Kiteworks Lifts Emergency Shutdown After Government Tip-Off on Possible Attack
Managed file transfer provider Kiteworks has told customers they can bring their systems back online after a highly unusual precautionary shutdown. The company had asked self-hosted customers, including those running on AWS or Azure, to power down for nine hours on 25 September, while it did the same for systems it hosts itself.
Kiteworks CISO Frank Balonis said the move followed 'credible threat intelligence from federal intelligence authorities' suggesting a threat actor may target some Kiteworks systems. He stressed the action was preventative, with no confirmed breaches reported, and that all known vulnerabilities have been addressed in the current 9.5.1 release. Customers running self-hosted Advanced Forms have been asked to contact support for further assistance.
The exact nature of the threat remains unclear, though some in the security community suspect it may relate to an undisclosed zero-day vulnerability. File transfer platforms have become frequent targets for cybercriminals in recent years, with vendors including Accellion, GoAnywhere, Cleo and MOVEit all previously breached. The 2023 MOVEit campaign, linked to the Cl0p extortion group, compromised nearly 3,000 organisations and exposed data belonging to more than 90 million people downstream.