Kiteworks, a file-transfer company used by thousands of organizations across healthcare, government, and technology, is telling customers to pull their systems offline immediately. The warning comes after the company received credible threat intelligence from law enforcement indicating that a threat actor may attempt to exploit unknown vulnerabilities in its software.

The Warning and What Triggered It

Kiteworks chief information security officer Frank Balonis confirmed to TechCrunch that the company "received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers." The advisory, first reported by German publication Heise, was distributed to customers via email on Friday and warns of an attack that could materialize as soon as that weekend.

"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we and our law enforcement partners work through the matter," Balonis said. He emphasized that the company is "not aware of any compromise of Kiteworks systems" and that the advisory is preventative, not a response to a confirmed breach.

The Zero-Day Problem

The core concern is what security researchers call a zero-day vulnerability — a flaw in the software that Kiteworks has not yet discovered or patched, giving the vendor no window to fix it before it could be weaponized. The company's email told customers it was "concerned about the exploitation of vulnerabilities that are currently unknown to Kiteworks" and could not confirm whether other routes for unauthorized access exist.

Balonis said the company has fixed all known vulnerabilities in its latest software release, version 9.5.1, and recommends all customers upgrade to that version immediately. But since the feared exploit targets unknown flaws, even updated systems may not be safe.

Who Is at Risk

Kiteworks — formerly known as Accellion until its rebrand in late 2021 — serves thousands of customers across healthcare, technology, education, automotive, and government sectors. The company's platform handles the transfer of large files and sensitive datasets over the internet, making it a high-value target for anyone seeking access to confidential corporate or patient data.

Security researcher Kevin Beaumont identified at least a thousand internet-facing Kiteworks systems online at the time of the advisory, though he cautioned that the figure likely overcounts the number of distinct affected organizations. Even so, the potential attack surface is significant.

Real-World Disruption Already Underway

The precautionary shutdowns are causing operational damage. One Kiteworks customer in the healthcare sector told TechCrunch that they received the alert and immediately took down their organization's server, an outage that is now delaying doctors' ability to contact patients. The person requested anonymity.

For organizations that rely on Kiteworks as a core part of their data pipeline, the choice between maintaining service and accepting potential exposure is not a theoretical one.

The Shadow of the Past

Kiteworks is no stranger to devastating cyberattacks. Before its rebrand, the company — then operating as Accellion — suffered a breach in 2021 in which a vulnerability in its file-transfer application allowed an extortion gang to mass-hack hundreds of organizations. The attackers stole data that had been transmitted through the platform but not deleted from affected servers, then held it for ransom.

That earlier attack was part of a broader campaign targeting file-transfer products specifically for their troves of previously exchanged data. The precedent makes the current advisory particularly alarming for existing customers, who have reason to worry that the same playbook may be in motion.

What Remains Unknown

Several critical questions are still unanswered. Kiteworks has not disclosed which law enforcement agency issued the intelligence or which threat actor is suspected. The FBI declined to comment when approached by TechCrunch, and the Cybersecurity and Infrastructure Security Agency did not immediately respond to inquiries.

For the thousands of organizations now weighing whether to take their systems offline, the uncertainty is the most damaging part. The company's recommendation is clear: shut down before the weekend, upgrade to version 9.5.1, and wait for further guidance. Whether that is enough to prevent a breach — or whether the attackers have already slipped through an unknown door — is something only time will reveal.