Executive Summary

On September 25th, 2026, Kiteworks notified customers that it has received credible threat intelligence from the U.S federal government, specifically the intelligence community indicating an attack on Kiteworks systems may be imminent this weekend.

Kiteworks recommends that customers who manage their own Kiteworks systems, whether on-premises or in AWS or Azure, shut it down for nine hours beginning at 02:00 UTC on Saturday, September 26th, 2026. Beazley Security is unsure as to why this specific time window is the only expected exposure. Beazley Security labs recommends that organizations leave the systems shut down longer, if feasible until more information is provided.

Kiteworks states that its latest version, 9.5.1, accounts for all known vulnerabilities, and that it has no indication that Kiteworks or customer systems have been compromised, but it cannot be discounted potential attacks are related to a zero-day unknown to the vendor. Kiteworks will shut down the systems it hosts during the same window.

This is a developing situation, and Beazley Security will continue to monitor for new developments and update this advisory as necessary. In the meantime, Beazley Security recommends that self-managed customers shut down the potentially affected systems as soon as possible.

Affected Systems or Products

Self-managed Kiteworks instances (on-premises, AWS, or Azure).

Kiteworks notification states that no user action is needed for *Kiteworks* hosted system that the vendor themselves will be bringing systems down on behalf of clients.

Mitigations / Workarounds

There are no known workarounds or mitigations. Kiteworks simply recommends shutting down Kiteworks systems during a 9 hour shutdown Window. Beazley Security recommends shutting these systems down for longer, if possible.

The kiteworks suggested shutdown window is available below:

  • New York: 10:00 PM Friday, September 25th to 7:00 AM Saturday, September 26th

  • London: 3:00 AM to 12:00 PM Saturday, September 26th

  • Sydney: 12:00 PM to 9:00 PM Saturday, September 26th

Technical Details

Kiteworks, formerly known as Accellion, previously operated a widely used file transfer platform that became the target of a major exploitation campaign in December 2020. During the campaign, the Clop ransomware group exploited a zero-day vulnerability to steal data from high profile organizations.

No known CVE, patch, or additional technical details are publicly available at this time.

How Beazley Security is responding

Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in taking action as soon as possible.

If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.

Sources