Recommended shutdown window: 6 hours (Source: Kiteworks customer notification, as reported by Heise and BleepingComputer (September 2026))
What Kiteworks told customers
Kiteworks, a secure file-sharing software company, urged customers worldwide to shut down their servers for six hours on Saturday, September 26. It said it had received threat intelligence warning of a possible attack. According to German technology publication Heise, Kiteworks CISO Frank Balonis emailed customers that the company had received "credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend."
Kiteworks confirmed the warning to BleepingComputer. It said the intelligence came from federal authorities and indicated that a threat actor "may attempt to target some Kiteworks systems for customers." The company described the shutdown as a precaution taken while it and law enforcement partners work through the matter.
What is and is not confirmed
Kiteworks told BleepingComputer: "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach." The company also said all known vulnerabilities are addressed in its current release, 9.5.1, and that it continues to recommend customers run the latest version.
Heise reports that Kiteworks customer support said the shutdown is intended to protect against potential zero-day attacks. BleepingComputer notes that neither the company's statement nor the customer notification confirms that a zero-day vulnerability has been discovered or exploited. The threat actor has not been identified. The source reporting does not say whether any attack occurred during the window.
Scope of the request
Heise says the window applies to customers worldwide, across time zones from Australian Eastern Standard Time to Pacific Daylight Time. In Central Europe, customers were told to shut down between 4:00 a.m. and 10:00 a.m. on Saturday. In New York, the window ran from 10:00 p.m. Friday to 4:00 a.m. Saturday.
The company reportedly recommends shutting down before the scheduled window. It also reportedly says customers should take systems offline even if they are not directly accessible from the Internet. For an organisation, that means internal-only deployments were inside the scope of the request.
Why file-transfer platforms draw attention
BleepingComputer notes that secure file-sharing platforms commonly store sensitive documents, which makes them a valuable target for cybercriminals who conduct data-theft extortion attacks. Kiteworks products are used by government organizations, financial institutions, and enterprises.
BleepingComputer adds that, although no actor has been linked to the potential attacks, the Clop extortion gang has a long history of targeting enterprise platforms in data-theft attacks. It names Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. That context is BleepingComputer's. Kiteworks has not attributed the intelligence to any group.
Questions for your team
1. Do we run Kiteworks, or another vendor-supplied file-transfer platform, and who owns it? Name the person, not the department.
2. Which release are we on compared with 9.5.1? If we are behind, what is the dated plan to close the gap?
3. Did we receive the Kiteworks notification, through which channel, and how long did it take to reach someone with authority to act? Heise reported the notice was sent by email.
4. Who can approve taking this system offline at short notice, and which partner, customer, or regulatory transfers depend on it? Is that documented?
5. If we did shut down, what did it cost, and did we review access logs around the window? If we did not, what was the reasoning, and was it recorded?





