Kiteworks, a vendor whose secure file transfer software is widely deployed in regulated industries including healthcare, told customers this week to switch off its platform during a six-hour window on Saturday.
The company said it acted on “credible threat intelligence from federal intelligence authorities” that a threat actor might target some customer systems, according to The Record. Chief Information Security Officer Frank Balonis called the advisory preventative, saying Kiteworks is not aware of any compromise and that all known flaws are fixed in version 9.5.1. A support official told German outlet Heise the warning stemmed from a possible zero-day. No CVE or patch details have been released, and neither the FBI nor CISA would comment.
The caution is unusual. Security firm watchTowr noted that vendors rarely ask an entire customer base to unplug production servers over a hunch. Under its former name, Accellion, the company ran a file transfer tool that the Clop crew cracked in late 2020, vacuuming data from dozens of well-known victims, among them Bombardier and the University of Colorado.
For hospital IT teams running managed file transfer appliances to move PHI, the practical steps are straightforward: confirm the Kiteworks version in use, move to 9.5.1, watch for vendor updates, and treat transfer logs as a hunting ground for unusual activity.