Kiteworks urges server shutdown after attack warning

Published

Kiteworks, the secure file-sharing company formerly known as Accellion, has told its customers to take their servers offline for a six-hour window this morning after law enforcement warned it of an "imminent" cyberattack, according to an advisory from the Sophos Counter Threat Unit (CTU) research team.

Per Sophos, Kiteworks emailed customers on September 25, 2026, saying law enforcement had alerted it to an imminent attack on Kiteworks systems, possibly involving exploitation of a zero-day vulnerability, meaning a flaw for which no patch exists yet. The company reportedly advised customers to shut down their servers between 02:00 and 08:00 UTC on September 26, if not sooner, describing the step as precautionary.

A shutdown order instead of a patch

Vendors facing a suspected zero-day normally answer with a patch, a mitigation or a detection script. Asking customers to power servers down on a fixed schedule is a much blunter instruction. Our reading, which neither Kiteworks nor Sophos has stated, is that the company did not have a fix it could ship before the warned window.

The stakes come from what these systems hold. Kiteworks products are built to move sensitive files between organizations, and internet-facing enterprise software of this kind has been a steady target for attackers exploiting unpatched flaws: in the past month alone IntelFusions has covered actively exploited zero-days in N-able N-central and PaperCut.

Almost nothing about the flaw is public

As of the Sophos advisory, no CVE identifier, affected version list, technical description or threat actor has been published. Nothing in the advisory confirms that an attack has actually taken place, and the zero-day is described only as a possible cause. IntelFusions has not independently seen the Kiteworks email, so its exact wording and scope rest on what Sophos reported.

Follow the Kiteworks email, or call the vendor

Sophos CTU researchers recommend that Kiteworks customers follow the guidance in the vendor's email or contact Kiteworks directly. Customers who did not receive the notice should check with Kiteworks whether their deployment is in scope rather than wait for a public advisory, and with the reported window running until 08:00 UTC today, anyone who has not acted should treat this as urgent.

When a patch or technical advisory does appear, apply it before bringing servers back onto the internet. A precautionary shutdown buys time, but it cannot tell a customer whether their server was touched before the warning arrived, so the logs from the days leading up to it deserve a careful look.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions