Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief
Kiteworks, a leading technology company specializing in secure file transfer tools, is warning its customers to shut down their systems due to an "imminent" threat of a potential cyberattack. The company, formerly known as Accellion, has informed its customer base about the impending attack, which could potentially occur as early as this weekend. This advisory was first reported exclusively by Heise, a German publication, and a copy of the email sent by Kiteworks to customers has been shared with TechCrunch.
The urgent notification stems from credible threat intelligence received from law enforcement, which suggests that a threat actor may target some of Kiteworks' systems for its customers. Despite this, Kiteworks has not disclosed the specific law enforcement agency that provided this information or the hacking group responsible for the threat. The FBI and the U.S. cybersecurity agency, CISA, have not responded to queries from TechCrunch regarding the Kiteworks alert.
To mitigate the threat, Kiteworks recommends that all customers update their systems to the latest software release, version 9.5.1, which contains patches for known vulnerabilities. The company urges customers to shut down their systems before the weekend, or sooner if possible, to protect against any potential zero-day attacks. These vulnerabilities, known as zero-days because they are unknown to the vendor, can be exploited before they are patched.
Security researcher Kevin Beaumont noted that there are at least a thousand internet-facing Kiteworks systems accessible online. This revelation has raised concerns about the potential number of customers affected by this threat. Kiteworks, which has a wide range of clientele spanning healthcare, technology, education, automotive, and government sectors, has faced cyberattacks in the past.
In 2021, prior to its rebranding, an extortion gang exploited a vulnerability in Kiteworks' file-transfer application to hack and steal data from hundreds of organizations. The hackers then threatened to release this confidential information publicly unless ransom was paid. As of now, Kiteworks maintains that it is not aware of any compromise to their systems, and this advisory is purely preventive.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.