Kiteworks tells customers to shut down servers over possible zero-day threat
Kiteworks, led by CEO Jonathan Yaron, advised a precautionary shutdown after receiving law-enforcement threat intelligence; CISO Frank Balonis says it is unaware of any compromise.
By Ryan Merket · Published
Primary source: TechCrunch
Why it matters
A security platform's warning can force customers to choose between keeping sensitive-data workflows running and taking systems offline. The alert's undisclosed scope makes clear technical guidance essential.

Kiteworks told customers on September 25th to shut down their systems before the weekend after receiving law-enforcement intelligence about a possible attack, a warning that puts the continuity of customers' sensitive-data operations in the balance. CEO Jonathan Yaron leads Kiteworks, which says it is unaware of any compromise of its systems and describes the shutdown advice as precautionary.
The warning, first reported by Heise and confirmed by Kiteworks to TechCrunch, leaves the central technical question unanswered: what exactly prompted the alert? Kiteworks has not identified the law-enforcement agency, a suspected hacking group, a vulnerability, or the customers and systems it considers at risk.
Frank Balonis, Kiteworks' chief information security officer, told TechCrunch the company received credible threat intelligence indicating that an actor might target some customer systems. He said Kiteworks notified customers directly and recommended a shutdown window while Kiteworks and law-enforcement partners investigated. Balonis said Kiteworks was unaware of any compromise and that the advisory was preventive, not a response to a confirmed breach.
The reported customer email warned of possible exploitation of vulnerabilities unknown to Kiteworks, which would make them zero-days if exploited before the vendor could fix them. The email does not establish that a zero-day exists, that an attack has begun, or that customer data has been accessed. Kiteworks said it had fixed all known vulnerabilities in version 9.5.1 and recommended customers install it. A patch for known flaws cannot, by itself, answer a warning about flaws the company says it does not know about.
A shutdown is the mitigation
For customers running Kiteworks on their own infrastructure, taking systems offline is a blunt but immediate way to reduce exposure while details remain unclear. It can also interrupt the secure file transfers, email, sharing workflows, and other exchanges those systems support. The recommendation asks customers to weigh operational downtime against the risk described in the alert. Heise reported a six-hour shutdown window for customer systems worldwide beginning Saturday; TechCrunch reported that it was unclear how many customers might be affected.
TechCrunch reported that security researcher Kevin Beaumont pointed to at least 1,000 internet-facing Kiteworks systems on Shodan. That is a count of systems visible online, not a count of vulnerable or affected deployments. The publication also said Kiteworks describes its customer base as numbering in the thousands across sectors including healthcare, technology, education, automotive, and government. Neither figure establishes how widely the warning applies.
For Yaron, the incident tests the central promise of the business he has spent years reshaping: that organizations can move sensitive information outside their own systems while maintaining control over it. Kiteworks began as Accellion, founded in 1999 by Nikhil Jhingan and S. Mohan. A 2004 Venture Intelligence account described its early focus on oversized email attachments, which could overwhelm corporate email systems. The original product separated those files from email and sent them through a dedicated appliance.
Yaron arrived later. He encountered Accellion in 2015 while consulting for the private-equity firm that owned it, became chairman, and took the CEO job in 2017. In an Insight Partners profile, the investor describes his work rebuilding the leadership team and shifting Kiteworks from file-transfer software toward a broader data-protection platform. Yaron's background includes founding and selling enterprise software businesses. The transformation expanded what Kiteworks sells; today's shutdown warning puts pressure on the trust customers place in the systems through which that data moves.
The stakes are heightened by Accellion's past. In 2021, CISA documented attacks exploiting vulnerabilities in Accellion's legacy File Transfer Appliance. Kiteworks has said those flaws were limited to the legacy product and did not affect its platform, as described on its security updates page. That history does not connect the old attacks to the current alert. Customers and security teams will look closely at whether Kiteworks can explain the present warning with the specificity needed to distinguish a precaution from an incident.
Trust under operational pressure
Kiteworks has a substantial investor base behind its current strategy. In August 2024, Kiteworks announced a $456 million growth-equity investment from Insight Partners and Sixth Street Growth, describing it as a partial liquidity event. That financing reflected investor confidence in a platform built around secure data movement. The September advisory presents the operational counterpart: when a vendor tells customers to take the platform offline, its security response becomes part of the product customers are paying for.
Kiteworks' recommendation may prove to be the right precaution. From the information disclosed so far, customers cannot determine the suspected route of access, whether a specific product configuration is involved, or how long systems should remain down. Those details would let administrators make a more targeted decision than a broad shutdown. Kiteworks says it is working with law-enforcement partners and is unaware of any compromise; the scope and technical basis for the warning remain unspecified.