Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure25 September 2026, Friday

File transfer firm Kiteworks asks thousands of customers to shut their systems for 6 hours on 26 September after a threat warning from federal authorities

Kiteworks told customers on 25 September that it had received a credible warning from federal authorities that a threat actor could target its systems, and recommended a 6-hour shutdown window for Saturday 26 September. The company said there was no confirmed breach and that the measure was precautionary; at least 1,000 systems are exposed to the internet.

Location: USA

According to a 25 September report by The Record, Kiteworks' chief information security officer wrote that they had received credible threat intelligence from federal intelligence authorities that a threat actor could target some Kiteworks systems. TechCrunch reported the same statement as a warning originating from law enforcement; the two sources use different wording on which agency the warning came from. According to BleepingComputer, the shutdown window runs from 04:00 to 10:00 Central European Time on 26 September, or from 22:00 on 25 September to 04:00 on 26 September New York time; the recommendation also covers installations not exposed to the internet, and the company is asking customers to move to version 9.5.1. According to The Record, the FBI declined to comment and CISA did not respond; no CVE number or threat actor name has yet been disclosed.

According to TechCrunch, at least 1,000 Kiteworks systems are exposed on the internet and thousands of customers in the healthcare, technology, education, automotive and public sectors could be affected; one healthcare customer reported delays in patient communications because it shut its server down immediately. A customer support official was reported to have referred to a possible zero-day flaw, without giving details. The file transfer product of the company's predecessor, Accellion, was compromised in December 2020 in a zero-day attack by the Clop group, and according to TechCrunch data was stolen from hundreds of organisations. No confirmed breach or number of affected customers has been disclosed; the source of the threat could not be verified.

Talay assessment

Bottom line

A vendor having production systems shut down pre-emptively on a federal warning is a rare step and shows the warning is being taken seriously. Accellion's zero-day history in 2020 and the targeting of file transfer products by data extortion gangs suggest that unpatched or un-shut systems may remain at risk after 26 September as well.

Likely effects

  • Public sector and healthcareNegativeWeeks

    The mandatory 6-hour outage caused operational delays for healthcare, education and public sector customers; one healthcare provider reported disruption to patient communications.

  • Supply chain riskNegative1–6 months

    Because file transfer platforms concentrate many organisations' data in a single point, a successful exploit across more than 1,000 exposed systems could turn into a multi-organisation leak.

  • Users in TürkiyeUncertainWeeks

    If Turkish organisations use Kiteworks, the warning applies to them too; moving to version 9.5.1 and reviewing access logs are the priorities.

Possibilities, ranked

  1. 1
    Flaw and patch announced50%

    Kiteworks publishes a CVE number and patch within a few days, and no confirmed mass breach is reported.

    Watch: Kiteworks security bulletin and CVE assignment

  2. 2
    Limited breach emerges35%

    Data theft is detected at some customers that did not shut down or did so late, and an extortion group claims responsibility.

    Watch: Kiteworks customer listings on leak sites

  3. 3
    Threat does not materialise15%

    The attack foreseen in the warning is not observed and the company instructs a return to normal operation.

    Watch: The company's announcement of a return to normal operation

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Shutdown window▼ 6 hours (26 Sep)
  • Internet-exposed Kiteworks systems▼ 1,000+
  • Recommended version▲ 9.5.1

Sources

  1. The Record — Kiteworks urges customers to stop using platform after federal warning
  2. BleepingComputer — Kiteworks urges 6-hour server shutdown over potential zero-day attacks
  3. TechCrunch — Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack