<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn" -->

---
title: Kiteworks asks customers to shut down servers for six...
description: Secure file-sharing vendor Kiteworks (formerly Accellion) asked customers worldwide to take servers offline for a six-hour precautionary window after federal...
canonical: https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Kiteworks asks customers to shut down servers for six hours after law enforcement warns of imminent attack | daily.dev
og:description: Secure file-sharing vendor Kiteworks (formerly Accellion) asked customers worldwide to take servers offline for a six-hour precautionary window after federal...
og:url: https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn
og:image: https://api.daily.dev/og/posts/lkPr8gptN.png
og:image:alt: Kiteworks asks customers to shut down servers for six hours after law enforcement warns of imminent attack
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Kiteworks asks customers to shut down servers for six hours after law enforcement warns of imminent attack

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Secure file-sharing vendor Kiteworks (formerly Accellion) asked customers worldwide to take servers offline for a six-hour precautionary window after federal law enforcement warned of a possible imminent cyberattack. Regions were staggered by time zone, with Central Europe down 4-10 a.m. and New York 10 p.m.-4 a.m. on September 26. The company says it has no evidence of a confirmed breach but pointed customers to version 9.5.1, which patches all known vulnerabilities. Kiteworks was previously breached in 2021 as Accellion, and similar managed file-transfer platforms like GoAnywhere MFT, SolarWinds Serv-U, Cleo, and MOVEit have been repeatedly targeted by extortion groups such as Clop.

## Content

Kiteworks, the secure file-sharing vendor formerly known as Accellion, has asked customers worldwide to take their servers offline for a six-hour window after receiving threat intelligence from federal law enforcement about a possible imminent cyberattack.

CISO Frank Balonis emailed customers recommending the precautionary shutdown, with regional windows staggered by time zone: Central Europe from 4–10 a.m. on Saturday, September 26, and New York from 10 p.m. Friday through 4 a.m. Saturday.

Kiteworks says it has no evidence of a confirmed breach. Support staff told German outlet Heise the shutdown was meant to guard against potential zero-day vulnerabilities, and the company pointed customers to its latest release, version 9.5.1, which it says patches all known vulnerabilities.

The precaution is notable given who uses the platform. Kiteworks serves government agencies, financial institutions, healthcare organizations, and large enterprises — the kind of clients that make file-transfer platforms attractive targets for data-theft extortion groups. More than a thousand Kiteworks systems are internet-facing, according to Shodan.

The concern isn't hypothetical. The company has been here before: in 2021, when it was still called Accellion, an extortion gang exploited a flaw in its legacy file-transfer appliance to breach hundreds of organizations. Since then, similar platforms have been hit repeatedly — Clop alone has exploited GoAnywhere MFT, SolarWinds Serv-U, Cleo, and MOVEit Transfer in successive campaigns.

No attack has been confirmed as of the time of writing.

## Questions this post answers

### Why did Kiteworks ask customers to shut down their servers for six hours?

Kiteworks, the file-sharing vendor formerly known as Accellion, requested a precautionary six-hour shutdown after federal law enforcement provided threat intelligence about a possible imminent cyberattack. The company said it had no evidence of a confirmed breach but wanted to guard against potential zero-day vulnerabilities, staggering the shutdown window by region, including Central Europe from 4-10 a.m. and New York from 10 p.m. to 4 a.m. on September 26.

_Teams running managed file-transfer platforms follow security incidents like this one on daily.dev._

### What Kiteworks version patches all known vulnerabilities as of the September 2025 shutdown warning?

Kiteworks pointed customers to version 9.5.1, which the company says patches all known vulnerabilities, as the recommended upgrade during the precautionary shutdown prompted by a law enforcement warning of a possible imminent attack. No confirmed breach had been identified at the time of the advisory.

_Admins tracking managed file-transfer patches can follow Kiteworks version updates on daily.dev._

### Why are managed file-transfer platforms like Kiteworks frequent targets for extortion attacks?

These platforms handle sensitive data for government agencies, financial institutions, healthcare organizations, and large enterprises, making them attractive targets for data-theft extortion groups. Accellion (now Kiteworks) was breached in 2021 via a legacy appliance flaw, and the extortion gang Clop has since exploited similar tools including GoAnywhere MFT, SolarWinds Serv-U, Cleo, and MOVEit Transfer in successive campaigns.

_Security teams evaluating file-transfer vendors weigh this attack history on daily.dev._

## Similar posts on daily.dev

- [Progress urges ShareFile customers to shut down servers over "credible" threat](https://daily.dev/posts/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat-nilsinzqc) · BleepingComputer · 2 upvotes · 0 comments
- [Progress orders emergency ShareFile server shutdown over mystery security threat](https://daily.dev/posts/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat-y5p3nyqak) · The Register · 1 upvotes · 0 comments

---

[View this post on daily.dev](https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Kiteworks asks customers to shut down servers for six hours after law enforcement warns of imminent attack","url":"https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn"},"datePublished":"2026-09-25T22:25:48.302Z","dateModified":"2026-09-25T22:26:27.514Z","description":"Secure file-sharing vendor Kiteworks (formerly Accellion) asked customers worldwide to take servers offline for a six-hour precautionary window after federal...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/099ab45260c9d6abdf9f1a8a0d306603?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/099ab45260c9d6abdf9f1a8a0d306603?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Kiteworks asks customers to shut down servers for six hours after law enforcement warns of imminent attack"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/kiteworks-asks-customers-to-shut-down-servers-for-six-hours-after-law-enforcement-warns-of-imminent--lkpr8gptn#faq","mainEntity":[{"@type":"Question","name":"Why did Kiteworks ask customers to shut down their servers for six hours?","acceptedAnswer":{"@type":"Answer","text":"Kiteworks, the file-sharing vendor formerly known as Accellion, requested a precautionary six-hour shutdown after federal law enforcement provided threat intelligence about a possible imminent cyberattack. The company said it had no evidence of a confirmed breach but wanted to guard against potential zero-day vulnerabilities, staggering the shutdown window by region, including Central Europe from 4-10 a.m. and New York from 10 p.m. to 4 a.m. on September 26. Teams running managed file-transfer platforms follow security incidents like this one on daily.dev."}},{"@type":"Question","name":"What Kiteworks version patches all known vulnerabilities as of the September 2025 shutdown warning?","acceptedAnswer":{"@type":"Answer","text":"Kiteworks pointed customers to version 9.5.1, which the company says patches all known vulnerabilities, as the recommended upgrade during the precautionary shutdown prompted by a law enforcement warning of a possible imminent attack. No confirmed breach had been identified at the time of the advisory. Admins tracking managed file-transfer patches can follow Kiteworks version updates on daily.dev."}},{"@type":"Question","name":"Why are managed file-transfer platforms like Kiteworks frequent targets for extortion attacks?","acceptedAnswer":{"@type":"Answer","text":"These platforms handle sensitive data for government agencies, financial institutions, healthcare organizations, and large enterprises, making them attractive targets for data-theft extortion groups. Accellion (now Kiteworks) was breached in 2021 via a legacy appliance flaw, and the extortion gang Clop has since exploited similar tools including GoAnywhere MFT, SolarWinds Serv-U, Cleo, and MOVEit Transfer in successive campaigns. Security teams evaluating file-transfer vendors weigh this attack history on daily.dev."}}]}
```

