Circuit Wire — a daily news update from the Circuit.
Secure file-transfer company Kiteworks told customers worldwide to shut down their servers this weekend after federal authorities warned that a threat actor may try to target its systems. The company confirmed the advisory to TechCrunch on Friday, September 25, saying it had received credible threat intelligence from law enforcement.
The warning first surfaced through German publication Heise, which reported on an email from Kiteworks chief information security officer Frank Balonis. According to BleepingComputer, the original notice asked customers to take systems offline for six hours on Saturday, September 26. In Central Europe that meant 4:00 a.m. to 10:00 a.m., while in New York the window ran from 10:00 p.m. Friday to 4:00 a.m. Saturday. Customers were told to shut down even systems that were not reachable from the internet.
A company press release dated September 25 described a nine-hour window in each customer's local time zone. Kiteworks said it would shut down the systems it hosts on customers' behalf. Customers who manage their own systems, on premises or on AWS or Azure, had to take them offline themselves.
Balonis said the company acted "out of an abundance of caution." Kiteworks said it has no sign that its own systems or customer systems were compromised. It also said all known vulnerabilities are fixed in its current release, version 9.5.1. Its customer email, shared with TechCrunch, raised concern about flaws not yet known to the company, known as zero-days.
Kiteworks did not name the agency behind the warning or the group it suspects. The FBI declined to comment to TechCrunch, and a CISA spokesperson would not comment on the record. Security researcher Kevin Beaumont pointed to at least 1,000 internet-facing Kiteworks systems, though TechCrunch noted that figure likely overcounts affected customers. One healthcare customer told the outlet the outage was delaying doctors' ability to contact patients.
The company, known as Accellion until its rebrand in late 2021, has been hit before. A flaw in its older file-transfer product let an extortion gang steal data from hundreds of organizations. BleepingComputer notes that the Clop gang has repeatedly targeted file-transfer platforms, including Accellion FTA, GoAnywhere MFT, Cleo and MOVEit Transfer. No group has been publicly linked to the current threat.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

