Kiteworks told customers to shut down servers after federal threat warning
The secure file-sharing vendor asked for a nine-hour precautionary shutdown, then lifted it after isolating a severe flaw in its Advanced Forms product.
By Tech CEO Daily Staff, Newsroom
· 2 min read

The news
Kiteworks, which sells secure file-sharing and data-transfer software to governments, banks and enterprises, told customers on September 25 to take their systems offline for a nine-hour precautionary window. In a press release, the company said it had received credible threat intelligence from federal intelligence authorities that a threat actor might try to target some Kiteworks systems.
The company stressed that the step was preventive. CISO Frank Balonis said Kiteworks had “no indication” that its own or customers’ systems had been compromised. Kiteworks shut down the systems it hosts itself, while customers running on-premises or self-managed cloud instances had to initiate their own shutdowns. German outlet Heise first reported the advisory, according to BleepingComputer.
On September 27, Kiteworks lifted the recommendation for all customers. SecurityWeek reported that the company identified a severe vulnerability in its Advanced Forms data-collection product, affecting fewer than 1% of customers, and that other products were not affected. Kiteworks said all known vulnerabilities are addressed in release 9.5.1 and that it is working with Mandiant and federal authorities. No CVE had been published at the time of writing.
The numbers
- Recommended shutdown window
- 9 hours
- Customers affected by Advanced Forms flaw (per SecurityWeek)
- <1%
- Fixed release
- 9.5.1
Why CEOs should care
Managed file-transfer platforms have been prime targets for mass data-theft campaigns, because they concentrate sensitive files from many partners in one place. If your company, a law firm, bank or supplier you work with uses Kiteworks, ask whether it is on 9.5.1, whether Advanced Forms is deployed, and whether logs from the past weeks have been reviewed.
The episode is also a test of vendor communication. Leaders should know who inside the organisation receives urgent vendor advisories, who has authority to take a business-critical system offline on short notice, and how that decision is communicated to customers.
What's next
Watch for a CVE, technical details and any confirmation of exploitation. Kiteworks says it will continue to share threat intelligence with federal authorities.
Sources
- PrimaryKiteworks Issues Precautionary Shutdown Advisory for Customers— Kiteworks
- ReportKiteworks urges server shutdown over potential zero-day attacks— BleepingComputer
- ReportKiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability— SecurityWeek
Newsroom
Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.
Spotted an error? Request a correction. Read our editorial standards and AI policy.
The Daily Brief
The technology briefing for people running businesses.
Weekdays at 6 a.m. ET. Free.


