Kiteworks to customers: shut down your systems; cyberattack imminent
A zero-day warning has been sent via email to customers worldwide, industry insiders say.

Image by Kiteworks
- Kiteworks urged customers to shut down systems for six hours over an imminent zero-day threat.
- No CVE, patch, or technical details are available yet.
- Researchers warn file-transfer systems remain lucrative targets for attackers.
- Kiteworks supports secure file transfers and communications for 100 million-plus users globally.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Kiteworks on Friday is urging customers to temporarily shut down all Kiteworks systems after credible threats from law enforcement warned the company of an imminent zero-day attack.
Signed by CEO Jonathan Yaron, the content communications company fired off an email asking customers to shut down Kiteworks servers for a six-hour window on Saturday – between 02:00 and 08:00 UTC – based on “credible intelligence” from authorities.
Kiteworks handles workflows such as managed file transfer (MFT), secure file sharing, secure email, web forms, and APIs – and can run on-site, in private clouds, or as a hybrid model.
According to its website, its 1500+ customer base includes large corporations, healthcare organizations, and government agencies, serving more than 100 million end users globally.
Why Kiteworks is sounding the alarm
Jake Knott, head of threat intelligence at watchTowr, tells Cybernews his team is now “actively tracking the emerging threat to Kiteworks appliances,” noting that when a company suggests customers shut down their servers, it’s “not only unusual but never a good sign.”
A potential zero-day leaves defenders helpless against exploits, Knott says, pointing out there are "no known CVEs, patches, or additional technical details available" – likely prompting what could be the only solution to protect its customers from unauthorized data access and loss.
Managed File Transfer appliances remain an extremely lucrative and achievable target for attackers of every motivation – allowing for both initial and immediate access to sensitive information that can be used for extortion or further pivoting,said Jake Knott, head of threat intelligence at watchTowr.
And while researchers are likely “throwing the codebase through their favourite LLMs” hoping to find a quick fix, unfortunately Knott says, so are the attackers.
“Vulnerabilities impacting MFT appliances rarely remain a secret for long, and typically rapidly accelerate from targeted exploitation to indiscriminate, in-the-wild exploitation," he says.
Kiteworks no stranger to zero-day attacks
Formerly known as Accellion, the California-based company changed its name in 2021 to match its now signature secure-content platform, Kiteworks.
The change also happened following a series of devastating hacks on an end-of-life system known as the Accellion File Transfer Appliance (FTA).
Attackers – later linked to the Cl0p ransomware gang – managed to exploit a total of four previously unknown FTA vulnerabilities, since added to the CISA-run KEV catalog.
The zero-days, which led the attackers to compromise FTA servers, steal data, and extort victims, hit government, healthcare, legal, telecommunications, finance, and energy sectors worldwide.
Whilst years have passed and the name has changed, attackers' appetites for targeting MFT appliances have not, and we have no reason to believe this time will be any different,explains Jake Knott, head of threat intelligence at watchTowr.
“In other words, this is familiar territory, but not the comforting kind, “ Knott said.
On an interesting note, Knott also believes Friday’s publicity could wind up pushing the hackers “back underground” – at least for now.
This may give Kiteworks just enough time to develop a patch and deploy it before any potential strike might happen.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.