The short answer
Kiteworks told customers to switch off self-managed file-transfer servers for a weekend window because law enforcement warned of a possible attack, likely through an unknown flaw. Nothing is confirmed as breached, and version 9.5.1 fixes every known bug. Still, a vendor asking customers to unplug is rare. It is a good moment for a security audit of your internet-facing systems, starting with the ones that store partner files.
The wider lesson: a file-transfer box on the internet edge is a high-value target, and you need a plan for running without it for a day.
What did Kiteworks announce?
On Friday, September 25, 2026, Kiteworks emailed customers that it had received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target Kiteworks systems. German outlet heise online first reported the email. Kiteworks then published a public advisory and confirmed the details to TechCrunch and BleepingComputer.
The request was blunt: shut systems down. Customers who run Kiteworks themselves, on-premises or in their own AWS or Azure accounts, had to power down during a set window. Kiteworks said it would do the same for hosted customers. Reports differ on the length. BleepingComputer cited a six-hour window starting at 02:00 UTC on Saturday, September 26, while the company’s public advisory refers to a nine-hour window in each customer’s local time zone.
CISO Frank Balonis said Kiteworks has no indication that its systems or customer systems have been compromised and called the step preventative. The company says version 9.5.1 fixes every currently known vulnerability. As of Sunday, September 27, no CVE, new build or indicators of compromise had been published. The FBI declined to comment to TechCrunch, and CISA declined to comment on the record. Kiteworks says its subsidiaries, including Zivver, DRACOON, totemo and ownCloud, are not affected.
Why are file-transfer servers such a target?
Managed file transfer (MFT) systems sit at the network edge and hold exactly what attackers want: contracts, patient records, payroll files and data exchanged with suppliers and banks. Kiteworks says its customers include healthcare, education, automotive manufacturing, technology and government organizations. TechCrunch reported that one healthcare customer said the shutdown disrupted contact between doctors and patients.
The history explains the caution. In 2021 the Clop group used zero-days in Accellion FTA, the product Kiteworks grew out of, to steal data from hundreds of organizations and extort them. The same playbook later hit MOVEit Transfer, GoAnywhere MFT and Cleo. Each time, one flaw in one product turned into a mass data theft, usually over a holiday or weekend when fewer people were watching.
What it means for US & EU software teams
First, know which file-transfer systems you actually run. MFT servers often come in through a single department or an acquired company and never reach the main asset list. If you do not know the version, owner and internet exposure of every such server, this weekend showed why you should.
Second, plan for downtime you do not choose. A precautionary shutdown stops partner exchanges, claims files and customer uploads. Teams that had a fallback, such as a second secure channel or a queue that holds transfers until the server returns, lost a few hours. Teams without one lost business processes. Build that fallback before you need it.
Third, the compliance clock only starts if data leaks, but you must be able to prove it did not. If an MFT server holding personal data is compromised, GDPR gives you 72 hours to notify the regulator. NIS2 entities owe a 24-hour early warning, and HIPAA-covered US organizations have their own breach rules. Logs that show who accessed which files, kept off the server itself, are what let you say “nothing was taken.”
What should you do now?
- Follow the vendor guidance. If you run Kiteworks, confirm you received and followed the shutdown notice, and do not restart until Kiteworks gives the all-clear through its support channels.
- Upgrade to 9.5.1. Kiteworks says this version fixes all known vulnerabilities. Check every instance, including test and disaster-recovery servers.
- Cut internet exposure. Put admin interfaces behind VPN or zero-trust access, restrict inbound traffic to partner IP ranges where you can, and remove servers nobody uses.
- Move logs off the box. Send access and file-activity logs to a central SIEM so you can review them even if the server itself is compromised.
- Hunt, then watch. Look for unknown admin accounts, unusual large downloads and new files in web directories. Watch for a CVE or indicators of compromise from Kiteworks, CISA or national CERTs in the coming days.
Frequently asked questions
What did Kiteworks ask customers to do?
On September 25, 2026, Kiteworks asked customers who run its secure file-transfer platform themselves, on-premises or in their own AWS or Azure accounts, to shut the systems down for a precautionary window over the weekend of September 26. Kiteworks said it would shut down hosted customer instances itself.
Has Kiteworks been breached?
Kiteworks says no. CISO Frank Balonis said the company has no indication that Kiteworks or customer systems have been compromised and described the notice as preventative. It was triggered by credible threat intelligence from law enforcement that a threat actor may try to target Kiteworks systems.
Is there a CVE or a patch?
As of September 27, 2026, no CVE, new build or indicators of compromise had been published. Kiteworks says version 9.5.1 fixes all currently known vulnerabilities and recommends that customers run it. The concern is a possible zero-day, a flaw the vendor does not yet know about.
Which Kiteworks products are affected?
The advisory covers the Kiteworks platform. Kiteworks says its subsidiaries, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder, are not affected.
Why does a file-transfer server matter so much?
Managed file transfer systems sit on the internet edge and hold the files companies exchange with partners, often contracts, health records and financial data. The Clop group mass-exploited zero-days in Accellion FTA in 2021, the predecessor of Kiteworks, and later in MOVEit Transfer, GoAnywhere and Cleo, stealing data from hundreds of organizations each time.
Sources
Kiteworks — Precautionary Shutdown Advisory (September 25, 2026)
TechCrunch — Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
BleepingComputer — Kiteworks urges server shutdown over potential zero-day attacks
heise online — Imminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down Servers