News

Kiteworks Orders Customers to Kill Servers After Feds Warn of an Imminent Zero-Day Attack

Kiteworks told customers to shut down their file-transfer servers for nine hours after federal authorities warned an attacker may target them. No breach has been confirmed.

Kiteworks Orders Customers to Kill Servers After Feds Warn of an Imminent Zero-Day Attack

Security vendors almost never tell their customers to pull the plug. Kiteworks just did. The secure file-transfer company is asking its entire customer base to shut down their systems this weekend after federal authorities warned that an attacker may be about to strike.

Kiteworks CISO Frank Balonis said the company received credible threat intelligence from federal intelligence and law enforcement that a threat actor may try to target some customer systems. The company's press release lays out a nine-hour precautionary shutdown window this weekend, timed to each customer's local time zone.

The split matters for who does the work. Customers running Kiteworks themselves, on premises or in AWS or Azure, have to power their systems down on their own. Kiteworks is shutting down the systems it hosts. Its subsidiaries Zivver, DRACOON, totemo and ownCloud are not affected.

A zero-day nobody has named

Kiteworks says there is no known compromise and calls the move preventative. Known vulnerabilities were fixed in release 9.5.1. The worry is what nobody knows yet. A customer email, first reported by Heise, urged the shutdown to protect against potential zero-day attacks and flagged concern about unknown vulnerabilities and improper access routes.

There is no public CVE and no named attacker. The FBI declined to comment, and CISA offered nothing on the record, The Record reported.

The history explains why nobody is taking chances. Kiteworks used to be called Accellion, and its legacy File Transfer Appliance was the entry point for the Clop gang's December 2020 campaign, which spilled data from dozens of organizations. File-transfer tools remain a favorite target, and Clop's brand still echoes through the underground, as the recent ShinyHunters takeover of the Clop leak site showed.

The cost of unplugging

watchTowr researcher Jake Knott called asking a whole customer base to take production offline unusual and concerning. The disruption is real, too. A healthcare customer told TechCrunch the outage kept doctors from contacting patients.

For now, this is a warning and not a confirmed breach, and there is no evidence every customer was hit. Whether the nine-hour blackout turns out to be an overreaction or the thing that kept Accellion's history from repeating depends on what the federal tip was actually about, and nobody is saying yet.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free