Kiteworks Lifts Precautionary Shutdown Following Federal Intelligence Warning
Share
Kiteworks has lifted a temporary shutdown recommendation for its customers after receiving threat intelligence from federal authorities. The vendor had previously advised a precautionary pause to mitigate the risk of a potential targeted attack on its systems.
The shutdown, which was implemented on 25 September, lasted nine hours. The order applied to customers managing their own Kiteworks systems—either on-premises or via cloud providers such as AWS and Azure—as well as to all systems hosted directly by Kiteworks.
Preventative Measures Taken
Kiteworks CISO Frank Balonis stated that the company received “credible threat intelligence from federal intelligence authorities” suggesting a threat actor might attempt to target certain Kiteworks systems. Balonis emphasised that the decision to recommend a shutdown was an abundance of caution and that there have been no confirmed reports of a breach.
The company confirmed on 27 September that all Kiteworks-hosted systems have been brought back online and are operating normally. However, customers using self-hosted Advanced Forms have been advised to contact customer support for assistance in restoring their systems.
MFT Platforms Under Scrutiny
While the exact nature of the threat remains unconfirmed, industry speculation suggests the intelligence may have concerned the potential exploitation of a zero-day vulnerability. Managed file transfer (MFT) platforms have become increasingly lucrative targets for cybercriminals.
Major historical breaches involving MFT providers, including MOVEit, Accellion, and GoAnywhere, have resulted in massive data exfiltration and extortion campaigns. In the 2023 MOVEit campaign, the Cl0p extortion group successfully compromised the data of over 90 million downstream customers.
To ensure continued security, Kiteworks recommends that all customers run the latest software release, version 9.5.1, which accounts for all known vulnerabilities. Security experts noted that while the decision to take systems offline is unusual, it serves as a proactive example of utilising threat intelligence to prevent compromise before it occurs.




Leave a Reply