Kiteworks Tells 1,000+ Organizations to Shut Down Servers Over Unconfirmed Cyber Threat
Most cybersecurity warnings tell you to patch something. This one told more than a thousand organizations to shut their servers down entirely, before anyone could confirm whether anything was actually wrong.
Kiteworks, a secure file-transfer and content-communications platform used across healthcare, government, finance and education, emailed customers worldwide on September 25 recommending a coordinated six-hour shutdown.
The company said the move followed credible threat intelligence from federal law enforcement indicating that a threat actor might target Kiteworks deployments imminently, potentially through an unknown, unpatched vulnerability. Kiteworks CISO Frank Balonis said the company had received credible intelligence pointing to a possible imminent attack.
The shutdown was organized on a rolling regional schedule rather than happening everywhere at once. Central European customers were told to power down from 4 a.m. to 10 a.m. local time on September 26, while U.S. East Coast organizations were given a window from 10 p.m. Friday to 4 a.m. Saturday.
“Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” said Frank Balonis, Chief Information Security Officer at Kiteworks.
What Kiteworks Knows
“We have no indication that Kiteworks or our customers’ systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach,” said Frank Balonis, Chief Information Security Officer at Kiteworks.
Kiteworks described the shutdown as a precaution based on intelligence it considered credible. Customer support staff told German outlet Heise that the company was protecting against “potential zero-day attacks,” but that wording does not establish that a specific zero-day vulnerability had been confirmed.
“Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version,” Balonis said. Security researcher Kevin Beaumont identified more than 1,000 internet-facing Kiteworks systems, although that does not establish how many organizations received the shutdown recommendation.
The uncertainty is what makes the response unusual. Kiteworks was asking customers to take production systems offline without first presenting evidence that their deployments had been compromised.
“There is no known CVE, patch, or additional technical details available but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch,” said Jake Knott, head of threat intelligence at watchTowr.
Offline For Safety; Offline For Care
At least one healthcare customer experienced that disruption directly. TechCrunch reported that the organization took its Kiteworks server offline and saw an impact on how doctors could communicate with patients during the shutdown window.
That is the practical cost behind the advisory. Organizations had to weigh an unconfirmed cyber threat against a confirmed interruption to systems used to exchange sensitive information and support daily operations.
Kiteworks’ decision also went beyond systems that were obviously exposed to the internet. Advising customers to shut down non-internet-facing deployments suggests the company was unwilling to assume that a particular network configuration eliminated the potential risk while the threat intelligence was still being assessed.
Preemptive Shutdown, Unconfirmed Breach
“Whilst years have passed and the name has changed, attackers’ appetites for targeting [managed file transfer] appliances has not,” said Jake Knott, head of threat intelligence at watchTowr.
That history explains why a warning involving a possible zero-day in file-transfer infrastructure would receive immediate attention. It does not, however, connect the current Kiteworks advisory to Clop or any other known group. No public evidence has established who, if anyone, was preparing to attack Kiteworks customers.
The shutdown window was intended to buy time while Kiteworks and law enforcement assessed the threat. As of the latest information available, the company had not reported a confirmed compromise. Until Kiteworks provides that update, the incident remains a case of a vendor taking an unusually disruptive step in response to credible but unverified intelligence.