Kiteworks has told customers worldwide to take their servers offline as part of a Kiteworks zero-day server shutdown precaution, after the company said it received credible threat intelligence from federal authorities warning that an attack may be imminent. The request, which is preventative rather than a response to any confirmed breach, asks customers to keep systems dark for a six-hour window.

According to Sophos, reports emerged on 25 September that Kiteworks emailed customers warning that law enforcement had alerted the company to a potentially imminent cyberattack, possibly involving the exploitation of a zero-day vulnerability. The recommended shutdown window was between 02:00 and 08:00 UTC on 26 September, or sooner if customers could manage it.

What Kiteworks Told Its Customers

Kiteworks CISO Frank Balonis sent an email to customers stating the company had received ‘credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend,’ according to German technology publication Heise. The notification reportedly instructed customers to shut down their Kiteworks systems for a six-hour window, with the advice applying globally, from Australian Eastern Standard Time through to Pacific Daylight Time.

In Central Europe, the shutdown window ran from 4:00 a.m. to 10:00 a.m. on Saturday 26 September. Customers in New York were advised to take systems offline from 10:00 p.m. Friday through to 4:00 a.m. Saturday. The company also recommended shutting down ahead of the scheduled window and said customers should take systems offline even if they are not directly internet-accessible.

Kiteworks confirmed the advisory to BleepingComputer, stating: ‘Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers. Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter.’

The company was explicit that no breach has been confirmed. ‘We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach,’ it said, adding that all known vulnerabilities are addressed in version 9.5.1 and recommending customers run the latest release.

Zero-Day Fears and the Silence From Regulators

The phrase ‘zero-day’ has circled the story without being formally confirmed by the company. When Heise contacted Kiteworks customer support to verify the original warning, support staff reportedly said the shutdown recommendation was intended to ‘protect against any potential zero-day attacks.’ That wording goes further than the company’s official statements to BleepingComputer, which describe only a precautionary measure based on law enforcement intelligence, and confirm that all currently known vulnerabilities are patched in the current release.

On the regulatory side, the silence has been conspicuous. According to Penligent, the FBI declined to comment when asked about the alert, and CISA would not comment on record. That kind of institutional quiet is not unusual in live threat situations, but it leaves the precise nature and source of the intelligence unconfirmed from the government side.

Why Secure File-Transfer Platforms Are Prime Targets

Kiteworks develops secure file-transfer and communications products used by government organisations, financial institutions, and enterprises. Platforms of this type store sensitive documents at scale, making them attractive targets for cybercriminals who conduct data-theft extortion campaigns.

The Clop extortion gang has a well-documented history of targeting enterprise file-transfer platforms in exactly this fashion, exploiting vulnerabilities in Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. No threat actor has been identified as linked to this specific intelligence, and it is not known whether Clop is involved. The U.S. Department of State has offered a $10 million reward for information linking Clop’s attacks to a foreign government.

Kiteworks has said it and its law enforcement partners continue to work through the matter, with customers advised to remain on version 9.5.1 while the situation develops.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version