Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 27, 2026 · 7 min read

Kiteworks Zero Day Warning: Why It Told Customers to Unplug

On September 25, 2026, Kiteworks, the secure file sharing company formerly known as Accellion, told customers worldwide to power down their servers over the weekend after federal authorities warned that a threat actor may target its systems. There is still no CVE, no named attacker, and no technical detail.

Vendors almost never tell every customer to switch off production. Kiteworks did exactly that on Friday. CISO Frank Balonis wrote to customers that the company had received "credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend," according to the customer email first reported by Heise. A support agent was blunter: "The reason we're asking you to shut down the servers is to protect against any potential zero-day attacks."

The last time this company's software was hit by a zero day, it became one of the defining data theft campaigns of 2021.

Key Takeaways

  • Kiteworks asked customers to shut down their systems on Saturday, September 26, 2026, with early customer emails naming a six hour window from 02:00 to 08:00 UTC and the company's official press release describing a nine hour window in local time zones.
  • Frank Balonis, Kiteworks' CISO, said the warning came from "federal intelligence authorities" and that the company is "not aware of any compromise of Kiteworks systems."
  • Kiteworks 9.5.1 addresses all known vulnerabilities, yet the vendor still asked customers to go offline, which suggests the concern is a flaw nobody has patched yet.
  • Clop, the extortion gang behind the 2020 to 2021 Accellion FTA attacks, has since hit GoAnywhere, MOVEit and Cleo file transfer products, though no source has tied this warning to Clop.
  • As of September 27, 2026, Kiteworks had published no CVE, no patch beyond 9.5.1, and no public all clear.
An empty corporate server room at night with one rack powered down and dark while a laptop on a crash cart beside it shows a shutdown screen

What Did Kiteworks Tell Customers?

Kiteworks told customers to take their Kiteworks systems offline over the weekend of September 26, 2026, even systems that are not reachable from the internet. According to BleepingComputer, the first emails set the window at 4:00 to 10:00 a.m. Central European time, or 10:00 p.m. Friday to 4:00 a.m. Saturday in New York.

The company's formal press release, dated September 25, describes a "nine-hour precautionary shutdown" and says the exact hours went to each customer by email. It also splits responsibility:

  • Customers who run Kiteworks themselves, on premises or in AWS or Azure, must shut the systems down on their own.
  • Kiteworks shuts down the customer systems it hosts.
  • Subsidiary products, including Zivver, DRACOON, totemo and ownCloud, are not affected.

Balonis told The Record that "this advisory is preventative rather than a response to a confirmed breach. All known vulnerabilities are addressed in our current release, 9.5.1." The FBI declined to comment. CISA did not respond.

Why Would a Vendor Ask Everyone to Unplug Production?

A vendor asks for a full shutdown when it believes attackers have a working exploit for a flaw it cannot yet fix. Jake Knott of watchTowr put it plainly to Computer Weekly: "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch."

Read the two statements side by side. Kiteworks says 9.5.1 fixes every known vulnerability. It also says shut 9.5.1 down. The only way both are true is if the threat sits outside the known list, which is the working definition of a zero day. Patching to the latest release, the standard answer to almost every vendor advisory, was not enough here, and Kiteworks effectively said so.

The instruction to power down internal systems matters too. Balonis said the company could not rule out indirect access paths, so network isolation alone was not treated as a safe substitute.

Has Clop Done This Before?

Yes. Clop has built its business on zero days in file transfer software, starting with this vendor. In December 2020 the gang exploited Accellion's legacy File Transfer Appliance, and CISA advisory AA21-055A later listed four CVEs, CVE-2021-27101 through CVE-2021-27104, plus a web shell disguised as an about.html page. Victims named by The Record include Kroger, Flagstar Bank, Bombardier, the University of Colorado and the Washington State Auditor's Office.

The pattern then repeated:

  • GoAnywhere MFT, January 2023: Clop claimed data from roughly 130 victims over 10 days, per CISA advisory AA23-158A.
  • MOVEit Transfer, May 2023: exploitation of CVE-2023-34362 began on May 27, the Saturday of the US Memorial Day weekend.
  • Cleo, December 2024: CISA added CVE-2024-50623 to its Known Exploited Vulnerabilities catalog on December 13.
  • Oracle E-Business Suite, 2025: the campaign behind the Michelin and Oracle EBS breaches.

That is at least five mass exploitation campaigns since December 2020, and the MOVEit wave began on a holiday weekend, when fewer defenders were watching. A warning aimed at one specific Saturday fits that playbook. Still, no one has publicly named the actor, and Clop spent the same week dealing with ShinyHunters hijacking its leak site. Treat any attribution as a guess until Kiteworks or the FBI says otherwise.

What Happened After the Shutdown Window?

As of Sunday, September 27, no public follow up had appeared: no CVE, no new build, no indicators of compromise and no confirmation that an attack was attempted. The cost of the shutdown was real, though. TechCrunch heard from one healthcare customer whose patient communications were disrupted once the system went offline.

Kiteworks says it protects more than 100 million end users. A nine hour outage at that scale is a large bet, and the vendor made it without telling customers what it was protecting them from.

What Should Kiteworks Admins Do Now?

Kiteworks admins should confirm the shutdown happened, preserve evidence, and only restore service once the vendor gives a clear go ahead. The Kiteworks advisory and the Accellion history suggest this checklist:

  • Know your deployment: hosted tenants are handled by Kiteworks; on premises, AWS and Azure instances are your job.
  • Snapshot before you restart: keep authentication, admin and network logs covering at least the week before September 26.
  • Confirm the version: make sure every node runs 9.5.1 before it comes back online.
  • Check egress: look for unusually large outbound transfers, new admin accounts, and unfamiliar files in web directories. The 2020 attackers hid a web shell behind an innocent page name.
  • Rotate secrets on any anomaly: service accounts, API keys and SSO or LDAP bind credentials connected to Kiteworks.
  • Verify vendor messages: confirm restoration guidance through your account contact or support@kiteworks.com, not a link in an unexpected email.

What Should Compliance Teams Document?

Compliance teams should record the vendor notice, the time systems went down and came back, and the evidence reviewed, because a later CVE could turn a precaution into a reportable incident. Under GDPR Article 33, a controller has 72 hours from becoming aware of a personal data breach to notify its supervisory authority. If Kiteworks later confirms exploitation before September 26, that clock may depend on what you logged this weekend.

Clop's file transfer campaigns stole data rather than encrypting it. They copy files and extort, the exfiltration only model that leaves no ransom note to trigger an incident response. Vendor risk reviews should ask how quickly each file transfer supplier can push a shutdown order, and whether your team can actually carry one out on a Friday night.

What This Means for Your Inbox

Kiteworks is email infrastructure for many regulated organizations. Banks, insurers and hospitals use it to send attachments too sensitive for ordinary email, so a secure link lands in your inbox and the file stays on a Kiteworks server. Heise reported that its German customers include state banks, insurance companies and Google's Mandiant unit. If one of those servers is breached, the contracts, medical records and tax files you received as "secure" links are exactly what gets copied.

Kiteworks also owns two email encryption brands, totemo and Zivver. The company says neither is affected. For recipients, the practical advice is simple: if a bank or clinic sends you a "shared file" email this week, confirm it through a channel you already trust before you click. Fake file sharing notices are a standard phishing lure, and an incident that has thousands of organizations sending unusual messages to customers gives attackers cover.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.