Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-26 · updated: 2026-09-26 · tags: [incident, vendor, supply-chain] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false

Managed file-transfer vendor Kiteworks — the company formerly known as Accellion — emailed customers urging them to shut the platform down during a six-hour window on Saturday over concerns of a possible attack. Its CISO, Frank Balonis, told Recorded Future News the company had "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers", and that the advisory was "preventative rather than a response to a confirmed breach": no Kiteworks systems are known compromised and all known vulnerabilities are addressed in release 9.5.1. The company would not say whether a CVE exists or which group might be involved; the FBI declined to comment and CISA did not respond. watchTowr's Jake Knott called it "unusual and concerning" that a vendor would ask its whole customer base to unplug production systems "because of a hunch", noting attackers' appetite for managed file-transfer appliances has not faded since the 2020 Clop campaign against Accellion that breached dozens of organisations.

Attribute Detail
Sector Global (Macro)
Date 2026-09-26
Source The Record
Reliability Tier 2