Kiteworks, the file-transfer company formerly known as Accellion, is urging customers to take their servers offline after receiving what it called credible threat intelligence from law enforcement about a possible attack as soon as this weekend. The advisory, reported by TechCrunch and first cited by German publication Heise, is precautionary rather than a response to a confirmed breach, according to chief information security officer Frank Balonis.
The company said it has fixed all known vulnerabilities in its latest release, 9.5.1, but warned that hackers could try to exploit unknown flaws, known as zero-days. Kiteworks did not name the law enforcement agency or the suspected threat actor, and it told customers to shut down systems to "protect against any potential zero-day attacks."
The warning is already causing disruption for some customers. One healthcare customer told TechCrunch that it took down its server immediately, leading to delays in doctors' ability to contact patients. Kiteworks says it serves thousands of customers across healthcare, technology, education, automotive, and government.
The episode has echoes of the company's past security struggles. Before its rebrand from Accellion in late 2021, a vulnerability in its file-transfer product was exploited by an extortion gang that stole data from hundreds of organizations. In this case, Kiteworks says it is not aware of any compromise so far, and the advisory is meant to prevent an attack rather than respond to one.