Skip to content
Tech CEO Daily

Kiteworks told customers to shut down servers after federal threat warning

The secure file-sharing vendor asked for a nine-hour precautionary shutdown, then lifted it after isolating a severe flaw in its Advanced Forms product.

TC

By Tech CEO Daily Staff, Newsroom

· 2 min read

A server room with racks powered down
AI-generated image for illustration. Not a photograph of the events described.

The news

Kiteworks, which sells secure file-sharing and data-transfer software to governments, banks and enterprises, told customers on September 25 to take their systems offline for a nine-hour precautionary window. In a press release, the company said it had received credible threat intelligence from federal intelligence authorities that a threat actor might try to target some Kiteworks systems.

The company stressed that the step was preventive. CISO Frank Balonis said Kiteworks had “no indication” that its own or customers’ systems had been compromised. Kiteworks shut down the systems it hosts itself, while customers running on-premises or self-managed cloud instances had to initiate their own shutdowns. German outlet Heise first reported the advisory, according to BleepingComputer.

On September 27, Kiteworks lifted the recommendation for all customers. SecurityWeek reported that the company identified a severe vulnerability in its Advanced Forms data-collection product, affecting fewer than 1% of customers, and that other products were not affected. Kiteworks said all known vulnerabilities are addressed in release 9.5.1 and that it is working with Mandiant and federal authorities. No CVE had been published at the time of writing.

The numbers

Recommended shutdown window
9 hours
Customers affected by Advanced Forms flaw (per SecurityWeek)
<1%
Fixed release
9.5.1

Why CEOs should care

Managed file-transfer platforms have been prime targets for mass data-theft campaigns, because they concentrate sensitive files from many partners in one place. If your company, a law firm, bank or supplier you work with uses Kiteworks, ask whether it is on 9.5.1, whether Advanced Forms is deployed, and whether logs from the past weeks have been reviewed.

The episode is also a test of vendor communication. Leaders should know who inside the organisation receives urgent vendor advisories, who has authority to take a business-critical system offline on short notice, and how that decision is communicated to customers.

What's next

Watch for a CVE, technical details and any confirmation of exploitation. Kiteworks says it will continue to share threat intelligence with federal authorities.

Sources

TC
Tech CEO Daily Staff

Newsroom

Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.

Spotted an error? Request a correction. Read our editorial standards and AI policy.

The Daily Brief

The technology briefing for people running businesses.

Weekdays at 6 a.m. ET. Free.

More in Cybersecurity