30 SEP 2026 — Kiteworks, a secure file-sharing company, told customers on 25 September to shut down their servers for nine hours after federal authorities warned of a possible attack. During the shutdown it found a previously unknown critical flaw in one of its products, and it lifted the advice on 27 September.
No compromise has been reported. The episode is unusual: vendors almost never ask customers to switch off production systems before anything has happened.
What Kiteworks asked for
Kiteworks' advisory says it acted on "credible threat intelligence from federal intelligence authorities" and recommended a nine-hour precautionary shutdown in each customer's local time. Customers running their own systems, whether on premises or on Amazon Web Services or Azure, had to switch off themselves. Kiteworks shut down the systems it hosts.
"We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach," said Frank Balonis, the company's chief information security officer.
Which products were covered
The advisory covered only the Kiteworks platform. Products the company owns under other names (Zivver, DRACOON, totemo and ownCloud) were not affected, it said.
What the shutdown turned up
While systems were down, Kiteworks found a severe vulnerability in Advanced Forms, its secure data-collection product. The flaw is confined to that product, which is enabled for fewer than 1% of customers, under 50 organisations, the company said, as SecurityWeek reports.
Kiteworks has not published a CVE number or technical details. It recommends customers run version 9.5.1, which it says accounts for all known vulnerabilities in the current release.
Why a file-transfer vendor takes a warning seriously
Kiteworks was formerly Accellion. A flaw in Accellion's legacy file-transfer appliance was exploited by an extortion gang to compromise hundreds of organisations, CyberScoop notes, and the company renamed itself in October 2021. File-transfer software has been a favourite target since, because it holds the very documents attackers want.
"Telling customers to take production systems offline is not a decision any vendor makes lightly," Balonis said, CyberScoop reports. "We made it anyway, because when the choice is between certainty and convenience, customer data is not something we are willing to gamble with."
What customers should do
Confirm the platform is on 9.5.1. Customers using Advanced Forms should watch for Kiteworks' technical advisory and a CVE, and review logs from the days before the shutdown for anything unusual, since the warning was about a threat the company could not yet describe.
The broader lesson is about readiness. A vendor telling customers to switch off within hours only works if those customers can reach the vendor's notices quickly and have a way to stop a production system on short notice.