Kiteworks has told customers to shut down their file-transfer servers for six hours. The window runs from 02:00 to 08:00 UTC on Saturday 26 September 2026, and the company says it applies to every version and every network setup. The Kiteworks server shutdown is precautionary: no breach has been confirmed.

When the Shutdown Window Falls in Your Time Zone

The six-hour window is 02:00 to 08:00 UTC on Saturday 26 September 2026, which puts it on Friday evening in the Americas and Saturday afternoon in Australia.

Time zoneLocal shutdown window
UTC02:00–08:00, Saturday 26 September
British Summer Time (London)03:00–09:00, Saturday 26 September
Central European Summer Time (Berlin, Paris)04:00–10:00, Saturday 26 September
India Standard Time07:30–13:30, Saturday 26 September
Singapore and Hong Kong10:00–16:00, Saturday 26 September
Australian Eastern Standard Time (Sydney)12:00–18:00, Saturday 26 September
Eastern Daylight Time (New York)22:00 Friday 25 September – 04:00 Saturday 26 September
Pacific Daylight Time (Los Angeles)19:00 Friday 25 September – 01:00 Saturday 26 September

Kiteworks told customers they can go offline earlier than the window if that suits their operations better. The company did not ask anyone to stay down beyond the six hours.

What Kiteworks Told Its Customers

Kiteworks says the warning came from law enforcement, not from anything it found in its own systems.

Frank Balonis, chief information security officer at Kiteworks, the San Francisco company whose platform moves large files and sensitive records between organisations, said the firm had “received credible threat intelligence from law enforcement indicating that a threat actor may attempt to target some Kiteworks systems for customers”. He added that the company is “not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach”.

The customer email is blunter. As reported on 25 September 2026 by the German technology publication Heise, which obtained it, the message reads: “We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend. We strongly recommend you shut down your Kiteworks system for six hours.”

On software versions, Kiteworks told customers that “all known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version”. It still wants systems switched off, whichever version they run.

Why the Advice Is a Shutdown and Not a Patch

A vendor recommends downtime instead of an update when it does not know which flaw an attacker intends to use.

A zero-day is a software flaw that the people who could fix it do not yet know about, which means no patch exists on the day an attack starts. Kiteworks’ support staff told customers the reason for the request is “to protect against any potential zero-day attacks”. Pulling the power is the only control that works against a bug nobody has written a fix for.

That logic explains two unusual details. The advice ignores version numbers, because 9.5.1 closes the holes Kiteworks knows about and says nothing about one it does not. And it covers servers that are not reachable from the public internet, because the company says it cannot rule out other routes in.

Enterprise security warnings normally arrive the other way round: a numbered flaw, a severity score and a fix, as with the SAP OVERPASS flaw rated CVSS 10.0 earlier this month. Here there is no number and no fix, only a time window.

What to Do Before the Window Opens

Administrators should take the system offline ahead of 02:00 UTC, include servers that are not internet-facing, and make sure they are on release 9.5.1.

  1. Shut down early rather than late: Kiteworks says customers may go offline before the window begins, and its own advice is to do so if the weekend timing allows.
  2. Do not skip internal servers: the instruction covers Kiteworks systems that have no direct internet exposure, because the company cannot say how an attacker would reach them.
  3. Confirm the release: 9.5.1 is the version Kiteworks says fixes everything it currently knows about, so bring older deployments up before restarting.
  4. Treat the email as the instruction: Kiteworks has not posted a public advisory page. The security firm Sophos, which flagged the warning to its own customers, told them to follow the vendor’s email or contact Kiteworks directly.

Kiteworks has not published indicators of compromise, log entries to search for, or any guidance on what to check when a server comes back up. Until it does, there is no vendor-sanctioned way to tell whether a given system was touched.

What Is Confirmed and What Is Not

As of 26 September 2026, no attack on a Kiteworks customer has been reported, no vulnerability has been given a CVE identifier, and no attacker has been named.

Confirmed by Kiteworks: the advisory exists, the window is six hours, release 9.5.1 addresses every flaw the company knows about, and the company has found no compromise of its own systems.

Not established:

  • The agency behind the tip: Kiteworks declined to name which law enforcement body passed on the intelligence. The FBI and the US Cybersecurity and Infrastructure Security Agency both declined to comment to TechCrunch.
  • The flaw: no CVE identifier, no affected-version list and no technical description has been published, by Kiteworks or by anyone else.
  • The attacker: no group has been named and no ransomware or extortion crew has claimed anything.
  • The exposure: TechCrunch reported that at least 1,000 internet-facing Kiteworks systems can be found online. That count comes from a single outlet and has not been independently confirmed.

A warning with no CVE behind it is rare, and it is the part of this story most likely to change over the weekend.

Why File-Transfer Servers Draw This Kind of Warning

Kiteworks was called Accellion until October 2021, and its earlier file-transfer product was mass-hacked in one of the biggest extortion campaigns of that period.

Attackers began exploiting zero-days in Accellion’s legacy File Transfer Appliance in mid-December 2020 and kept going in waves through January 2021, planting a web shell that researchers named DEWMODE. Fewer than 100 organisations were breached and fewer than 25 suffered significant data theft, according to the incident response work published at the time, but the victims included universities, hospitals and government bodies, and the Clop extortion group published stolen files to pressure them into paying.

The appeal is structural. A file-transfer server sits at the edge of the network, accepts connections from outsiders by design, and holds exactly the documents an extortionist wants. The same logic drove this month’s campaigns against 440 PaperCut print servers and against 996 Zyxel network switches.

Kiteworks says on its own website that it protects “more than 100 million end-users and over 1,500 global corporations and government agencies”, among them NYC Health + Hospitals, KPMG and the National Health Service. That is the scale behind a six-hour outage request.

Frequently Asked Questions

Has Kiteworks Been Hacked?

No. Kiteworks says it is not aware of any compromise of its systems and that the advisory is preventative. No customer breach has been reported as of 26 September 2026.

Does the Shutdown Apply to Every Kiteworks Customer?

Yes. The advice covers all versions and all network configurations, including servers that are not reachable from the public internet. Kiteworks did not limit it to a subset of customers.

Is There a Patch Instead of Shutting Down?

No patch has been offered for this warning. Release 9.5.1 fixes every flaw Kiteworks says it knows about, but the company is asking customers to power down anyway because it is guarding against a flaw it may not know about.

What Happens After 08:00 UTC?

Kiteworks has not said. It asked for six hours and has not published guidance on restarting, on what to check afterwards, or on whether a second window may follow.

Which Vulnerability Is Being Exploited?

None has been identified publicly. There is no CVE number, no technical write-up and no named attacker attached to this advisory.