Kiteworks Advises Customers to Shut Down Servers Due to Cyberattack Threat
Kiteworks, a technology company specializing in secure file transfers, has issued a warning to its customers to shut down their servers amid credible intelligence of a potential cyberattack. The alert comes after the company received information from law enforcement indicating that hackers may target its systems. This advisory was first reported by the German publication Heise, which noted that the threat could materialize as soon as this weekend.
Frank Balonis, Kiteworks' chief information security officer, confirmed to TechCrunch that the company is taking the threat seriously. He stated that they have not detected any compromise of their systems but are acting out of an abundance of caution. The company has recommended that customers implement a precautionary shutdown while they collaborate with law enforcement to investigate the threat.
In the communication sent to customers, Kiteworks expressed concern over potential exploitation of unknown vulnerabilities, referred to as zero-day flaws. These vulnerabilities could allow hackers to gain access to systems before the company has a chance to address them. As a result, Kiteworks urged customers to shut down their systems before the weekend to mitigate the risk of such attacks.
The exact number of customers potentially affected by this threat is unclear, but Kiteworks serves a diverse clientele across various sectors, including healthcare, technology, education, automotive, and government. Security researcher Kevin Beaumont noted that there are at least a thousand Kiteworks systems currently accessible online, although this figure may overestimate the number of systems at risk.
Immediate Customer Reactions to Security Alert
One healthcare customer reported taking immediate action following the alert, shutting down their server to prevent any potential breach. This precaution has led to disruptions in their operations, affecting doctors' ability to communicate with patients.
Approved for Dissemination
Kiteworks has a history of cybersecurity issues. Previously, while operating under the name Accellion, the company faced a significant data breach that resulted from vulnerabilities in its file transfer application. This incident allowed an extortion group to hack into numerous organizations, stealing sensitive data and demanding ransom payments.
As Kiteworks navigates this latest threat, it continues to emphasize the importance of customer safety and the need for vigilance against potential cyberattacks. The company has assured its clients that it has addressed all known vulnerabilities in its latest software release, version 9.5.1, which it recommends all customers to utilize.