Heise security published the exclusive first, citing the customer email. Balonis wrote that LE partners flagged an attack that “may be imminent this weekend,” and urged a temporary shutdown. Heise’s English report and German original both say the company confirmed a worldwide six-hour window on Saturday, September 26 — in Central Europe 04:00–10:00 CEST — and recommended shutting down even earlier, including systems that are not internet-facing, because other access paths cannot be ruled out.
The worry named in customer messaging is exploitation of vulnerabilities currently unknown to Kiteworks (zero-days). Separately, Balonis told TechCrunch that all known vulnerabilities are fixed in the latest release, 9.5.1, which customers should run. The company did not name the LE agency or a suspected actor when asked; FBI and CISA did not comment to TechCrunch on deadline.
Scope: Kiteworks says it has thousands of customers across healthcare, tech, education, automotive, and government — treat that as a company claim. Impacted-customer count remains Undisclosed. One unnamed healthcare customer told TechCrunch they took their server down immediately and saw delays contacting patients. Kevin Beaumont pointed to a public listing of at least ~1,000 internet-facing Kiteworks hosts; TechCrunch notes that figure is likely an overcount of affected customer systems.
Why the desk cares: Accellion FTA was the file-transfer blast radius that fed mass extortion campaigns before the Kiteworks rebrand. A LE-driven, vendor-wide weekend kill-switch for a named enterprise file-transfer / private data network is Breaking even when the breach is still unconfirmed. CVE ID, actor name, and victim count: none is published for this advisory.
