Kiteworks, the secure file transfer vendor once known as Accellion, has asked customers to shut their systems down for nine hours this weekend as a precaution. The company said it received credible threat intelligence from federal authorities warning that an actor may move against some Kiteworks systems.
“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window,” said chief information security officer Frank Balonis. Kiteworks stressed it has found no sign that customer systems were compromised, framing the advisory as preventive. German outlet Heise first reported the step.
An unwelcome echo of the Accellion campaign
The vendor did not name the agency that raised the alarm or say who might be behind a coming attack. It said all known vulnerabilities are addressed in its latest release, 9.5.1, and urged customers to patch. Sister products including Zivver, DRACOON, totemo, ownCloud, and 123FormBuilder are unaffected, the company added.
For long-time customers the timing stings. Between late 2020 and early 2021 the Clop gang, also tracked as UNC2546, exploited zero-days in Accellion’s file transfer appliance to steal data from high-profile victims and extort them. Kiteworks has since rebuilt the product line, but the memory of that campaign still shapes how its customers read a warning like this one. Customers should confirm their patch level before service resumes.
