www.infosecurity-magazine.com 29 Sept 2026, 09:30 UTC

Kiteworks Restores File Transfer Systems After Threat Warning

Kiteworks Restores File Transfer Systems After Threat Warning
CyberSIXT Evidence Panel Source marked as original reporting

KITEWORKS has lifted a precautionary shutdown notice issued to customers after receiving what it described as credible threat intelligence from federal intelligence authorities. The managed file transfer provider said on 27 September that customers could bring their systems back online. Hosted systems had already been restored and were operating normally, while customers using self-hosted Advanced Forms were told to contact support for assistance.

The original notice asked customers managing Kiteworks systems on-premises or through AWS or Azure to shut them down for nine hours on 25 September. Kiteworks also temporarily disabled systems it hosted on customers’ behalf. CISO Frank Balonis said the measure was preventative, stating that the company had received information that a threat actor might target some Kiteworks systems, but that there had been no reports of a confirmed breach. He added that known vulnerabilities had been addressed in the current 9.5.1 release and recommended that customers run the latest version.

The nature of the suspected threat remains unclear. Online speculation has focused on a possible attempt to exploit an undisclosed vulnerability, but this was not confirmed by Kiteworks. Security experts differed over the unusual shutdown: John Strand called it unprecedented for a non-active attack, while Phil Wylie described it as proactive use of threat intelligence.

Wylie recommended assessing exposure, increasing monitoring, preserving logs, checking patch levels and privileged access, and considering temporary isolation where the potential impact justified disruption.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline