Kiteworks has urged customers worldwide to temporarily shut down their servers for six hours this weekend after receiving credible threat intelligence warning that an attack on some Kiteworks systems could be imminent.

The secure file-sharing company said it received intelligence from federal authorities indicating that a threat actor may attempt to target some customer systems. As a precaution, Kiteworks recommended that customers take their systems offline during a scheduled six-hour window.

The shutdown window varies depending on location. In Central Europe, customers were instructed to take their Kiteworks systems offline from 4:00 a.m. to 10:00 a.m. on Saturday, September 26. In New York, the recommended shutdown period runs from 10:00 p.m. Friday until 4:00 a.m. Saturday. The company also advised customers to shut down their systems before the scheduled window, even if those systems are not directly accessible from the internet.

Kiteworks stressed that the warning does not mean the company has confirmed a breach. The company said it is not aware of any compromise of its systems and described the shutdown recommendation as a preventative measure while it works with law enforcement partners.

The warning has also raised concerns about a possible zero-day vulnerability. According to Heise, Kiteworks customer support said the shutdown was intended to protect customers against potential zero-day attacks. However, neither Kiteworks’ statement nor the customer notification confirms that an unknown vulnerability has been discovered or that attackers are currently exploiting one.

READ
Cloudflare Containers Flaw Exposed Data From Other Customers

Kiteworks said it has addressed all currently known vulnerabilities in version 9.5.1 and continues to recommend that customers use the latest release.

The company provides secure file-transfer and communications products to government organizations, financial institutions and enterprises. Because these platforms can contain sensitive documents, they have become attractive targets for cybercriminals involved in data theft and extortion attacks.


Buy ExpressVPN with PayPal or Credit Card

It remains unclear which threat actor, if any, is behind the potential attacks. The warning comes as cybercriminal groups such as Clop continue to target enterprise file-transfer platforms, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo and MOVEit Transfer.

Advertisement