Kiteworks has urged customers worldwide to temporarily shut down their servers after receiving credible law-enforcement intelligence that a threat actor may target Kiteworks deployments over the weekend.
The emergency advisory is preventive, but the company said the potential activity may involve an unknown zero-day vulnerability.
The secure file-sharing and managed content communications provider asked organizations to take Kiteworks systems offline for a six-hour window on Saturday, September 26.
Kiteworks Warns Users to Take Systems Offline
The coordinated shutdown runs from 02:00 to 08:00 UTC, equivalent to 04:00 to 10:00 Central European time, although customers were advised to power down systems beforehand where possible.
Kiteworks CISO Frank Balonis said the company had received “credible threat intelligence from law enforcement” indicating that an attack on some customer systems could be imminent.
The vendor characterized the response as a precaution while it investigates the threat alongside law-enforcement partners. Kiteworks stressed that it is not currently aware of a compromise affecting its systems.
Balonis said the advisory should not be interpreted as confirmation of a breach, but rather as a defensive measure designed to reduce exposure while the company assesses intelligence about the potential campaign.
The vendor has not publicly identified the suspected threat actor, exploitation technique, affected product component, or a CVE identifier.
Customer support reportedly described the shutdown recommendation as protection against “potential zero-day attacks,” suggesting the concern centers on a vulnerability that may be unknown to the vendor and therefore unavailable for normal patch-based remediation.
Heise said all known vulnerabilities are addressed in the current 9.5.1 release and continues to recommend that customers run the latest version.
However, the company’s request applies more broadly than internet-exposed deployments. Organizations were reportedly told to shut down servers even when they are not directly accessible from the public internet because they could not rule out potential access paths.
The advisory carries significant operational consequences because Kiteworks products support secure file transfer, enterprise webmail, and sensitive-data collaboration.
Its customer base includes enterprises, government-related organizations, financial institutions, and other environments where service interruption must be weighed against the risk of unauthorized access or data theft.
Recommending that an entire customer base take production servers offline is unusual and signals that Kiteworks views the intelligence as credible enough to justify disruption.
Security researchers noted that without a known CVE, patch, or technical mitigation, disconnection can be the most reliable short-term control against a potentially exploitable zero-day. Administrators should treat the vendor directive as an urgent incident-response event.
Organizations should confirm whether any Kiteworks components are deployed across production, disaster-recovery, testing, and internal-only environments; execute the shutdown within the vendor’s specified window; and preserve relevant authentication, application, web-server, endpoint, and network logs before restarting systems.
Security teams should also validate that all deployments are on Kiteworks 9.5.1 or later, restrict administrative access, review unusual file-transfer activity, and monitor for unexpected authentication events or changes to user privileges.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

