Managed file-transfer vendor Kiteworks — the company formerly known as Accellion — emailed customers urging them to shut the platform down during a six-hour window on Saturday over concerns of a possible attack. Its CISO, Frank Balonis, told Recorded Future News the company had "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers", and that the advisory was "preventative rather than a response to a confirmed breach": no Kiteworks systems are known compromised and all known vulnerabilities are addressed in release 9.5.1. The company would not say whether a CVE exists or which group might be involved; the FBI declined to comment and CISA did not respond. watchTowr's Jake Knott called it "unusual and concerning" that a vendor would ask its whole customer base to unplug production systems "because of a hunch", noting attackers' appetite for managed file-transfer appliances has not faded since the 2020 Clop campaign against Accellion that breached dozens of organisations.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-26 |
| Source | The Record |
| Reliability | Tier 2 |