AI News Feed
Market watch
Cybersecurity

Kiteworks Urges Customers to Shut Down Systems Over 'Imminent' Cyber Threat

Kiteworks told customers to shut down systems before the weekend after law enforcement warned a threat actor may target some customer systems. The company says it has no evidence of a breach and has fixed known flaws in its latest release.

The alert was first reported by German publication Heise, which cited an email Kiteworks sent to customers warning of an 'imminent' attack that could occur as soon as this weekend. Kiteworks confirmed to TechCrunch that it had notified customers about the potential threat.

In an email on Friday, Kiteworks chief information security officer Frank Balonis told TechCrunch that the company 'received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers.' Balonis said: 'Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter. We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach.'

Kiteworks did not say which law enforcement agency alerted the company or which hacking group may be behind the threat. The FBI and the U.S. cybersecurity agency CISA did not respond to TechCrunch requests for comment about the Kiteworks alert.

Balonis said the company has fixed all known vulnerabilities in its latest software release, 9.5.1, which it recommends all customers use.

According to a copy of the email sent to customers on Friday and shared with TechCrunch, the company said it was concerned about the exploitation of vulnerabilities that are currently unknown to Kiteworks. These bugs are known as zero-day flaws because they give the vendor no time to fix the flaws before they are exploited. In the email, Kiteworks urged customers to shut down their systems before the weekend, if not sooner, to 'protect against any potential zero-day attacks,' as the company cannot confirm whether there are other potential routes for improper access.

It is unclear exactly how many customers may be affected. Kiteworks says on its website that it has thousands of customers across healthcare, technology, education, automotive, and government, among others. Security researcher Kevin Beaumont pointed to a listing of at least a thousand internet-facing Kiteworks systems online today.

Kiteworks is no stranger to cyberattacks. Prior to its rebrand from Accellion in late 2021, a vulnerability in its file-transfer application allowed an extortion gang to mass hack and steal data from hundreds of organizations that relied on the product to send customer or internal corporate data over the internet. The mass hack was part of a broader hacking campaign targeting file transfer products, with the goal of stealing copies of the data that had been previously sent over the internet but not deleted from the affected servers. The hackers then held the data for ransom, threatening to publicly release customers' information if the victim organizations did not pay a ransom.

Editor's Summary Kiteworks is advising customers to shut down systems before the weekend after law enforcement warned of a possible attack on some customer systems. The company says it has no evidence of a breach and has released software 9.5.1 to fix known vulnerabilities, while the number of affected customers remains unclear.