AI News Feed
Market watch
Cybersecurity

Kiteworks Lifts Nine-Hour Shutdown Advisory After Credible Cyberattack Warning

Kiteworks urged customers worldwide to shut down systems for nine hours after federal threat intelligence warned of a planned cyberattack. No breach was reported, and the company lifted the advisory on Sept. 27, 2026, saying version 9.5.1 is secure.

The company said in a blog post that customers who self-manage Kiteworks systems on-premises or on AWS or Azure should shut down those systems themselves during the window in their local time zone. Kiteworks said it would shut down customer systems it hosts during the same window, so hosted customers did not need to act.

Frank Balonis, Kiteworks' chief information security officer, said the measure was proactive. "Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities," Balonis said. He added that there was no indication Kiteworks or customer systems had been compromised, describing the advisory as preventative rather than a response to a confirmed breach.

BleepingComputer, citing German media, reported that the shutdown window applied to customers worldwide, spanning time zones from Australian Eastern Standard Time to Pacific Daylight Time. In Central Europe, customers were told to shut down between 4 a.m. and 10 a.m. on Saturday. On the U.S. East Coast, the window was from 10 p.m. Friday to 4 a.m. Saturday.

Kiteworks said it did not have fixes in the pipeline and that all known vulnerabilities were addressed in version 9.5.1. Customers were advised to run that version rather than older, potentially vulnerable ones. The company also said subsidiaries Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder were not affected.

Secure data-sharing platforms are attractive targets because they are used by high-value organizations and handle sensitive information. The identity of any potential attacker was not disclosed. TechRadar noted parallels with past campaigns by the hacking group Cl0p, which three years earlier hit file-sharing platforms GoAnywhere MFT and MOVEit. Those breaches affected thousands of customers, including government agencies, schools, healthcare organizations, Sony and PricewaterhouseCoopers. Cl0p used extortion against many victims, and estimates of the group's proceeds ranged from about $40 million to $100 million.

Cl0p largely disappeared after those incidents, but last week it was reported that ShinyHunters, described as one of the most active and dangerous data exfiltration groups, attacked Cl0p. ShinyHunters leaked sensitive Cl0p data and said it acted in retaliation for threats of doxxing and physical violence. TechRadar said it was unknown whether Cl0p was preparing to hit Kiteworks, but that a possible attempt at reputation management after being embarrassed by ShinyHunters could not be ruled out.

Kiteworks said on Sept. 27 that customers who had not already restarted could bring their Kiteworks systems back online. Customers with self-hosted Advanced Forms were told to contact customer support for assistance. No actual breaches at Kiteworks customers had been reported, and TechRadar said it was continuing to monitor the situation.