutdown.

Original story on CyberScoop