Skip to content
Expecting cyber attack, Kiteworks tells users to turn off servers

Expecting cyber attack, Kiteworks tells users to turn off servers

Computerweekly • September 25, 2026

Kiteworks has warned users of its products to shut down their managed file transfer (MFT) servers immediately after apparently being alerted to the existence of a highly-dangerous zero-day vulnerability .

The company, formerly known as Accellion, bills itself as providing a secure control plane for data exchange. However, thanks to the utility of its core file transfer product in spreading malware and other nasties it has become a serial target for threat actors attempting to compromise multiple downstream users via software supply chain attacks.

At the time of writing, the latest vulnerability to draw attention has not yet been assigned a CVE designation and no information has been made public as to the conditions in which it becomes exploitable.

The shutdown notice – which was first reported by Germany-based outlet Heise , citing an email to customers it received – applies worldwide for a six-hour period on Saturday 26 September, from 3am to 9am in the UK, but the organisation has suggested servers are shut down prior to that.

“We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend,” said Frank Balonis, Kiteworks chief information security office (CISO), in the email.

In a further statement, Balonis said he was unaware of any compromise of Kiteworks services, and said the move was being taken “out of an abundance of caution”.

Jake Knott, head of threat intelligence at Watchtowr , a vulnerability management platform provider, confirmed he was actively tracking an emerging threat to Kiteworks appliances.

Knott said that the suggestion a customer shut off their servers was both highly unusual, and a very bad sign.

“There is no known CVE, patch, or additional technical details available - but nobody requests that their entire customer base to unplug production systems over the weekend because of a hunch,” he said.

“Managed File Transfer appliances remain an extremely lucrative and achievable target for attackers of every motivation, allowing for both Initial Access and immediate access to sensitive information that can be used for extortion, or further pivoting,” Knott told Computer Weekly via email.

“Vulnerabilities impacting MFT appliances rarely remain a secret for long, and typically rapidly accelerate from targeted exploitation to indiscriminate, in-the-wild exploitation, with both researchers and attackers likely already throwing the codebase through their favourite LLMs.”

Knott said Kiteworks’ somewhat vague assertions raised multiple questions, particularly given it has asked users to power off systems that do not face the internet. “What is the vulnerability, what specifically does it impact, how is it exploited and has “turn it off and leave it off” officially become a security control?” he mused.

But while he said Kiteworks customers should heed its advice, it was also entirely possible that the publicity around the undisclosed zero-day might push attackers underground for now.

MFT: A target for ransomware

Cleo, Fortra, Progress Software, and Kiteworks ‘ancestor’ Accellion – the list of MFT service suppliers targeted by threat actors is a long one, and the effects can be problematic, if not downright devastating for their customers.

But why are MFT systems such tempting targets? Mostly, it is because they control vast flows of sensitive, often regulated user data in a single location. In practice, this means one single vulnerability can provide a ‘successful’ threat actor with access to vast numbers of organisations. This is powerful leverage for financially-motivated ransomware gangs.

Take car rental firm Hertz, which was targeted by the Cl0p ransomware crew after supposedly being compromised through a vulnerability in Cleo products in April 2025, or cloud data management and security services supplier Rubrik, which was likewise hit following a breach of Fortra’s GoAnywhere product .

But perhaps the most infamous example of an MFT supply chain breach occurred at the end of May 2023, when a vulnerability in Progress Software’s MOVEit tool was mercilessly exploited, with UK-based targets including the BBC, Boots, and British Airways .

The Progress Software breaches were also orchestrated by the Cl0p ransomware gang, which ultimately hit well over a thousand targets via MOVEit. Cl0p makes a point of targeting large numbers of victims simultaneously and its members are particularly partial to MFT flaws for this reason.

While, as of Friday 25 September, there is no public evidence to suggest the involvement of Cl0p in the Kiteworks incident, the crew remains one of the most prolific ransomware gangs operating today, and is also currently involved in a cyber criminal turf war after being targeted by the teenage ShinyHunters crew , which accuses it of ‘stealing’ a vulnerability they found first.

AI accelerates exploit timelines from months to hours. Organisations must shift from patch-all to risk-based prioritisation using exploitability metrics .

Microsoft's July Patch Tuesday broke records by addressing over 600 CVEs. What does this reveal the effect that AI models have on vulnerability and patch management?

The application of agentic AI to vulnerability management workflows has slashed mitigation times in experimental conditions, claims Sase specialist Cato Networks .

Multiple organisations investigating fresh wave of Cl0p breaches By: Alex Scroxton

Cosmetics giant Estée Lauder victim of mass Oracle breach By: Alex Scroxton

ICO fines Cl0p victim South Staffs Water over data breach By: Alex Scroxton

Cl0p claims ransomware hit on NHS By: Alex Scroxton

CIOs looking for ways to say yes to the iPad in the enterprise CIOs are looking for ways to say yes to the iPad in the enterprise, despite the technological and cultural challenges associated ...

CIOs are looking for ways to say yes to the iPad in the enterprise, despite the technological and cultural challenges associated ...

What CISOs should take from the Hugging Face-OpenAI incident Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems ...

Security experts say the lesson isn't to abandon sandboxing, but to strengthen the security controls around surrounding systems ...

Red agents vs. blue agents: How to make AI better at defense The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their ...

The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their ...

When AppSec scanners become a supply chain attack vector New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for ...

New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for ...

5G Quiz - Can you speak 5G? -generation 5G wireless technology will offer faster speeds and increased capacity. Do you speak the language well enough to ...

-generation 5G wireless technology will offer faster speeds and increased capacity. Do you speak the language well enough to ...

5G expansion is coming, but where will operators reap profits? In this recap of industry blogs, networking pundits examine the profit potential of 5G expansion, responsible use of AI and some ...

In this recap of industry blogs, networking pundits examine the profit potential of 5G expansion, responsible use of AI and some ...

5G, cloud embolden network outsourcing and ultimate virtualization Could the cloud, 5G, small cell technology, BYOD and carrier-provisioned networks completely virtualize network infrastructure? ...

Could the cloud, 5G, small cell technology, BYOD and carrier-provisioned networks completely virtualize network infrastructure? ...

Distributed computing: The infrastructure shift AI demands The hyperscale era is ending. AI's energy and latency demands are driving infrastructure toward the edge -- closer to users, ...

The hyperscale era is ending. AI's energy and latency demands are driving infrastructure toward the edge -- closer to users, ...

Why and the NSA love graph databases Graph databases play six degrees of separation to find real connections. See how IT teams can use the database approach for ...

Graph databases play six degrees of separation to find real connections. See how IT teams can use the database approach for ...

DevOps and Agile IT save mainframe training from skills quagmire The problem isn't that new hires aren't familiar with the complex, custom daily tasks of mainframe ops. The problem is that ...

The problem isn't that new hires aren't familiar with the complex, custom daily tasks of mainframe ops. The problem is that ...

HR makes major strides toward improving employee engagement

Cloud vs. legacy ERP systems: Tug of war intensifies for SMBs Aging legacy ERP systems at SMBs seem to be getting plenty of scrutiny these days. Heightened consumer demands, shifting ...

Aging legacy ERP systems at SMBs seem to be getting plenty of scrutiny these days. Heightened consumer demands, shifting ...

Develop smart AI in CRM strategies to win and keep customers Of the three words that comprise customer relationship management , one word binds the other two. As necessity and ...

Of the three words that comprise customer relationship management , one word binds the other two. As necessity and ...