---
title: "Kiteworks tells customers to switch off their servers for six hours"
description: "On 25 September 2026, secure file transfer vendor Kiteworks advised customers worldwide to power down for six hours on Saturday. Nothing has actually been breached: the advice rests on intelligence passed on by federal authorities."
canonical: https://inyourgeek.com/en/articles/2026-09-26-kiteworks-demande-a-ses-clients-d-eteindre-leurs-serveurs
type: article
author: "Sébastien Soulier"
publisher: "InYourGeek"
language: en
datePublished: 2026-09-26
dateModified: 2026-09-26
section: "Security"
tags: ["kiteworks", "zeroday", "mft", "clop"]
---
# Kiteworks tells customers to switch off their servers for six hours
> On 25 September 2026, secure file transfer vendor Kiteworks advised customers worldwide to power down for six hours on Saturday. Nothing has actually been breached: the advice rests on intelligence passed on by federal authorities.
September 26, 2026 · Security · 3 min
## A shutdown window mapped onto the time zones

On 25 September 2026, Kiteworks — which sells software for secure file sharing and transfer — emailed its customers to recommend they turn their servers off. According to German outlet Heise, quoted by [BleepingComputer](https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/), our only source here, the message from the company's chief information security officer cites credible intelligence from law enforcement that an attack on Kiteworks systems could be imminent over the weekend. There is no hedging in the wording: "We strongly recommend you shut down your Kiteworks system for six hours".

The window is global, rolling from Australian time (AEST) to the US west coast (PDT). In central Europe, customers were meant to go dark between 4am and 10am on Saturday 26 September; in New York, from 10pm Friday to 4am Saturday. The vendor advises powering down before the window opens, and doing it even for systems that aren't reachable from the internet — which is the detail worth stopping on, because that is not a normal thing to ask.

## What the vendor confirms, and what it skips

Kiteworks confirmed the alert to BleepingComputer: it says federal intelligence authorities indicated a threat actor might be looking to target some customer systems, and that it recommended the shutdown window as a precaution while it works the problem with its law enforcement partners. The statement is emphatic that nothing has actually happened: "We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach". The company adds that every known vulnerability is patched in the current release, 9.5.1, and tells customers to stay current.

What's missing is everything else. No CVE. No indicators of compromise to grep your logs for. No named actor. No word on what changes when the six hours are up. A customer who pulls the plug is doing it on their vendor's word, and the vendor is going on the word of an authority it won't name.

## "Zero-day" came from the help desk, not the press office

It was Heise, chasing the story with Kiteworks, that got the blunt version out of support: the shutdown is meant to protect "against any potential zero-day attacks". Neither the statement given to BleepingComputer nor the email Heise quotes confirms that any such flaw has been found or exploited.

The vendor's own phrasing fits that gap rather neatly. Saying that all known vulnerabilities are fixed in 9.5.1 is, by definition, a statement about the known ones — it tells you precisely nothing about the unknown ones. On a single source, the zero-day is a theory volunteered by a support rep, not something the company has announced.

## Six hours off, weighed against Clop's track record

The cost, meanwhile, is real and lands entirely on the customers: transfers cut off, overnight batch jobs failing, somebody on call at dawn on a Saturday — on a platform used by government bodies, financial institutions and large enterprises. All for a threat nobody has described in public.

On the other side of the scale sits the history. These platforms are where sensitive documents pile up, which makes them prime real estate for data-theft extortion, and Clop has made a career of exactly this: Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, MOVEit Transfer. Nobody has tied any particular group to this warning. The US State Department has a standing offer of $10 million for information linking the group's attacks to a foreign government.

Six hours of downtime is something you claw back on Monday morning. A document exfiltration is something you're still mailing breach notices about years later — and so far, nobody has said this one ever started.
## Sources
- [Kiteworks urges 6-hour server shutdown over potential zero-day attacks](https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/) — bleepingcomputer.com
_Article written with AI assistance from the cited sources, reviewed and approved by a human before publication._

---

Equivalent HTML page : https://inyourgeek.com/en/articles/2026-09-26-kiteworks-demande-a-ses-clients-d-eteindre-leurs-serveurs
Published by InYourGeek — https://inyourgeek.com/en/a-propos
Method and safeguards : https://inyourgeek.com/en/methode
All articles : https://inyourgeek.com/en/archives
