Security News

Kiteworks Lifts Emergency Shutdown After Government Tip-Off on Possible Attack

Infosecurity Magazine · 29 Sept 2026
Key Takeaway Businesses using managed file transfer tools should keep software fully updated and act quickly on vendor security advisories, even when no breach has been confirmed.

Managed file transfer provider Kiteworks has told customers they can bring their systems back online after a highly unusual precautionary shutdown. The company had asked self-hosted customers, including those running on AWS or Azure, to power down for nine hours on 25 September, while it did the same for systems it hosts itself.

Kiteworks CISO Frank Balonis said the move followed 'credible threat intelligence from federal intelligence authorities' suggesting a threat actor may target some Kiteworks systems. He stressed the action was preventative, with no confirmed breaches reported, and that all known vulnerabilities have been addressed in the current 9.5.1 release. Customers running self-hosted Advanced Forms have been asked to contact support for further assistance.

The exact nature of the threat remains unclear, though some in the security community suspect it may relate to an undisclosed zero-day vulnerability. File transfer platforms have become frequent targets for cybercriminals in recent years, with vendors including Accellion, GoAnywhere, Cleo and MOVEit all previously breached. The 2023 MOVEit campaign, linked to the Cl0p extortion group, compromised nearly 3,000 organisations and exposed data belonging to more than 90 million people downstream.

managed file transfer Kiteworks vulnerability management data security incident response

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.