Threat Intelligence

Kiteworks Tells Customers to Power Down for Nine Hours Amid Cyber Attack Warning

The Hacker News · 26 Sept 2026
Key Takeaway If you use Kiteworks or its file transfer products, follow the vendor's shutdown guidance closely and ensure you are running the latest patched software version.

Kiteworks, formerly known as Accellion, has urged its customers to shut down systems for nine hours as a precaution after receiving credible threat intelligence from federal intelligence authorities warning that a threat actor may target its systems. CISO Frank Balonis said the company notified customers directly and recommended the shutdown window while it continues working with authorities on the matter.

The company stressed there is currently no evidence that any customer systems have been compromised, and that the advisory is preventative rather than a response to a confirmed breach. It has not disclosed which agency provided the warning or who may be behind the potential attack. Kiteworks said all known vulnerabilities have been fixed in its latest software release, version 9.5.1, and is recommending customers apply this update for optimal protection. Other Kiteworks-owned brands, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder, are not affected.

This situation echoes a previous incident involving Accellion in late 2020 and early 2021, when the Clop threat actor group exploited zero-day vulnerabilities in its file transfer software to steal data and extort high-profile organisations. That history adds weight to the current precautionary measures being taken.

Kiteworks file transfer security threat intelligence data breach prevention vendor advisory

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.