Kiteworks, the secure file‑transfer platform used by thousands of organisations, has ordered clients to power down all on‑premises servers immediately after receiving what it described as a "credible threat" of an imminent cyber‑attack.

Immediate action requested

In an email sent to customers on Tuesday, the company warned that law‑enforcement agencies had alerted it to a pending attack targeting its infrastructure. Kiteworks said the warning was specific enough to merit a full shutdown of any self‑hosted appliances, regardless of the size of the deployment.

"We have been advised that a coordinated attack is imminent and that our servers are a likely target," the notice read. "Customers should shut down all Kiteworks servers until further notice to protect their data and networks."

The directive applies to the on‑premises version of Kiteworks' software, which many large enterprises use to exchange sensitive files, such as financial statements, legal documents and health records. The cloud‑based service remains operational, the company added.

Nature of the threat

Kiteworks said it could not disclose the exact nature of the threat, citing ongoing investigations and the need to protect operational security. The company indicated that the warning came from a credible source within law‑enforcement, but did not name the agency.

Industry analysts note that the phrasing mirrors previous alerts issued after high‑profile ransomware campaigns, where attackers often threaten to exploit known vulnerabilities in widely deployed software.

Industry response

Several major clients, including a multinational bank and a global pharmaceutical firm, confirmed they were already beginning the shutdown process. "We are following Kiteworks' guidance and have isolated our file‑transfer nodes as a precaution," a spokesperson for the bank said, according to a statement released on Wednesday.

Cyber‑security firms warned that the timing could coincide with a broader wave of attacks that have targeted supply‑chain software in recent months. "When a platform as ubiquitous as Kiteworks is threatened, the ripple effect can be massive," said a senior analyst at CyberEdge, a consultancy that tracks ransomware trends.

Wider cybersecurity context

Kiteworks, formerly known as Accellion, suffered a high‑profile breach in 2020 that exposed personal data from several U.S. government agencies and private companies. Since then, the firm has rebuilt its security architecture and marketed the service as a hardened solution for regulated industries.

The current alert arrives at a time when ransomware groups have increasingly targeted the software supply chain, exploiting trust relationships between vendors and their clients. According to the Global Cybersecurity Index, incidents involving third‑party platforms have risen by roughly 30 % year‑on‑year.

Experts say the precautionary shutdown is a rare step, reflecting the seriousness of the warning. "Shutting down production servers is disruptive, but the alternative—potential data exfiltration or ransomware encryption—could be far more damaging," explained Dr Lena Patel, a professor of information security at the University of Cambridge.

Kiteworks has pledged to keep customers updated as the investigation unfolds and has offered free technical assistance to accelerate the shutdown and subsequent reinstatement of services.

The situation remains fluid, with the company urging organisations to monitor internal networks for any anomalous activity and to prepare incident‑response plans in case the threat materialises.